hardMultiple Choice
CISA Practice Question: An IS auditor is performing a review of an…
An IS auditor is performing a review of an organization's IT governance framework. Which of the following findings would be of MOST concern?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No documented IT strategy aligned with business strategy
The absence of a documented IT strategy aligned with the business strategy is the most critical governance finding. Without strategic alignment, IT decisions may not support business objectives, making all other controls less effective. Option B (incomplete project portfolio management) is tactical and can be addressed after strategic alignment. Option C (lack of an IT steering committee) is a structural issue but not as fundamental as lack of strategy. Option D (absence of an enterprise-wide information security policy) is operational and less strategic than the alignment issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
No documented IT strategy aligned with business strategy
Why this is correct
Without a documented IT strategy aligned to business strategy, IT investments lack direction and governance oversight, so alignment between IT and business objectives cannot be demonstrated or measured. This is the most fundamental governance failure, outweighing operational or documentation gaps.
- ✗
Incomplete IT project portfolio management
Why it's wrong here
Incomplete portfolio management is a maturity gap affecting optimisation across projects, but governance concerns centre on decision rights, accountability and oversight of IT. It would be the primary finding where the audit scope specifically covers investment prioritisation and portfolio value delivery.
- ✗
Lack of an IT steering committee
Why it's wrong here
A steering committee is a governance oversight mechanism, but its absence alone does not directly expose information assets; the missing enterprise-wide security policy leaves controls undefined and unenforced. The option tempts because steering committees are governance hallmarks, yet they are advisory rather than a direct control gap.
- ✗
Absence of an enterprise-wide information security policy
Why it's wrong here
An enterprise-wide information security policy is a foundational governance control, but its absence is a common finding that can be remediated; the auditor's greatest concern is typically the absence of an IT governance framework or steering committee. The policy is tempting because it is security-related, yet governance structure is the higher concern.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.