Courseiva

CISA IT Steering Committee Practice Question

A medium-sized manufacturing company has recently deployed an ERP system to integrate its financial, supply chain, and HR processes. The IT department is small (5 staff) and reports to the CFO. The company has no formal IT governance committee; IT decisions are made by the CFO and CEO informally. During a recent audit, it was found that several critical security patches for the ERP system have not been applied, and there are no documented procedures for change management. The IT manager states that patches are applied when time permits, and changes are discussed via email. The CFO argues that the ERP is running fine and the audit findings are low risk. The IS auditor needs to recommend a course of action to improve IT governance. Which of the following is the MOST appropriate initial step?

⚠ Common exam trap

CISA often tests the distinction between addressing a symptom (missing patches) and addressing the root cause (lack of governance); candidates frequently choose the technical fix because it feels more actionable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Recommend the formation of an IT steering committee comprising key business stakeholders to oversee IT strategy, risk, and resource allocation

The root cause of the audit findings is the absence of IT governance, not the missing patches themselves. Forming an IT steering committee establishes a governance structure that aligns IT strategy with business objectives, assigns accountability for risk, and provides oversight for change and patch management. This addresses the underlying governance gap rather than a symptom, making it the most appropriate initial step for the IS auditor to recommend.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Elevate the issue to the board of directors with a recommendation to outsource IT management

    Why it's wrong here

    Outsourcing IT management does not establish governance; the board lacks the committee structure to direct it, and the CFO's informal authority remains unchanged. It is tempting because escalation to the board addresses the governance vacuum, and would be correct if the board already had oversight mechanisms to act on the recommendation.

  • ✓

    Recommend the formation of an IT steering committee comprising key business stakeholders to oversee IT strategy, risk, and resource allocation

    Why this is correct

    An IT steering committee gives the five-person IT function formal governance oversight, addressing the absent decision-making structure the audit flagged. It routes patch and change-management accountability through business stakeholders rather than the CFO's informal judgement, satisfying the need for documented, risk-based governance.

  • ✗

    Develop a comprehensive patch management policy and present it to the CFO for approval

    Why it's wrong here

    A patch management policy addresses only one finding and bypasses the absent governance structure, leaving the CFO to approve IT controls unilaterally. It is tempting because documented policy is a recognised control, and would be correct after a governance committee exists to sponsor and enforce it.

  • ✗

    Insist that the IT manager immediately apply all missing patches within one week

    Why it's wrong here

    Incorrect. While necessary, this is a tactical fix that does not address the governance deficiency.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.