Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which TWO of the following are essential components that the auditor should verify are in place? (Choose two.)

⚠ Common exam trap

The trap here is equating operational IT practices, such as help desk support or software approval, with essential governance components, which focus on strategic alignment and risk oversight.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A formal IT risk management process integrated with enterprise risk management

Effective IT governance requires alignment of IT strategy with business objectives and integration of IT risk management with enterprise risk management. These components ensure that IT delivers value, risks are managed, and resources are optimized. The auditor should verify that these elements are formally established, documented, and actively used. Without them, governance is incomplete and may fail to meet organizational needs. Operational elements like training, help desks, and approval policies are not core governance components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A formal IT risk management process integrated with enterprise risk management

    Why this is correct

    IT risk management is critical for identifying, assessing, and mitigating risks that could impact business objectives. Integration with enterprise risk management ensures that IT risks are considered in the broader organizational context. The auditor should verify that risk assessments are performed regularly, risk appetite is defined, and mitigation strategies are implemented. This process helps the organization avoid surprises and ensures that IT governance is proactive rather than reactive, aligning with frameworks like COBIT and ISO 27001.

  • ✓

    IT strategic planning aligned with business objectives

    Why this is correct

    IT strategic planning ensures that IT initiatives support business goals. Without alignment, IT investments may not deliver value and could even hinder business performance. The auditor should verify that the IT strategy is formally documented, approved by executives, and integrated with business planning processes. This alignment is a cornerstone of effective IT governance, as it directs IT resources toward achieving organizational objectives and provides a basis for measuring IT performance.

  • ✗

    A centralized help desk with 24/7 support for all IT issues

    Why it's wrong here

    A help desk is an operational support function, not a governance component. While it contributes to service delivery, it does not establish governance direction or oversight. The auditor should not confuse operational efficiency with governance effectiveness. Governance components include strategic planning, risk management, performance measurement, and resource management. A help desk may be part of IT service management, but it is not essential for governance, and its absence would not necessarily indicate a governance failure.

  • ✗

    Detailed technical training for all IT staff on emerging technologies

    Why it's wrong here

    While technical training is beneficial, it is not an essential component of an IT governance framework. Governance focuses on direction, oversight, and value delivery, not on specific technical skills. The auditor should prioritize governance structures and processes over operational training. Training may support governance indirectly, but its absence does not constitute a governance deficiency. The essential components are those that establish accountability, alignment, and risk management.

  • ✗

    A policy requiring all software purchases to be approved by the CIO

    Why it's wrong here

    While approval policies can be part of governance, a blanket requirement for CIO approval of all software purchases is not an essential component and may even be impractical. Governance focuses on frameworks and oversight, not on specific approval workflows. The auditor should look for broader elements like IT strategy, risk management, and performance measurement. This option is too narrow and operational to be considered a core governance component, and its presence or absence does not determine governance effectiveness.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.