CISA Governance and Management of IT Practice Question
An IT manager is developing a governance policy for change management. Which element is MOST important to include?
⚠ Common exam trap
CISA often tests the distinction between governance (strategic, accountability-focused) and management (tactical, procedure-focused), so candidates may mistakenly choose detailed technical procedures or project management methodology as the most important element, overlooking that governance is fundamentally about roles and responsibilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Roles and responsibilities
Roles and responsibilities are the cornerstone of any governance policy because they establish accountability and authority for change approval, implementation, and review. Without clearly defined roles (e.g., change manager, change advisory board, implementer), even well-documented procedures lack ownership and enforcement. Governance is about decision rights and accountability, not operational details. Thus, defining who is responsible for what is the most critical element to include.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Project management methodology
Why it's wrong here
A delivery methodology governs how projects are run, not how changes are authorised, classified and approved. It is tempting because change requests often originate within projects, and would be correct when defining project delivery standards, but it supplies no approval authority or change categorisation for the policy.
- ✗
Detailed technical procedures
Why it's wrong here
Technical procedures describe how to implement a change, not the governance controls determining who may approve it and under what authority. They are tempting because operators rely on them daily, and would be correct for an operational runbook, but a governance policy requires roles, approval thresholds and change categorisation instead.
- ✗
List of all applications
Why it's wrong here
List of all applications is incorrect because listing applications is operational.
- ✓
Roles and responsibilities
Why this is correct
Roles and responsibilities define who may authorise, implement and verify each change, directly satisfying the governance requirement for accountability and segregation of duties. Without assigned ownership, approval controls cannot be enforced or audited, leaving changes unmanaged. This makes it the most important element for a change management governance policy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.