< Return to Video

CISA Domain 2 | Governance and Management of IT (Part 5) | Learn CISA

  • 0:00 - 0:03
    [UPBEAT MUSIC]
  • 0:03 - 0:08
  • 0:08 - 0:11
    Welcome to Global
    Information Security Society
  • 0:11 - 0:13
    for Professionals of Pakistan.
  • 0:13 - 0:17
  • 0:17 - 0:21
    [NON-ENGLISH SPEECH]
  • 0:21 - 0:25
    Global Information Society
    for Professionals of Pakistan
  • 0:25 - 0:27
    [NON-ENGLISH SPEECH]
  • 0:27 - 0:45
  • 0:45 - 0:47
    Governance and management of IT.
  • 0:47 - 0:50
    [NON-ENGLISH SPEECH]
    session 2.4.
  • 0:50 - 0:57
    [NON-ENGLISH SPEECH] Domain
    2 [NON-ENGLISH SPEECH] fourth
  • 0:57 - 1:01
    session [NON-ENGLISH SPEECH]
    obviously it is fifth.
  • 1:01 - 1:03
    [NON-ENGLISH SPEECH]
  • 1:03 - 1:23
  • 1:23 - 1:29
    Formally session 1, 2,
    3, and 4th, 2.4 session.
  • 1:29 - 1:32
    [NON-ENGLISH] session
    [NON-ENGLISH SPEECH]
  • 1:32 - 1:38
  • 1:38 - 1:40
    Portfolio management.
  • 1:40 - 1:41
    IT portfolio management.
  • 1:41 - 1:44
    [NON-ENGLISH SPEECH] investment.
  • 1:44 - 1:46
    Investment [NON-ENGLISH SPEECH].
  • 1:46 - 1:49
    Prioritization
    [NON-ENGLISH SPEECH]
  • 1:49 - 1:54
  • 1:54 - 1:57
    Allocation, [NON-ENGLISH SPEECH]
  • 1:57 - 2:02
  • 2:02 - 2:03
    For the alignment.
  • 2:03 - 2:06
    [NON-ENGLISH SPEECH]
  • 2:06 - 2:19
  • 2:19 - 2:22
    IT department
    [NON-ENGLISH SPEECH]
  • 2:22 - 2:41
  • 2:41 - 2:44
    Strategies [NON-ENGLISH]
    objectives [NON-ENGLISH SPEECH]
  • 2:44 - 2:45
  • 2:45 - 2:46
    [COUGHS] Sorry.
  • 2:46 - 2:48
    [COUGHING] Excuse me.
  • 2:48 - 2:51
    [NON-ENGLISH SPEECH]
  • 2:51 - 2:53
    Anyways, [NON-ENGLISH SPEECH]
  • 2:53 - 3:14
  • 3:14 - 3:17
    For example,
    [NON-ENGLISH SPEECH] easy money
  • 3:17 - 3:22
    [NON-ENGLISH SPEECH]
    Bitcoin [NON-ENGLISH SPEECH]
  • 3:22 - 3:25
    terminologies
    [NON-ENGLISH SPEECH]
  • 3:25 - 3:28
  • 3:28 - 3:30
    Foreign exchange
    [NON-ENGLISH SPEECH] investment
  • 3:30 - 3:32
    [NON-ENGLISH SPEECH]
  • 3:32 - 3:35
    Objective [NON-ENGLISH SPEECH]
  • 3:35 - 3:36
  • 3:36 - 3:39
    NGO [NON-ENGLISH SPEECH]
  • 3:39 - 4:05
  • 4:05 - 4:08
    [NON-ENGLISH SPEECH]
  • 4:08 - 4:09
  • 4:09 - 4:12
    [NON-ENGLISH SPEECH]
  • 4:12 - 4:23
  • 4:23 - 4:26
    day-to-day operations
    [NON-ENGLISH SPEECH]
  • 4:26 - 4:34
  • 4:34 - 4:36
    IT portfolio management
    [NON-ENGLISH].
  • 4:36 - 4:39
    IT portfolio management
    [NON-ENGLISH SPEECH] IT
  • 4:39 - 4:43
    portfolio management,
    [NON-ENGLISH SPEECH]
  • 4:43 - 6:26
  • 6:26 - 6:30
    Inside the organization,
    outside the organization
  • 6:30 - 6:32
    [NON-ENGLISH SPEECH]
  • 6:32 - 6:50
  • 6:50 - 6:59
    So this snapshot of
    existing status of our IT
  • 6:59 - 7:02
    of our organization,
    [NON-ENGLISH SPEECH] portfolio
  • 7:02 - 7:02
    [NON-ENGLISH].
  • 7:02 - 7:08
    I hope [NON-ENGLISH SPEECH] The
    IT portfolio is distinct from
  • 7:08 - 7:10
    the IT financial management.
  • 7:10 - 7:14
    Financial management
    [NON-ENGLISH SPEECH]
  • 7:14 - 7:48
  • 7:48 - 7:53
    It has strategic goals in
    determining the IT direction
  • 7:53 - 7:56
    towards [NON-ENGLISH SPEECH]
  • 7:56 - 8:27
  • 8:27 - 8:31
    On the basis of your
    expertise, your portfolio,
  • 8:31 - 8:34
    [NON-ENGLISH SPEECH]
  • 8:34 - 9:33
  • 9:33 - 9:38
    Redundant [NON-ENGLISH], slack
    time [NON-ENGLISH SPEECH]
  • 9:38 - 9:42
  • 9:42 - 9:46
    So this is what is called
    IT portfolio management.
  • 9:46 - 9:50
  • 9:50 - 9:53
    Key governance practices
    in IT portfolio management
  • 9:53 - 9:57
    include the evaluation,
    direction, and monitoring
  • 9:57 - 9:59
    of value optimization.
  • 9:59 - 10:01
    So [NON-ENGLISH] value
    [NON-ENGLISH SPEECH] Optimize
  • 10:01 - 10:04
    [NON-ENGLISH SPEECH]
  • 10:04 - 10:09
  • 10:09 - 10:13
    So key governance practices in
    IT portfolio management includes
  • 10:13 - 10:16
    [NON-ENGLISH SPEECH]
  • 10:16 - 10:29
  • 10:29 - 10:32
    OK, IT portfolio
    management continued.
  • 10:32 - 10:36
    The most significant advantage
    of IT portfolio management
  • 10:36 - 10:40
    is agility in adjusting
    investment based
  • 10:40 - 10:43
    on built-in feedback mechanism.
  • 10:43 - 10:46
    Obviously, [NON-ENGLISH SPEECH]
  • 10:46 - 11:09
  • 11:09 - 11:12
    Implementation method
    includes, portfolio management
  • 11:12 - 11:15
    [NON-ENGLISH] implement
    [NON-ENGLISH SPEECH] Number
  • 11:15 - 11:19
    [NON-ENGLISH], risk
    profile analysis.
  • 11:19 - 11:21
    [NON-ENGLISH SPEECH]
  • 11:21 - 11:42
  • 11:42 - 11:47
    Whatever is the
    treatment plan you have.
  • 11:47 - 11:50
    Diversification of projects,
    infrastructure and technology,
  • 11:50 - 11:53
    [NON-ENGLISH SPEECH]
  • 11:53 - 13:06
  • 13:06 - 13:11
    OK, next slide
    [NON-ENGLISH SPEECH] Now over
  • 13:11 - 13:12
    to you.
  • 13:12 - 13:15
    Discussion question number 1.
  • 13:15 - 13:20
  • 13:20 - 13:22
    Number 2 we have here.
  • 13:22 - 14:13
  • 14:13 - 14:15
    OK.
  • 14:15 - 14:19
    Usually, exam
    [NON-ENGLISH SPEECH]
  • 14:19 - 15:35
  • 15:35 - 15:37
    OK.
  • 15:37 - 15:41
    The merger of two organizations,
    multiple self-developed legacy
  • 15:41 - 15:43
    applications from
    both organizations
  • 15:43 - 15:47
    are to be replaced by
    a new common platform.
  • 15:47 - 15:49
    Which of the following
    would be the greatest risk?
  • 15:49 - 15:52
    Project management and
    the progress reporting
  • 15:52 - 15:55
    is combined in a project
    management office which is
  • 15:55 - 15:56
    driven by external consultant.
  • 15:56 - 16:02
    I think it's risk but it's
    not the greatest risk.
  • 16:02 - 16:07
    The replacement effort consists
    of several independent projects
  • 16:07 - 16:10
    without integrating the resource
    allocation in a portfolio
  • 16:10 - 16:13
    management approach, the risk.
  • 16:13 - 16:15
    The resource of
    each organization
  • 16:15 - 16:18
    is inefficiently
    allocated while they
  • 16:18 - 16:22
    are being from familiarized
    with the other companies legacy
  • 16:22 - 16:23
    system.
  • 16:23 - 16:25
    The new platform will
    force the business area
  • 16:25 - 16:27
    of both organizations to
    change their work process.
  • 16:27 - 16:28
    Good.
  • 16:28 - 16:31
    [NON-ENGLISH SPEECH]
  • 16:31 - 16:45
  • 16:45 - 16:52
    The correct answer is
    B. The correct answer
  • 16:52 - 16:53
    is the replacement
    effort consists
  • 16:53 - 16:58
    of several independent products
    without integrating the resource
  • 16:58 - 17:00
    allocation in a
    portfolio management.
  • 17:00 - 17:03
    [NON-ENGLISH SPEECH]
  • 17:03 - 17:31
  • 17:31 - 17:34
    To gain an understanding
    of the effectiveness
  • 17:34 - 17:38
    of an organization's planning
    and management of investment
  • 17:38 - 17:41
    in IT assets, an IS
    auditor should review the?
  • 17:41 - 17:48
  • 17:48 - 17:55
    Enterprise data model,
    IT balanced scorecard,
  • 17:55 - 18:01
    IT organizational structure,
    historical financial statement.
  • 18:01 - 18:07
    [NON-ENGLISH], simple,
    straightforward answer.
  • 18:07 - 18:12
    Naveed Ali
    [NON-ENGLISH SPEECH] C. OK.
  • 18:12 - 18:19
  • 18:19 - 18:24
    Ikra [NON-ENGLISH]
    answer [NON-ENGLISH] D.
  • 18:24 - 18:27
    [NON-ENGLISH SPEECH] Ikra
    [NON-ENGLISH] financial
  • 18:27 - 18:28
    background [NON-ENGLISH].
  • 18:28 - 18:30
    To gain an understanding
    of the effectiveness
  • 18:30 - 18:35
    of an organization's planning
    and management of investment
  • 18:35 - 18:39
    in IT assets, an IS
    auditor should review the?
  • 18:39 - 18:43
    IS auditor [NON-ENGLISH SPEECH]
    review [NON-ENGLISH SPEECH]
  • 18:43 - 18:45
    Management of investment.
  • 18:45 - 18:48
    [NON-ENGLISH SPEECH]
  • 18:48 - 18:59
  • 18:59 - 19:00
    Historical financial statements.
  • 19:00 - 19:03
    [NON-ENGLISH SPEECH] Seems good.
  • 19:03 - 19:07
    [NON-ENGLISH] enterprise data
    model [NON-ENGLISH SPEECH] IT
  • 19:07 - 19:13
    balanced scorecard
    [NON-ENGLISH SPEECH] OK.
  • 19:13 - 19:15
    So [NON-ENGLISH SPEECH]
  • 19:15 - 19:17
  • 19:17 - 19:21
    The correct answer is
    IT balanced scorecard.
  • 19:21 - 19:26
  • 19:26 - 19:27
    [NON-ENGLISH SPEECH]
  • 19:27 - 19:32
  • 19:32 - 19:34
    You can read.
  • 19:34 - 19:37
    Concentrate on answer B,
    the IT balanced scorecard.
  • 19:37 - 19:44
    [NON-ENGLISH SPEECH] IT balanced
    scorecard [NON-ENGLISH SPEECH]
  • 19:44 - 20:04
  • 20:04 - 20:10
    So IT balanced scorecard
    [NON-ENGLISH SPEECH]
  • 20:10 - 20:16
  • 20:16 - 20:19
    Number [NON-ENGLISH],
    financial growth.
  • 20:19 - 20:23
    Number [NON-ENGLISH SPEECH]
    internal processes.
  • 20:23 - 20:27
    Number [NON-ENGLISH],
    ability to innovate.
  • 20:27 - 20:29
    Innovation [NON-ENGLISH SPEECH].
  • 20:29 - 20:32
    [NON-ENGLISH SPEECH]
    customer satisfaction.
  • 20:32 - 20:36
  • 20:36 - 20:37
    OK.
  • 20:37 - 20:42
  • 20:42 - 20:44
    Process maturity framework.
  • 20:44 - 20:48
    [NON-ENGLISH SPEECH]
  • 20:48 - 20:52
  • 20:52 - 20:55
    Process maturity framework.
  • 20:55 - 20:57
    [NON-ENGLISH SPEECH]
  • 20:57 - 26:30
  • 26:30 - 26:33
    So these are the
    process maturity things.
  • 26:33 - 26:36
    [NON-ENGLISH SPEECH]
  • 26:36 - 26:39
  • 26:39 - 26:41
    It's a life cycle
    to complete a task.
  • 26:41 - 26:43
    [NON-ENGLISH SPEECH]
  • 26:43 - 26:47
  • 26:47 - 26:51
    [COUGHING]
  • 26:51 - 26:56
  • 26:56 - 26:58
    Sorry.
  • 26:58 - 27:01
    [NON-ENGLISH SPEECH]
  • 27:01 - 27:58
  • 27:58 - 27:59
    Obviously, it was efficient.
  • 27:59 - 28:02
    [NON-ENGLISH SPEECH]
  • 28:02 - 28:14
  • 28:14 - 28:17
    In another case,
    [NON-ENGLISH SPEECH]
  • 28:17 - 28:29
  • 28:29 - 28:31
    Yes, it was effective.
  • 28:31 - 28:34
    [NON-ENGLISH SPEECH]
  • 28:34 - 28:50
  • 28:50 - 28:52
    Yes, it was efficient.
  • 28:52 - 28:53
    [NON-ENGLISH SPEECH]
  • 28:53 - 28:55
    Yes, it was effective.
  • 28:55 - 28:57
    [NON-ENGLISH SPEECH]
  • 28:57 - 29:01
  • 29:01 - 29:03
    It was a quality process.
  • 29:03 - 29:05
    [NON-ENGLISH SPEECH]
  • 29:05 - 29:22
  • 29:22 - 29:25
    So this is called
    process maturity.
  • 29:25 - 29:27
    OK.
  • 29:27 - 29:29
    [NON-ENGLISH] different
    frameworks market
  • 29:29 - 29:32
    [NON-ENGLISH SPEECH]
    CMMI [NON-ENGLISH],
  • 29:32 - 29:34
    Capability Maturity
    Integration Model.
  • 29:34 - 29:36
    [NON-ENGLISH SPEECH]
  • 29:36 - 29:42
  • 29:42 - 29:46
    COBIT Process Assessment Model
    [NON-ENGLISH SPEECH] CMMI
  • 29:46 - 29:49
    [NON-ENGLISH SPEECH]
  • 29:49 - 29:54
  • 29:54 - 29:57
    Maintaining consistency,
    efficiency, and effectiveness
  • 29:57 - 30:01
    of IT processes require the
    implementation of a process
  • 30:01 - 30:02
    maturity framework.
  • 30:02 - 30:05
    [NON-ENGLISH SPEECH]
  • 30:05 - 30:30
  • 30:30 - 30:32
    Several models may be
    encountered in the organization,
  • 30:32 - 30:36
    including COBIT [NON-ENGLISH]
    process assessment model.
  • 30:36 - 30:39
    [NON-ENGLISH SPEECH]
  • 30:39 - 31:05
  • 31:05 - 31:11
    So they fall in about 35,
    36, 30, 30, 37 processes.
  • 31:11 - 31:13
    [NON-ENGLISH SPEECH]
  • 31:13 - 31:15
  • 31:15 - 31:17
    Stage 1, stage 2, stage 3.
  • 31:17 - 31:20
    [NON-ENGLISH SPEECH]
  • 31:20 - 31:56
  • 31:56 - 32:02
    CMMI, Capability Maturity
    Model Integration,
  • 32:02 - 32:04
    [NON-ENGLISH SPEECH]
  • 32:04 - 32:50
  • 32:50 - 32:53
    So initial processes
    are unpredictable.
  • 32:53 - 32:56
    [NON-ENGLISH SPEECH]
  • 32:56 - 33:03
  • 33:03 - 33:07
    The processes are unpredictable,
    poorly controlled, and reactive.
  • 33:07 - 33:10
    [NON-ENGLISH SPEECH]
  • 33:10 - 33:48
  • 33:48 - 33:51
    Processes are unpredictable,
    poorly controlled, and reactive.
  • 33:51 - 33:54
    Repeatable, [NON-ENGLISH SPEECH]
  • 33:54 - 36:03
  • 36:03 - 36:05
    Several organizations
    I want to name.
  • 36:05 - 36:11
    Allied Bank [NON-ENGLISH SPEECH]
    processes are well standardized
  • 36:11 - 36:13
    [NON-ENGLISH SPEECH]
  • 36:13 - 36:14
  • 36:14 - 36:17
    They are working in silos.
  • 36:17 - 36:19
    [NON-ENGLISH SPEECH]
  • 36:19 - 38:16
  • 38:16 - 38:18
    So that is called
    optimization level 5.
  • 38:18 - 38:21
    [NON-ENGLISH SPEECH]
  • 38:21 - 38:44
  • 38:44 - 38:50
    [CHUCKLES] [NON-ENGLISH SPEECH]
    [CHUCKLES] [NON-ENGLISH SPEECH]
  • 38:50 - 38:57
  • 38:57 - 39:02
    Optimize [NON-ENGLISH] according
    to your external customers,
  • 39:02 - 39:02
    stakeholders.
  • 39:02 - 39:07
    So this is called
    process maturity levels.
  • 39:07 - 39:10
    [NON-ENGLISH SPEECH]
  • 39:10 - 39:13
  • 39:13 - 39:19
    PDCA model, Plan,
    Do, Check, Act.
  • 39:19 - 39:22
    [NON-ENGLISH SPEECH]
  • 39:22 - 40:37
  • 40:37 - 40:39
    Implement the plan.
  • 40:39 - 40:42
    Collecting data for
    charting, analysis.
  • 40:42 - 40:44
    [NON-ENGLISH SPEECH]
  • 40:44 - 40:51
  • 40:51 - 40:55
    I'm going for studies
    [NON-ENGLISH SPEECH]
  • 40:55 - 41:03
  • 41:03 - 41:06
    [CHUCKLES] [NON-ENGLISH SPEECH]
  • 41:06 - 41:21
  • 41:21 - 41:24
    [CHUCKLES] [NON-ENGLISH SPEECH]
  • 41:24 - 42:18
  • 42:18 - 42:24
    [CHUCKLES] [NON-ENGLISH SPEECH]
    plan, do, check, act, clear?
  • 42:24 - 42:26
    [NON-ENGLISH] question.
  • 42:26 - 42:28
    [NON-ENGLISH SPEECH]
  • 42:28 - 42:31
  • 42:31 - 42:35
    [CHUCKLES] OK,
    quality management.
  • 42:35 - 42:39
    Quality management
    [NON-ENGLISH SPEECH]
  • 42:39 - 43:13
  • 43:13 - 43:17
    The development and maintenance
    of defined and documented IT
  • 43:17 - 43:25
    quality management processes
    is evident of effective GEIT,
  • 43:25 - 43:28
    Governances Enterprise IT.
  • 43:28 - 43:30
    [NON-ENGLISH] IT governance
    [NON-ENGLISH] governance
  • 43:30 - 43:33
    in enterprise IT,
    [NON-ENGLISH SPEECH]
  • 43:33 - 43:40
  • 43:40 - 43:46
    Governance in enterprise
    IT, end-to-end organization
  • 43:46 - 43:48
    [NON-ENGLISH SPEECH]
  • 43:48 - 44:00
  • 44:00 - 44:02
    Quality management
    defined as a set
  • 44:02 - 44:06
    of tasks that produce desired
    results when properly performed.
  • 44:06 - 44:08
    Various standards
    provides guidelines
  • 44:08 - 44:11
    for governance of
    quality management,
  • 44:11 - 44:16
    including those in
    ISO 20000 series.
  • 44:16 - 44:19
    [NON-ENGLISH SPEECH]
  • 44:19 - 44:31
  • 44:31 - 44:35
    Anyways, the good
    news is the IS auditor
  • 44:35 - 44:36
    should be aware of
    quality management.
  • 44:36 - 44:41
    However, [NON-ENGLISH SPEECH]
  • 44:41 - 45:46
  • 45:46 - 45:47
    Statement that the
    IS auditor should
  • 45:47 - 45:49
    be aware of quality management.
  • 45:49 - 45:53
    However, [NON-ENGLISH SPEECH]
    [CHUCKLES] [NON-ENGLISH SPEECH]
  • 45:53 - 45:58
    The CISA exam does not test
    specific on any ISO standard.
  • 45:58 - 46:01
    So [NON-ENGLISH SPEECH]
  • 46:01 - 46:12
  • 46:12 - 46:13
    Excuse me.
  • 46:13 - 46:16
    Discussion question number 3.
  • 46:16 - 46:18
    OK, go ahead.
  • 46:18 - 47:10
  • 47:10 - 47:12
    OK [NON-ENGLISH].
  • 47:12 - 47:14
    [NON-ENGLISH SPEECH]
  • 47:14 - 48:04
  • 48:04 - 48:07
    Identify and report the
    controls currently in place.
  • 48:07 - 48:10
    [NON-ENGLISH SPEECH]
  • 48:10 - 48:24
  • 48:24 - 48:28
    Correct answer is D.
    [NON-ENGLISH SPEECH]
  • 48:28 - 49:16
  • 49:16 - 49:21
    Process number 4, element number
    4, identify [NON-ENGLISH SPEECH]
  • 49:21 - 49:32
  • 49:32 - 49:36
    OK, next question
    [NON-ENGLISH SPEECH] Number 4.
  • 49:36 - 49:50
  • 49:50 - 49:55
    [NON-ENGLISH] critical success
    factor [NON-ENGLISH SPEECH]
  • 49:55 - 51:10
  • 51:10 - 51:14
    Most critical success
    factor, security program
  • 51:14 - 51:18
    [NON-ENGLISH SPEECH]
    Establishment of a review board.
  • 51:18 - 51:20
    Creation of security unit.
  • 51:20 - 51:25
  • 51:25 - 51:28
    Effective support of
    an executive sponsor.
  • 51:28 - 51:30
    Selection of a
    security process owner.
  • 51:30 - 51:35
  • 51:35 - 51:37
    [NON-ENGLISH SPEECH]
  • 51:37 - 51:52
  • 51:52 - 51:55
    A is a good option.
  • 51:55 - 51:58
    [NON-ENGLISH SPEECH] So rethink.
  • 51:58 - 52:03
  • 52:03 - 52:05
    [NON-ENGLISH SPEECH]
  • 52:05 - 52:26
  • 52:26 - 52:30
    [CHUCKLES] [NON-ENGLISH SPEECH]
  • 52:30 - 52:35
  • 52:35 - 52:40
    Correct answer is C.
    [NON-ENGLISH SPEECH]
  • 52:40 - 52:55
  • 52:55 - 53:01
    OK, performance optimization.
  • 53:01 - 53:03
    Performance optimization.
  • 53:03 - 53:06
    Performance optimization
    [NON-ENGLISH SPEECH]
  • 53:06 - 53:20
  • 53:20 - 53:22
    It's a balance.
  • 53:22 - 53:29
    It's a trade-off between the
    highest level of performance
  • 53:29 - 53:33
    and the minimum
    use of resources.
  • 53:33 - 53:35
    [NON-ENGLISH SPEECH]
  • 53:35 - 55:21
  • 55:21 - 55:25
    [CHUCKLES] [NON-ENGLISH SPEECH]
  • 55:25 - 55:31
  • 55:31 - 55:32
    [CHUCKLES] [NON-ENGLISH SPEECH]
  • 55:32 - 55:34
    So this is called optimization.
  • 55:34 - 55:41
    So maximum extract by using
    minimum possible resources.
  • 55:41 - 55:43
    [NON-ENGLISH SPEECH]
  • 55:43 - 55:47
  • 55:47 - 55:49
    Performance optimization
    is the process
  • 55:49 - 55:51
    of improving both perceived
    service performance
  • 55:51 - 55:54
    while bringing highest
    productivity to the highest
  • 55:54 - 55:57
    level possible.
  • 55:57 - 55:59
    [NON-ENGLISH]
  • 55:59 - 56:07
  • 56:07 - 56:09
    OK.
  • 56:09 - 56:10
    Ideally, this
    productivity will be
  • 56:10 - 56:13
    gained without excessive
    additional investment in the IT
  • 56:13 - 56:14
    infrastructure.
  • 56:14 - 56:16
    Effective performance
    measures are
  • 56:16 - 56:18
    used to create and
    facilitate action
  • 56:18 - 56:24
    to improve both performance and
    GEIT, Governances Enterprise IT.
  • 56:24 - 56:28
    [NON-ENGLISH SPEECH] these
    depend upon the clear definition
  • 56:28 - 56:29
    of performance goal.
  • 56:29 - 56:31
    [NON-ENGLISH SPEECH]
  • 56:31 - 56:46
  • 56:46 - 56:48
    [COUGHS] Sorry.
  • 56:48 - 56:51
    [COUGHING]
  • 56:51 - 56:56
  • 56:56 - 56:59
    [NON-ENGLISH SPEECH]
  • 56:59 - 57:24
  • 57:24 - 57:26
    Clear definition of
    performance goal,
  • 57:26 - 57:28
    the establishment
    of effective metrics
  • 57:28 - 57:30
    to monitor goal achievement.
  • 57:30 - 57:32
    [NON-ENGLISH SPEECH]
  • 57:32 - 57:53
  • 57:53 - 57:54
    You are on right track.
  • 57:54 - 57:57
    [NON-ENGLISH SPEECH]
  • 57:57 - 58:18
  • 58:18 - 58:19
    It's great.
  • 58:19 - 58:20
    It's the optimization.
  • 58:20 - 58:23
    [NON-ENGLISH SPEECH]
  • 58:23 - 58:38
  • 58:38 - 58:41
    Different tools and techniques
    [NON-ENGLISH SPEECH]
  • 58:41 - 58:57
  • 58:57 - 59:00
    White belt, brown
    belt, blue belt,
  • 59:00 - 59:04
    [NON-ENGLISH] then finally,
    [NON-ENGLISH SPEECH]
  • 59:04 - 59:23
  • 59:23 - 59:27
    White belt, green belt,
    blue belt, orange belt,
  • 59:27 - 59:28
    [NON-ENGLISH] belt,
    [NON-ENGLISH] belt,
  • 59:28 - 59:29
    [NON-ENGLISH].
  • 59:29 - 59:30
    [NON-ENGLISH SPEECH]
  • 59:30 - 60:15
  • 60:15 - 60:19
    Internal processes or
    customer satisfaction.
  • 60:19 - 60:23
    [NON-ENGLISH SPEECH] KPIs,
    Key Performance Indicator.
  • 60:23 - 60:24
    Key performance indicator.
  • 60:24 - 60:28
    Key performance indicator
    [NON-ENGLISH SPEECH]
  • 60:28 - 60:32
  • 60:32 - 60:34
    For example, [NON-ENGLISH]
    call center [NON-ENGLISH] key
  • 60:34 - 60:37
    performance indicator
    [NON-ENGLISH SPEECH]
  • 60:37 - 60:57
  • 60:57 - 60:59
    Yes, he's done a good job.
  • 60:59 - 61:01
    [NON-ENGLISH SPEECH]
  • 61:01 - 62:56
  • 62:56 - 62:57
    So this is called benchmarking.
  • 62:57 - 63:04
    Then [COUGHING] business
    process reengineering.
  • 63:04 - 63:07
    Business process reengineering
    [NON-ENGLISH SPEECH]
  • 63:07 - 64:28
  • 64:28 - 64:32
    Root Cause Analysis, RCA.
  • 64:32 - 64:35
    Root cause analysis
    [NON-ENGLISH SPEECH]
  • 64:35 - 65:47
  • 65:47 - 65:48
    It was the root cause analysis.
  • 65:48 - 65:51
    [NON-ENGLISH SPEECH]
  • 65:51 - 66:04
  • 66:04 - 66:06
    It was the root cause analysis.
  • 66:06 - 66:09
    [NON-ENGLISH] root cause
    analysis [NON-ENGLISH SPEECH]
  • 66:09 - 66:16
  • 66:16 - 66:19
    Life cycle cost
    benefit analysis.
  • 66:19 - 66:21
    [NON-ENGLISH SPEECH]
  • 66:21 - 66:48
  • 66:48 - 66:55
    Feasibility study, business
    case, requirement analysis,
  • 66:55 - 67:00
    requirement gathering,
    development, testing,
  • 67:00 - 67:01
    [NON-ENGLISH SPEECH]
  • 67:01 - 67:59
  • 67:59 - 68:01
    This is called optimization.
  • 68:01 - 68:03
    [NON-ENGLISH SPEECH]
  • 68:03 - 68:13
  • 68:13 - 68:14
    Clear, [INAUDIBLE].
  • 68:14 - 68:18
  • 68:18 - 68:23
    Thank you very much on
    the behalf of GISSP.
  • 68:23 - 68:25
    [NON-ENGLISH SPEECH]
  • 68:25 - 68:33
  • 68:33 - 68:37
    [COUGHING] Sorry.
  • 68:37 - 68:40
    [NON-ENGLISH SPEECH]
Title:
CISA Domain 2 | Governance and Management of IT (Part 5) | Learn CISA
Description:

more » « less
Video Language:
English
Duration:
01:08:41

English subtitles

Revisions