ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITHard
A CISA is evaluating an organization's IT governance framework. The CISA observes that the framework emphasizes compliance with external regulations (e.g., GDPR, HIPAA) but provides minimal guidance on internal control objectives for IT operations. Which of the following is the MOST significant risk resulting from this imbalance?
- AFailure to achieve strategic IT objectives despite regulatory adherence.
- BInadequate protection of organizational assets from internal threats.
- CDifficulty in attracting and retaining skilled IT personnel.
- DIncreased cost of external audits due to focus on compliance.
Show answer & explanationAnswer & explanation
Correct answer: B. Inadequate protection of organizational assets from internal threats.
While external compliance is crucial, a lack of internal control objectives means that day-to-day IT operations may not have adequate safeguards to protect organizational assets (data, systems, infrastructure) from internal errors, negligence, or malicious acts, which are often significant sources of risk.
Why the other options are wrong
- A. Strategic objectives are important, but the immediate and direct impact of weak internal controls is on the protection of assets, which is a foundational aspect of IT governance.
- C. Personnel attraction/retention is a human resources issue, not the direct outcome of this governance imbalance.
- D. Audit cost is a secondary concern; the primary risk is operational failure and asset loss.
Internal Control Objectives
Internal control objectives for IT operations define the desired state for the security, integrity, availability, and efficiency of information systems and data within an organization.
- Guides daily IT activities.
- Protects organizational assets.
- Forms the basis for internal audits.
Memory trick: Balance 'EXTERNAL' rules with 'INTERNAL' controls to shield assets.