CPA LogoCPA Exam Prep

Chapter Summary

Key Takeaways

  • IT Governance aligns technology with business objectives.
  • The five governance objectives are Strategic Alignment, Value Delivery, Risk Optimization, Resource Optimization, and Performance Measurement.
  • Frameworks such as COBIT, ITIL, ISO/IEC 27001, and NIST support governance implementation.
  • Risk management includes identification, assessment, response, and monitoring.
  • Risk responses include Avoid, Mitigate, Transfer, and Accept.
  • Internal controls reduce organizational risks.
  • Compliance ensures adherence to laws, regulations, standards, and policies.
  • Policies, standards, procedures, and guidelines provide governance structure.
  • Governance responsibilities are shared across management, IT, security, and auditors.
  • KPIs and KRIs help measure governance effectiveness.

Effective IT Governance transforms technology from a business cost into a strategic asset.

Summary
This chapter introduced IT Governance, Risk Management, and Compliance, explaining how organizations align technology with business strategy, manage technology risks, implement internal controls, comply with regulations, and measure governance performance. These concepts provide the foundation for understanding information system controls and IT auditing.