CISA - Governance and Management of IT - Section 2.1

Evaluate IT governance, organisational structure and IT strategy against applicable laws, regulations and industry standards.

Describe the key components of IT governance and how organisational structure and IT strategy should align with applicable laws, regulations and industry standards. Evaluate whether a given governance arrangement meets those requirements and identify gaps.

laws and regulationsIT governanceorganisational structureIT strategyindustry standards

Practice question for this objective

Free sampleGovernance and Management of ITmedium

An IS auditor is reviewing the IT steering committee charter of a publicly listed Australian company. The charter lists the chief information officer as chair, the head of infrastructure as secretary, and three operational managers as voting members. No business unit head, finance representative, or non-executive director is included. Senior management argues that this composition is efficient because every member understands technology. What is the BEST response by the IS auditor?

  • AConclude that the steering committee composition does not enable business-IT alignment and recommend the inclusion of business and finance representation with appropriate oversight from governance. Correct
  • BAccept the composition because all voting members hold senior positions and bring deep technical knowledge that is essential for evaluating proposed investments in core platforms.
  • CAccept the composition on condition that meeting minutes are circulated promptly to the executive team and that an annual report on committee decisions is presented to the audit committee.
  • DRecommend that the IS audit function take a permanent voting seat on the steering committee to ensure that audit considerations directly influence each investment decision taken by the group.
Evaluate IT steering committee composition against the requirement to align IT investment with enterprise strategy under recognised governance frameworks. ISO/IEC 38500 places the steering function at the intersection of business direction and IT delivery, and COBIT 2019 EDM01 expects governance bodies to reflect stakeholder needs. Membership without business and finance voices cannot deliver this alignment, so the IS auditor should recommend a balanced composition rather than accept a technically literate but unrepresentative committee.

Why A is correct: COBIT 2019 and ISO/IEC 38500 both expect the steering committee to balance business and IT perspectives so that investment decisions reflect enterprise direction. A committee dominated by IT cannot evidence that balance, which is a reportable governance finding.

Why B is wrong: Technical depth alone does not deliver enterprise alignment. The role of the steering committee is to ensure IT investments serve business priorities, so an all-IT membership cannot demonstrate that perspective.

Why C is wrong: Better communication of decisions does not correct an unbalanced decision-making body. The defect lies in who participates in the vote, not in how the outcomes are reported afterwards.

Why D is wrong: A voting role would compromise the IS auditor's independence, because the auditor would later be assessing decisions in which the auditor participated. ISACA standards expressly limit such direct involvement in management decisions.

See more CISA practice questions, answers explained.

More in this domain

Back to all Governance and Management of IT objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.