โ† All CISA Flashcard Decks

IT Governance and Strategy Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 IT Governance and Strategy flashcards as text
  1. An organization wants to improve IT governance maturity from level 2 to level 3 on a five-level scale. This MOST likely requires:

    Answer: Formalizing and documenting processes consistently across the organization

    Moving from maturity level 2 (repeatable but intuitive) to level 3 (defined process) requires formalizing, documenting, and standardizing processes organization-wide.

  2. Which of the following scenarios BEST demonstrates effective IT governance?

    Answer: The board reviews quarterly IT performance dashboards and adjusts strategy accordingly

    Board-level review of IT performance metrics with strategic adjustment demonstrates the evaluate-direct-monitor cycle central to effective IT governance.

  3. In the COBIT framework, which domain is MOST directly concerned with IT governance rather than IT management?

    Answer: Evaluate, Direct, and Monitor (EDM)

    The EDM (Evaluate, Direct, and Monitor) domain in COBIT 2019 represents governance processes, while other domains represent management processes.

  4. A company has strong IT controls but no formal IT governance structure. The MOST likely consequence is:

    Answer: IT controls may not address the right risks or business priorities

    Without governance directing which risks matter most, even strong controls may protect against the wrong threats while leaving strategic risks unaddressed.

  5. Which of the following is MOST important when defining IT governance roles and responsibilities?

    Answer: Clearly defining decision rights, accountability, and escalation paths

    Effective governance requires that decision rights, accountability, and escalation procedures be unambiguously defined so that the right decisions are made at the right level.

  6. An auditor is assessing whether IT investments are governed effectively. The BEST evidence would be:

    Answer: Board-approved IT investment portfolio with documented business cases and post-implementation reviews

    A board-approved investment portfolio with business cases and post-implementation reviews demonstrates that IT investments are selected, authorized, and evaluated against expected benefits.

  7. When IT governance is described as 'principle-based' rather than 'rule-based,' it means:

    Answer: Decision-makers use overarching principles to guide judgments rather than following a rigid checklist

    Principle-based governance empowers decision-makers to apply judgment guided by core principles, enabling flexible responses to diverse situations rather than rigid rule compliance.