CISA Governance and Management of IT Practice Question
A government agency has an IT governance framework that includes an IT strategy committee, an IT steering committee, and a project management office. Despite this, there is a lack of transparency regarding IT spending and resource allocation. The agency's annual audit found that several IT initiatives were not approved by the steering committee and were funded out of operational budgets. The CFO is frustrated because IT costs are unpredictable. The agency's chief information officer (CIO) reports to the CFO but the IT steering committee is chaired by the CIO. The auditor's best recommendation to improve governance is to:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the steering committee chair to a senior business executive independent of IT
Having an independent steering committee chair (e.g., a senior business executive) eliminates the conflict of interest where the CIO chairs the committee and can bypass governance. Option A (chargeback) addresses cost allocation but not the root cause of unauthorized spending. Option B (business case) is a good practice but can still be ignored if the committee chair is the CIO. Option D (policy) can be overridden or ignored without structural change in governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Establish a chargeback system to allocate IT costs to business units
Why it's wrong here
Chargeback improves transparency but does not address the governance bypass issue.
- ✗
Require all IT projects to submit a business case to the steering committee for approval
Why it's wrong here
This already exists; the problem is that projects bypass the committee because the CIO chairs it.
- ✓
Change the steering committee chair to a senior business executive independent of IT
Why this is correct
Independence strengthens oversight and reduces the ability of the CIO to bypass governance.
- ✗
Implement a policy that prohibits funding IT projects from operational budgets without steering committee approval
Why it's wrong here
Policy alone is ineffective if the governance structure allows the CIO to override it.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.