Courseiva

CISA Governance and Management of IT Practice Question

A medium-sized manufacturing company has a decentralized IT structure where each business unit manages its own IT budget and projects. The CEO is concerned that IT investments are not aligned with corporate strategy and that there is duplication of effort. The IT department lacks a formal project portfolio management process. The company has experienced several project failures due to poor prioritization. The CEO has asked the newly hired IT auditor to recommend an initial step to improve IT governance. The auditor should recommend:

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establishing an IT steering committee with representatives from business units and IT

An IT steering committee provides governance oversight, ensures alignment with corporate strategy, and helps prioritize projects to avoid duplication. This foundational step addresses the root cause of poor alignment and project failures before implementing tools or processes. Option B is premature because a tool without governance oversight may not improve prioritization. Option C focuses on security, not overall strategic alignment. Option D is drastic and does not address internal governance issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Establishing an IT steering committee with representatives from business units and IT

    Why this is correct

    A steering committee directly addresses the stem's constraint: no formal portfolio process across decentralised units. It creates a cross-functional forum that prioritises and aligns IT investments with corporate strategy, resolving duplication and poor prioritisation before any tooling or policy is introduced.

  • ✗

    Implementing a project portfolio management software tool immediately to track all projects

    Why it's wrong here

    A tracking tool automates an existing portfolio process; with no governance framework, prioritisation criteria or investment decision rights defined, it would catalogue projects without aligning them to strategy. It is tempting because portfolio tooling does support prioritisation and duplication visibility, and would be correct once a portfolio management process and governance structure exist.

  • ✗

    Conducting a security risk assessment of all IT systems

    Why it's wrong here

    A security risk assessment addresses threats and vulnerabilities, not the misalignment of IT investment with corporate strategy or duplicated effort across business units. It is tempting because risk assessment underpins governance, and would be correct if the CEO's concern were unidentified security exposure rather than poor project prioritisation and portfolio oversight.

  • ✗

    Outsourcing IT management to a third-party provider

    Why it's wrong here

    Outsourcing transfers operational responsibility but leaves the underlying governance gap: no mechanism ties IT investment decisions to corporate strategy or resolves duplication between business units. It is tempting because a provider can impose standardised processes, and would be correct if the problem were capability or resourcing rather than absent governance and prioritisation.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CISA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are key responsibilities of an IT steering committee?

medium
  • ✓ A.Monitoring IT performance and value delivery
  • B.Managing day-to-day IT operations
  • C.Writing and testing application code
  • ✓ D.Prioritizing IT projects and allocating resources
  • E.Conducting IT audit engagements

Why A: The IT steering committee is a senior-level governance body responsible for aligning IT strategy with business objectives. Monitoring IT performance and value delivery (A) is a key responsibility because the committee must ensure that IT investments generate the expected business benefits and that service levels meet agreed targets. Prioritizing IT projects and allocating resources (D) is also a core duty, as the committee decides which initiatives receive funding and staffing based on strategic importance and risk, rather than operational urgency.

Variation 2. A medium-sized manufacturing company has recently deployed an ERP system to integrate its financial, supply chain, and HR processes. The IT department is small (5 staff) and reports to the CFO. The company has no formal IT governance committee; IT decisions are made by the CFO and CEO informally. During a recent audit, it was found that several critical security patches for the ERP system have not been applied, and there are no documented procedures for change management. The IT manager states that patches are applied when time permits, and changes are discussed via email. The CFO argues that the ERP is running fine and the audit findings are low risk. The IS auditor needs to recommend a course of action to improve IT governance. Which of the following is the MOST appropriate initial step?

easy
  • A.Elevate the issue to the board of directors with a recommendation to outsource IT management
  • ✓ B.Recommend the formation of an IT steering committee comprising key business stakeholders to oversee IT strategy, risk, and resource allocation
  • C.Develop a comprehensive patch management policy and present it to the CFO for approval
  • D.Insist that the IT manager immediately apply all missing patches within one week

Why B: The root cause of the audit findings is the absence of IT governance, not the missing patches themselves. Forming an IT steering committee establishes a governance structure that aligns IT strategy with business objectives, assigns accountability for risk, and provides oversight for change and patch management. This addresses the underlying governance gap rather than a symptom, making it the most appropriate initial step for the IS auditor to recommend.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.