CISA - Governance and Management of IT (18% of the exam) - Section 2.1

Evaluate IT governance, organisational structure and IT strategy against applicable laws, regulations and industry standards.

Describe the key components of IT governance and how organisational structure and IT strategy should align with applicable laws, regulations and industry standards. Evaluate whether a given governance arrangement meets those requirements and identify gaps.

laws and regulationsIT governanceorganisational structureIT strategyindustry standards

Practice question for this objective

Free sampleGovernance and Management of ITmedium

An IS auditor is reviewing the IT steering committee charter of a publicly listed Australian company. The charter lists the chief information officer as chair, the head of infrastructure as secretary, and three operational managers as voting members. No business unit head, finance representative, or non-executive director is included. Senior management argues that this composition is efficient because every member understands technology. What is the BEST response by the IS auditor?

  • AConclude that the steering committee composition does not enable business-IT alignment and recommend the inclusion of business and finance representation with appropriate oversight from governance. Correct
  • BAccept the composition because all voting members hold senior positions and bring deep technical knowledge that is essential for evaluating proposed investments in core platforms.
  • CAccept the composition on condition that meeting minutes are circulated promptly to the executive team and that an annual report on committee decisions is presented to the audit committee.
  • DRecommend that the IS audit function take a permanent voting seat on the steering committee to ensure that audit considerations directly influence each investment decision taken by the group.
Evaluate IT steering committee composition against the requirement to align IT investment with enterprise strategy under recognised governance frameworks. ISO/IEC 38500 places the steering function at the intersection of business direction and IT delivery, and COBIT 2019 EDM01 expects governance bodies to reflect stakeholder needs. Membership without business and finance voices cannot deliver this alignment, so the IS auditor should recommend a balanced composition rather than accept a technically literate but unrepresentative committee.

Why A is correct: COBIT 2019 and ISO/IEC 38500 both expect the steering committee to balance business and IT perspectives so that investment decisions reflect enterprise direction. A committee dominated by IT cannot evidence that balance, which is a reportable governance finding.

Why B is wrong: Technical depth alone does not deliver enterprise alignment. The role of the steering committee is to ensure IT investments serve business priorities, so an all-IT membership cannot demonstrate that perspective.

Why C is wrong: Better communication of decisions does not correct an unbalanced decision-making body. The defect lies in who participates in the vote, not in how the outcomes are reported afterwards.

Why D is wrong: A voting role would compromise the IS auditor's independence, because the auditor would later be assessing decisions in which the auditor participated. ISACA standards expressly limit such direct involvement in management decisions.

See more CISA practice questions, answers explained.

Exam traps in Governance and Management of IT

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • Document the obsolete reference as an observation in the working papers and defer further action until the planned strategy refresh, then track it as part of the closing programme review.

    Why it is wrong: Deferral is plausible because the refresh is scheduled, but the auditor cannot accept eighteen months of misalignment with a mandatory industry standard. The exposure to non-compliance during that period is a current risk, not a future one.

  • ISO/IEC 27001 is used as the primary criterion for evaluating board-level direction and monitoring of IT across the enterprise.

    Why it is wrong: ISO/IEC 27001 specifies the requirements for an information security management system; using it as the governance criterion confuses an ISMS standard with a governance standard.

  • The chief information security officer reports administratively to the head of network operations and functionally to the chief information officer.

    Why it is wrong: Reporting into operations creates a conflict because security would be subordinate to the team whose work it is meant to assess; this is a common but flawed structure used as a distractor.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.