ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITEasy

An organization has recently implemented a new IT governance framework. During an audit, the CISA observes that while the framework defines clear roles and responsibilities for IT decision-making, there is a lack of communication channels and processes for escalating IT-related risks and issues to senior management. Which of the following areas of the IT governance structure is MOST likely to be ineffective?

  1. AResource Management
  2. BPerformance Measurement
  3. CRisk Management
  4. DStrategic Alignment
Show answer & explanation

Correct answer: C. Risk Management

The lack of communication channels and processes for escalating IT-related risks and issues directly impacts the organization's ability to effectively manage and respond to risks, making risk management the most affected area.

Why the other options are wrong

  • A. Resource management deals with allocating IT resources, which is a separate concern from risk escalation.
  • B. Performance measurement focuses on monitoring IT service delivery, not the escalation of risks themselves.
  • D. Strategic alignment ensures IT supports business goals, which is not directly impacted by risk escalation issues.

IT Governance Risk Management

IT governance includes establishing frameworks and processes for identifying, assessing, mitigating, and monitoring IT-related risks to support business objectives.

  • Requires clear risk escalation paths.
  • Integrates IT risk into enterprise risk management.
  • Ensures timely decision-making on IT risks.

Memory trick: IT Governance 'SARP's' its way to success: Strategic, Acquisition, Risk, Performance.

More Domain 2: Governance and Management of IT questions