ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium
A CISA is evaluating an organization's IT governance framework. The CISA observes that while the IT department has defined clear roles and responsibilities for system administration, there is no formal mechanism for business units to provide input or approve IT service levels and priorities. Which of the following is the MOST likely consequence of this observation?
- AHigher risk of security breaches due to unchecked IT activity.
- BDifficulty in attracting and retaining IT talent.
- CIncreased operational overhead within the IT department.
- DMisalignment between IT services and business needs.
Show answer & explanationAnswer & explanation
Correct answer: D. Misalignment between IT services and business needs.
Without a formal mechanism for business units to provide input and approve IT service levels and priorities, IT decisions may not reflect the actual needs and strategic objectives of the business. This leads to a disconnect where IT services might not adequately support critical business functions, resulting in misalignment.
Why the other options are wrong
- A. While unchecked IT activity can pose risks, the specific observation points more directly to issues with aligning IT services with business priorities, rather than security breaches.
- B. Talent retention is not a direct consequence of a lack of business input into IT service levels.
- C. Operational overhead is less direct than the fundamental issue of IT-business misalignment.
IT-Business Alignment
The process of ensuring that IT strategies, services, and investments are consistent with and support the overall business goals and objectives of an organization.
- Crucial for maximizing value from IT investments.
- Requires formal communication channels between IT and business.
- Ensures IT resources are prioritized based on business needs.
Memory trick: Align IT and Business to 'SYN'chronize Success.