Courseiva

CISA Governance and Management of IT Practice Question

An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?

⚠ Common exam trap

CISA often tests the difference between governance structures (steering committees) and operational activities (budgeting, reviews), tempting candidates to pick a tactical-sounding option that lacks ongoing business involvement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish an IT steering committee with business representation

An IT steering committee with business representation is the best approach because it creates a formal, ongoing governance mechanism where business and IT leaders jointly prioritize investments, review performance, and make strategic decisions. This ensures IT strategy is continuously aligned with business goals rather than being set in isolation. COBIT and ISO/IEC 38500 both emphasize such cross-functional governance bodies as the primary vehicle for strategic alignment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Align IT budget with the previous year's business plan

    Why it's wrong here

    Aligning the IT budget to the previous year's business plan funds past priorities rather than current business goals, so IT investment cannot support the new strategy. It is tempting because historical budget baselines are a legitimate financial planning input, and this would work where business plans are genuinely static year on year.

  • ✗

    Conduct annual IT strategy reviews independent of business cycles

    Why it's wrong here

    Reviewing IT strategy annually and independently of business cycles decouples IT planning from the business planning cycle, so IT priorities cannot respond to changing business objectives. It is tempting because periodic reviews are a genuine governance control, and this would suit a stable organisation whose business planning also runs on a fixed annual cycle.

  • ✓

    Establish an IT steering committee with business representation

    Why this is correct

    An IT steering committee with business representation provides the joint decision-making forum where IT strategy is shaped against business goals, satisfying the alignment requirement directly. It creates shared ownership and prioritisation rather than leaving strategy to IT alone.

  • ✗

    Delegate IT strategy to the CIO without business input

    Why it's wrong here

    Delegating IT strategy to the CIO without business input removes the shared ownership and business representation that alignment requires, so IT goals cannot be traced to business objectives. It is tempting because the CIO owns IT delivery and technical direction, and this would fit a purely operational IT function rather than enterprise governance.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.