CGEIT Preparation Course Fall 2009 About the Exam. The Certified in Governance of Enterprise IT exam administered by ISACA consists of 250 multiple choice questions that need to be completed within 3 hours. Questions assess the candidates understanding of five domains of IT governance. This is not to say that the exam is a simple test of the candidates' objective knowledge of material in ISACA's CGEIT Basic References, because it is not. Rather, the exam assesses the candidates judgment involved in the application of governance principles and best practice. The exam is deceptively difficult and most candidates report surprise that their answer sheet was not scored considerably higher than it was. About the Prep Course The course intends to tune the judgment of candidates to achieve the necessary alignment with the knowledge and principles of the CGEIT Basic References. This will be accomplished through a combination of lecture and class discussion of governance scenarios and case studies supplemented by selective reading from the CGEIT Basic References and other materials. Course lectures are intended to frame and summarize the CGEIT Basic References. CGEIT candidates can easily be overwhelmed by the large volume and detail of the material of the CGEIT Basic References. Exam success does not require complete mastery, but without reading the material, it is difficult to determine what need be retained. The lectures will help candidates avoid this conundrum and be more efficient in their study. Class participants will be expected to complete short practice exams prior to each class session. Items will be based on previous lectures and assigned readings. These items are intended to mimic questions appearing of the CGEIT exam. The practice exams will be available online. Answers options will be evaluated and the 'correct answer' discussed during subsequent class sessions. Class discussion is essential aspect of the course. The CGEIT exam requires judgment as much or more than simple recitation of fact from the CGEIT Basic References. However, successful candidates must be able to formulate judgments in a way that is consistent with the principles and best practices expressed in the Basic References. Distinctions are subtle, the discipline of argument and counter argument in group discussion is valuable in tuning this capability. Course Schedule. Class will meet weekly from October until the December administration of the exam. Sessions will be conducted using the DimDIm webinar service. Sessions will be held Thursday evenings from 5-8 PM. PDT / PST (Pacific | US) About the Instructors Bill Pankey been an technology risk management consultant focused on the US healthcare industry for more than 15 years. He led a CGEIT study group last Spring and successfully sat for the CGEIT exam in June. He holds a number of industry certifications including: CGEIT, CISA, CISSP, QSA, MCSE \ MCSA: Security, GCUX, GSEC, GCIH, COBIT Foundation, ITIL Foundation, NSA IAM. Jim Anderson has had a long career in information risk management at senior executive levels in the financial services industry. He is currently an Executive Consultant / Director at Emagined Security and the Principal of Professional Assurance, LLC. He successfully sat for the CGEIT exam in June. He has an MBA from the University of Chicago and is a CGEIT, CISSP, CISM. Ann Geyer has been a risk and business management consultant in the US healthcare industry for the past 15 years. She is a California attorney and received an MBA from the Peter Drucker & Masatoshi Ito School of Management at Claremont College. Course Outline 1. Session One: Course Introduction & Foundations of IT Governance Lessons learned from the CGEIT Exam The CGEIT Exam The enterprise role of the CGEIT holder The CGEIT Body of Knowledge CGEIT Study tools & cheat sheet Study and Exam Strategies The IT governance problem The COBIT 'Pentagon' Information Properties Basic Themes and Principles Roles & Responsibilities Reading: CGEIT Candidate Handbook; Board Briefing on IT Governance 2. Session Two: IT Governance in the Extended Enterprise What is the 'extended' enterprise What is 'core'? Problems of IT Governance in the extended enterprise Governance principles applies to the extended enterprise Practice Test review & Class Discussion Reading: Governance in the Extended Enterprise TBD supplemental / substitute material 3. Session Three: Governance Frameworks What is a governance framework? Framework benefits Framework selection Roles and responsibilities The COSO Framework ISACA Frameworks (COBIT | ValIT | RiskIT) Basic Themes and Principles Practice Test review & Class Discussion Reading: TBD 4. Session Four: Survey of Frameworks Relationship among frameworks (the map) What, why and how of various IT management frameworks COBIT (process management) ValIT (value management) ITIL (service management) ISO 2700x / ISO 17799 (risk management) TOGAF (architecture) PMPBOK (project management) CMM (process maturity) Roles & Responsibilities Practice Test review & Class Discussion Reading: TBD 5. Session Five: Alignment Principles of alignment Balanced Scorecards, definition and use Roles & responsibilities Problem recognition, diagnosis and correction Practice Test review & Class Discussion Reading: TBD 6. Session Six: Value Delivery Principles of Value Delivery Value definition and measurement Roles & responsibilities Problem recognition, diagnosis and correction Practice Test review & Class Discussion Reading: IT Governance Implementation Guide 7. Session Seven: Risk Management COSO ERM Framework Types of Risk | Beyond CIA RiskIT Framework Roles & responsibilities Problem recognition, diagnosis and correction Practice Test review & Class Discussion Reading: The RiskIT Framework: Exposure Draft 8. Session Eight Resource Management Enterprise architecture Sourcing strategies Resource utilization / optimization Practice Test review & Class Discussion Reading: TBD 9. Session Nine: Performance Measurement Goals and Performance Indicators Metrics Roles & responsibilities Themes Practice Test review & Class Discussion Reading: TBD 10. Session Ten: Review Lessons learned from the CGEIT exam Review of ISACA Governance Principles & Best Practices Practice Test review & Class Discussion