CISA Question of the Day: IT Performance Metrics Evaluation

CISA exam practice question — CISA Question of the Day: IT Performance Metrics Evaluation

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Governance and Management of IT.

Question

As part of an audit of IT governance, you receive the CIO's quarterly IT performance report containing uptime percentages, mean-time-to-repair, project status, and customer satisfaction scores. What is the most appropriate first step to evaluate whether these metrics demonstrate effective IT governance?

  • A. Determine whether each reported metric is linked to specific business objectives and verify the accuracy and completeness of the underlying data sources
  • B. Accept the metrics as evidence of governance effectiveness because they are produced by the IT governance office and presented to the board
  • C. Compare the current metrics to prior quarters to identify trends before examining their relation to business outcomes
  • D. Recommend adding more technical infrastructure counters to the report to provide a fuller operational view
Show the answer and explanation

Correct answer: A. Determine whether each reported metric is linked to specific business objectives and verify the accuracy and completeness of the underlying data sources

The best first step is to confirm that metrics are tied to business objectives and to test the reliability of their data. Metrics that are not aligned with business goals or that are based on inaccurate data cannot demonstrate effective governance. Option B is incorrect because board presentation or origin does not guarantee relevance or accuracy. Option C is incomplete: trend analysis is useful but should follow validation of alignment and data integrity, not precede it. Option D is premature because adding technical counters may increase noise unless those counters are selected for their relevance to business objectives and validated data quality.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.