ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium

A CISA is reviewing an organization's IT asset management practices. The CISA observes that while hardware assets are meticulously tracked from acquisition to disposal, there is no formal process for managing software licenses, including procurement, deployment, and decommissioning. What is the MOST significant risk posed by this oversight?

  1. AIncreased vulnerability to cyberattacks from outdated software.
  2. BInefficient allocation of IT resources for software development.
  3. CLegal non-compliance and financial penalties from license violations.
  4. DDifficulty in conducting effective IT audits.
Show answer & explanation

Correct answer: C. Legal non-compliance and financial penalties from license violations.

Lack of formal software license management significantly increases the risk of legal non-compliance. Organizations can face substantial fines and legal action from software vendors for under-licensing, using unauthorized software, or failing to adhere to license terms. This also leads to unnecessary expenditure on over-licensing.

Why the other options are wrong

  • A. Outdated software is a security risk, but the core issue of *license management* is about compliance and cost, not solely security updates.
  • B. Inefficient resource allocation is a consequence, but legal and financial penalties are a more critical and direct risk of this oversight.
  • D. While it can complicate audits, the direct and more severe risk is legal and financial.

Software Asset Management (SAM)

The practice of managing and optimizing the purchase, deployment, maintenance, utilization, and disposal of software applications within an organization.

  • Ensures legal compliance with licensing agreements.
  • Optimizes software spending and reduces costs.
  • Provides visibility into software inventory and usage.

Memory trick: SAM 'SAVES' an organization from 'S'oftware 'A'udits and 'M'ismanagement.

More Domain 2: Governance and Management of IT questions