CISA Governance and Management of IT Practice Question
An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation, and success depends on individual heroics. Which of the following maturity levels BEST describes this situation?
⚠ Common exam trap
A common mix-up: candidates confuse Level 1 with Level 0; Level 0 means processes are not performed at all, while Level 1 means they are performed but informally.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Level 1 – Initial
COBIT 2019 defines maturity levels from 0 to 5. Level 1 (Initial) is assigned when processes are ad hoc and undocumented, and success depends on individual competence. This matches the scenario precisely. Higher levels require increasing degrees of planning, documentation, and standardization, which are not present here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Level 3 – Defined
Why it's wrong here
Level 3 requires documented and standardized processes, which are communicated and understood. The scenario explicitly states there is no formal documentation, so it cannot be Level 3. Defined processes are repeatable and consistent, not ad hoc.
- ✗
Level 0 – Incomplete
Why it's wrong here
Level 0 indicates that processes are not implemented at all or fail to achieve their purpose. Here, processes exist but are ad hoc and rely on individuals, meaning some work is being done, albeit inconsistently. Therefore, it is not Level 0 but Level 1.
- ✗
Level 2 – Managed
Why it's wrong here
Level 2 involves processes that are planned, monitored, and adjusted, with some documentation. In this scenario, there is no formal documentation or planning, so it does not meet Level 2 criteria. Level 2 requires basic management controls, which are absent here.
- ✓
Level 1 – Initial
Why this is correct
Level 1 in COBIT 2019 is characterized by ad hoc processes, lack of documentation, and reliance on individual efforts. The scenario describes exactly this: no formal processes and success dependent on heroics. This is the lowest maturity level, indicating that governance is unstructured and unpredictable.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.