A
、
Project database
B
、
Policy documents
C
、
Project portfolio database
D
、
Program organization
ANSWER:C
NOTE:A project portfolio database is the basis for project portfolio
management. It includes project data, such as owner, schedules,
objectives, project type, status and cost. Project portfolio management
requires specific project portfolio reports. A project database may
contain the above for one specific project and updates to various
parameters pertaining to the current status of that single project. Policy
documents on project management set direction for the design, development,
implementation and monitoring of the project. Program organization is the
team required (steering committee, quality assurance, systems personnel,
analyst, programmer, hardware support, etc.) to meet the delivery
objective of the project.
350
、
An organization has outsourced its wide area network (WAN) to a
third-party service provider. Under these circumstances, which of the
following is the PRIMARY task the IS auditor should perform during an
audit of business continuity (BCP) and disaster recovery planning (DRP)?
A
、
Review whether the service provider's BCP process is aligned with
the organization's BCP and contractual obligations.
B
、
Review whether the service level agreement (SLA) contains a penalty
clause in case of failure to meet the level of service in case of a
disaster.
C
、
Review the methodology adopted by the organization in choosing the
service provider.
D
、
Review the accreditation of the third-party service provider's
staff.
ANSWER:A
NOTE:Reviewing whether the service provider's business continuity plan
(BCP) process is aligned with the organization's BCP and contractual
obligations is the correct answer since an adverse effect or disruption to
the business of the service provider has a direct bearing on the
organization and its customers. Reviewing whether the service level
agreement (SLA) contains a penalty clause in case of failure to meet the
level of service in case of a disaster is not the correct answer since the
presence of penalty clauses, although an essential element of a SLA, is
not a primary concern. Choices C and D are possible concerns, but of