ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITHard

A CISA is auditing an organization's IT organizational structure. The CISA observes that the IT department reports directly to the Chief Financial Officer (CFO). While the CFO is highly effective in financial management, they have limited understanding of complex IT security and operational risks. What is the MOST significant concern for the organization's IT governance?

  1. ACommunication between IT and other business units may be inefficient.
  2. BThe IT department may struggle to recruit and retain specialized security talent.
  3. CThe IT department may face budget cuts due to the CFO's focus on cost control.
  4. DIT strategic decisions may not adequately address critical security and operational risks.
Show answer & explanation

Correct answer: D. IT strategic decisions may not adequately address critical security and operational risks.

Effective IT governance requires leadership with a comprehensive understanding of IT's strategic value and associated risks. If the head of IT's reporting line is to a CFO with limited understanding of IT security and operational risks, strategic IT decisions, especially concerning risk mitigation and security investments, may be undervalued or misdirected, leaving the organization vulnerable.

Why the other options are wrong

  • A. Communication issues are operational, whereas the direct reporting structure impacts strategic decision-making and risk posture.
  • B. Recruitment is an HR challenge, not the primary governance concern regarding risk management oversight.
  • C. Budget cuts are a possibility, but the more fundamental governance concern is the lack of informed decision-making regarding risk.

IT Reporting Structure Impact

The reporting structure of the IT department significantly influences the organization's ability to integrate IT strategy with business objectives and manage IT risks effectively, depending on the reporting executive's understanding of IT.

  • Reporting executive's expertise impacts IT governance quality.
  • Influences IT's strategic alignment and risk management.
  • Should ensure IT risks are understood at a senior level.

Memory trick: A financial captain can steer the ship, but a tech captain knows the cyber-storms.

More Domain 2: Governance and Management of IT questions