ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITEasy
During an audit of an organization's IT governance structure, the CISA observes that the IT department frequently initiates projects without formal approval from business units, leading to scope creep and unmet business expectations. Which of the following is the MOST significant implication of this observation?
- ALack of alignment between IT initiatives and business objectives.
- BDifficulty in tracking project progress and reporting to stakeholders.
- CPotential for security vulnerabilities in hastily developed systems.
- DIncreased operational costs due to inefficient resource allocation.
Show answer & explanationAnswer & explanation
Correct answer: A. Lack of alignment between IT initiatives and business objectives.
When IT projects are initiated without formal business unit approval, it indicates a fundamental breakdown in the alignment between IT and the business. This directly leads to projects that may not support strategic organizational goals, making lack of alignment the most significant implication.
Why the other options are wrong
- B. Difficulty in tracking progress is a project management issue, but the lack of formal approval points to a more fundamental governance failure regarding strategic direction.
- C. Security vulnerabilities are a potential risk in any project, but the primary and most direct implication of unapproved projects is the lack of business relevance.
- D. While increased costs can result, it is a symptom of the deeper problem of misaligned objectives.
IT-Business Alignment
The process of ensuring that IT strategies, initiatives, and operations are integrated with and support the organization's overarching business goals and objectives.
- Crucial for maximizing IT value.
- Requires strong governance and communication.
- Prevents IT projects from becoming 'solutions looking for a problem'.
Memory trick: Govern well, business thrives, IT aligns.