Courseiva
easyMultiple Choice

CISA Practice Question: Is a key principle of corporate governance of IT…

Which of the following is a key principle of corporate governance of IT according to ISO/IEC 38500?

⚠ Common exam trap

Test-takers frequently confuse the principles of specific IT management frameworks (like Agile, ITIL, or COBIT) with the high-level corporate governance principles defined in ISO/IEC 38500, leading them to select a familiar-sounding but incorrect option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Responsibility

ISO/IEC 38500 defines six key principles for the corporate governance of IT: Responsibility, Strategy, Acquisition, Performance, Conformance, and Human Behaviour. The 'Responsibility' principle mandates that individuals and groups within the organization understand and accept their responsibilities for the supply of, and demand for, IT. This is the foundational governance principle because it establishes clear accountability, which is necessary for all other governance activities to function effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Progress iteratively

    Why it's wrong here

    ISO/IEC 38500 principles are evaluate, direct, and monitor; iterative progress belongs to ITIL or agile delivery. It is tempting because iterative working is a genuine service-management practice, which would be correct if the question asked about continual improvement rather than board-level governance.

  • ✗

    Optimize and automate

    Why it's wrong here

    ISO/IEC 38500's principles are responsibility, strategy, acquisition, performance, conformance and human behaviour. Optimise and automate belongs to ITIL's four dimensions, so it addresses service management practise rather than board-level governance of IT direction and accountability.

  • ✗

    Focus on value

    Why it's wrong here

    ISO/IEC 38500 lists responsibility, strategy, acquisition, performance, conformance, and human behaviour; value focus is not one of them. It is tempting because value delivery is a recognised governance outcome, which would be correct if the question asked about COBIT objectives rather than 38500 principles.

  • ✓

    Responsibility

    Why this is correct

    Responsibility is a core ISO/IEC 38500 principle, requiring that individuals and groups within the organisation understand and accept their responsibilities for IT supply and demand. It directly satisfies the stem's requirement by naming the governance principle governing accountability for IT.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.