CISA Governance and Management of IT Practice Question
An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?
⚠ Common exam trap
CISA often tests the difference between governance structures (steering committees) and operational activities (budgeting, reviews), tempting candidates to pick a tactical-sounding option that lacks ongoing business involvement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish an IT steering committee with business representation
An IT steering committee with business representation is the best approach because it creates a formal, ongoing governance mechanism where business and IT leaders jointly prioritize investments, review performance, and make strategic decisions. This ensures IT strategy is continuously aligned with business goals rather than being set in isolation. COBIT and ISO/IEC 38500 both emphasize such cross-functional governance bodies as the primary vehicle for strategic alignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Align IT budget with the previous year's business plan
Why it's wrong here
Aligning the IT budget to the previous year's business plan funds past priorities rather than current business goals, so IT investment cannot support the new strategy. It is tempting because historical budget baselines are a legitimate financial planning input, and this would work where business plans are genuinely static year on year.
- ✗
Conduct annual IT strategy reviews independent of business cycles
Why it's wrong here
Reviewing IT strategy annually and independently of business cycles decouples IT planning from the business planning cycle, so IT priorities cannot respond to changing business objectives. It is tempting because periodic reviews are a genuine governance control, and this would suit a stable organisation whose business planning also runs on a fixed annual cycle.
- ✓
Establish an IT steering committee with business representation
Why this is correct
An IT steering committee with business representation provides the joint decision-making forum where IT strategy is shaped against business goals, satisfying the alignment requirement directly. It creates shared ownership and prioritisation rather than leaving strategy to IT alone.
- ✗
Delegate IT strategy to the CIO without business input
Why it's wrong here
Delegating IT strategy to the CIO without business input removes the shared ownership and business representation that alignment requires, so IT goals cannot be traced to business objectives. It is tempting because the CIO owns IT delivery and technical direction, and this would fit a purely operational IT function rather than enterprise governance.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.