CISA - Information Systems Operations and Business Resilience - Section 4.1

Evaluate IT components, IT asset management and end-user computing including shadow IT.

Recognise the hardware, software and network components that make up an IS environment and the asset management lifecycle used to track them. Evaluate end-user computing risks and the control challenges posed by shadow IT, where business units deploy unsanctioned applications outside IT oversight.

IT componentsIT asset managementshadow ITend-user computing

Practice question for this objective

Free sampleInformation Systems Operations and Business Resilienceeasy

An IS auditor is reviewing the IT asset management process at a logistics firm and finds that the configuration management database (CMDB) records hardware ownership, location, and warranty status, while the software asset register records licence entitlements and deployment counts. Which statement BEST describes how these two records should relate within a mature IT asset management programme?

  • AThe software asset register should be reconciled against the CMDB so that entitlements are compared with deployments and unsupported or unlicensed software is identified. Correct
  • BThe CMDB should replace the software asset register because configuration items already include installed software components and their version data.
  • CThe two records should remain independent to preserve segregation of duties between operations staff who maintain the CMDB and procurement staff who maintain the licence register.
  • DThe CMDB should be updated only when a software audit by the vendor is announced, so that the operational record matches the entitlement position at that moment.
Recognise that periodic reconciliation between the software asset register and the CMDB is the primary control for identifying licensing and deployment exposures. Software asset management relies on comparing contractual entitlements with actual deployments. The software asset register captures rights granted by licences, while the CMDB captures the operational footprint. Without reconciliation, an organisation cannot evidence licence compliance, plan renewals, or detect unsupported software that increases security and continuity risk.

Why A is correct: Reconciling entitlements held in the software asset register against deployment data in the CMDB is the recognised control that surfaces under-licensing, over-licensing, and unsupported versions, satisfying both audit and compliance objectives.

Why B is wrong: This is tempting because the CMDB does record installed software as configuration items; however, a CMDB tracks operational state for service management, not licence entitlements or contractual rights, so it cannot satisfy software asset management obligations on its own.

Why C is wrong: Segregation of duties applies to who can authorise and record asset changes, not to whether two registers may be reconciled; keeping the records permanently disconnected defeats the purpose of asset management.

Why D is wrong: Updating the CMDB only in response to vendor audits is reactive and undermines day-to-day service management; the CMDB must reflect the current operational state continuously, regardless of audit timing.

See more CISA practice questions, answers explained.

More in this domain

Back to all Information Systems Operations and Business Resilience objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.