ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium

A CISA is evaluating the effectiveness of an organization's IT governance structure. The CISA observes that the IT department consistently implements new technologies without formal approval from a cross-functional steering committee, despite such a committee being documented in the governance framework. What is the MOST likely consequence of this situation?

  1. AReduced employee morale within the IT department.
  2. BMisalignment of IT investments with business strategy.
  3. CDifficulty in attracting and retaining skilled IT personnel.
  4. DIncreased IT operational costs due to redundant systems.
Show answer & explanation

Correct answer: B. Misalignment of IT investments with business strategy.

If IT implements new technologies without formal cross-functional approval, it indicates a lack of effective governance oversight. This bypasses the mechanism designed to ensure IT projects align with overall business objectives, leading to potential investments in technologies that do not support strategic goals or create unintended business risks.

Why the other options are wrong

  • A. Employee morale is a human resources issue, not the primary consequence of a breakdown in IT governance approval processes.
  • C. Personnel issues are generally separate from the direct consequences of IT governance failures regarding project approval.
  • D. Redundant systems are a possible outcome, but the core issue is the breakdown in strategic alignment that causes such inefficiencies.

IT Governance Effectiveness

The degree to which an organization's IT governance framework successfully ensures that IT delivers value, manages risks, and aligns with business objectives.

  • Requires active engagement from leadership.
  • Involves clear roles and responsibilities.
  • Measured by achievement of strategic goals.

Memory trick: Ignoring the steering committee means IT is driving blind, off the business road.

More Domain 2: Governance and Management of IT questions