ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITHard

A CISA is reviewing an organization's IT risk management framework. The CISA notes that while the organization has identified numerous IT risks, the risk register lacks a consistent methodology for quantifying potential financial impacts or likelihood of occurrence, and risk appetite is not clearly defined. What is the MOST significant consequence of this deficiency for IT governance?

  1. ARegulatory compliance fines may increase due to unmanaged risks.
  2. BOperational IT staff will be unable to prioritize daily tasks effectively.
  3. CIT management may allocate excessive resources to low-impact risks.
  4. DThe organization's board may struggle to make informed strategic decisions regarding IT investments.
Show answer & explanation

Correct answer: D. The organization's board may struggle to make informed strategic decisions regarding IT investments.

Effective IT governance, especially at the board level, relies on clear, quantifiable risk information to make strategic decisions about IT investments, resource allocation, and overall risk posture. Without a consistent methodology for quantifying risks and a defined risk appetite, the board lacks the necessary data to understand the true impact of IT risks on business objectives or to align IT strategy with enterprise risk management.

Why the other options are wrong

  • A. Compliance fines are a consequence of unmanaged risks, but the fundamental governance issue is the inability to assess and prioritize risks strategically.
  • B. Prioritization for operational staff is a tactical issue, whereas the lack of a consistent risk quantification method and defined risk appetite impacts strategic decision-making at the highest level.
  • C. While possible, this is an operational allocation issue; the lack of quantification and appetite definition has a higher-level strategic impact.

Quantifiable IT Risk Management

Quantifiable IT risk management involves consistently assessing the likelihood and potential impact (often financial) of IT risks, and defining the organization's risk appetite, to enable informed strategic decision-making.

  • Provides objective basis for risk prioritization.
  • Essential for strategic IT investment decisions.
  • Aligns IT risk with enterprise risk management.

Memory trick: Guessing the risk is like sailing without a depth map; you might hit icebergs.

More Domain 2: Governance and Management of IT questions