Courseiva
hardMultiple Choice

CISA Practice Question: An IS auditor is performing a review of an…

An IS auditor is performing a review of an organization's IT governance framework. Which of the following findings would be of MOST concern?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No documented IT strategy aligned with business strategy

The absence of a documented IT strategy aligned with the business strategy is the most critical governance finding. Without strategic alignment, IT decisions may not support business objectives, making all other controls less effective. Option B (incomplete project portfolio management) is tactical and can be addressed after strategic alignment. Option C (lack of an IT steering committee) is a structural issue but not as fundamental as lack of strategy. Option D (absence of an enterprise-wide information security policy) is operational and less strategic than the alignment issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    No documented IT strategy aligned with business strategy

    Why this is correct

    Without a documented IT strategy aligned to business strategy, IT investments lack direction and governance oversight, so alignment between IT and business objectives cannot be demonstrated or measured. This is the most fundamental governance failure, outweighing operational or documentation gaps.

  • ✗

    Incomplete IT project portfolio management

    Why it's wrong here

    Incomplete portfolio management is a maturity gap affecting optimisation across projects, but governance concerns centre on decision rights, accountability and oversight of IT. It would be the primary finding where the audit scope specifically covers investment prioritisation and portfolio value delivery.

  • ✗

    Lack of an IT steering committee

    Why it's wrong here

    A steering committee is a governance oversight mechanism, but its absence alone does not directly expose information assets; the missing enterprise-wide security policy leaves controls undefined and unenforced. The option tempts because steering committees are governance hallmarks, yet they are advisory rather than a direct control gap.

  • ✗

    Absence of an enterprise-wide information security policy

    Why it's wrong here

    An enterprise-wide information security policy is a foundational governance control, but its absence is a common finding that can be remediated; the auditor's greatest concern is typically the absence of an IT governance framework or steering committee. The policy is tempting because it is security-related, yet governance structure is the higher concern.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.