← All CISA Flashcard Decks

IT Governance and Strategy Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 IT Governance and Strategy flashcards as text
  1. When reviewing IT governance, an auditor discovers that business units independently purchase software without IT involvement. This PRIMARILY indicates a weakness in:

    Answer: IT demand management and governance oversight

    Shadow IT (business units procuring technology without IT oversight) signals a breakdown in IT demand management and governance authority.

  2. A CISA auditing IT strategy would MOST likely review which document to assess strategic alignment?

    Answer: IT strategic plan compared against the enterprise strategic plan

    Comparing the IT strategic plan to the enterprise strategic plan directly reveals whether IT goals are aligned with organizational objectives.

  3. Which of the following is an example of an IT governance output?

    Answer: An approved IT policy defining acceptable use

    IT governance outputs include policies, principles, frameworks, and accountability structures—not day-to-day operational activities like patching or backups.

  4. In IT governance, the concept of 'accountability' differs from 'responsibility' in that accountability:

    Answer: Rests with one individual who answers for the final outcome

    Accountability is singular and non-delegable—one person ultimately answers for an outcome—while responsibility can be shared or delegated.

  5. Which of the following BEST characterizes an IT governance framework versus an IT management framework?

    Answer: Governance sets direction and evaluates performance; management plans and operates

    Governance defines the direction, evaluates outcomes, and ensures accountability, while management handles planning, building, running, and monitoring IT activities.

  6. An auditor finds that IT project prioritization is done solely by the IT department without business input. The GREATEST risk of this practice is:

    Answer: IT projects may not align with business strategic priorities

    Without business input, IT prioritization may fund technically attractive but strategically irrelevant projects, undermining the value of IT investments.

  7. The PRIMARY purpose of IT governance performance metrics is to:

    Answer: Provide management with objective evidence for informed decision-making

    IT governance metrics give management quantitative and qualitative evidence about IT performance, enabling informed decisions about resource allocation and risk.