Courseiva

CISA Governance and Management of IT Practice Question

An IT manager is developing a governance policy for change management. Which element is MOST important to include?

⚠ Common exam trap

CISA often tests the distinction between governance (strategic, accountability-focused) and management (tactical, procedure-focused), so candidates may mistakenly choose detailed technical procedures or project management methodology as the most important element, overlooking that governance is fundamentally about roles and responsibilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Roles and responsibilities

Roles and responsibilities are the cornerstone of any governance policy because they establish accountability and authority for change approval, implementation, and review. Without clearly defined roles (e.g., change manager, change advisory board, implementer), even well-documented procedures lack ownership and enforcement. Governance is about decision rights and accountability, not operational details. Thus, defining who is responsible for what is the most critical element to include.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Project management methodology

    Why it's wrong here

    A delivery methodology governs how projects are run, not how changes are authorised, classified and approved. It is tempting because change requests often originate within projects, and would be correct when defining project delivery standards, but it supplies no approval authority or change categorisation for the policy.

  • ✗

    Detailed technical procedures

    Why it's wrong here

    Technical procedures describe how to implement a change, not the governance controls determining who may approve it and under what authority. They are tempting because operators rely on them daily, and would be correct for an operational runbook, but a governance policy requires roles, approval thresholds and change categorisation instead.

  • ✗

    List of all applications

    Why it's wrong here

    List of all applications is incorrect because listing applications is operational.

  • ✓

    Roles and responsibilities

    Why this is correct

    Roles and responsibilities define who may authorise, implement and verify each change, directly satisfying the governance requirement for accountability and segregation of duties. Without assigned ownership, approval controls cannot be enforced or audited, leaving changes unmanaged. This makes it the most important element for a change management governance policy.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.