
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Governance and Management of IT.
Question
During an engagement the auditor finds that IT decisions are made variably across divisions and there is no documented risk appetite. The board asks for a governance improvement that will align IT decisions with organizational strategy and acceptable risk levels. Which action should the auditor recommend?
Show the answer and explanation
Correct answer: C. Develop and approve a formal, board‑endorsed IT risk appetite and tolerance statement that is cascaded into IT policies, budgets and decision criteria
The best recommendation is to develop a board‑endorsed IT risk appetite and tolerance statement and embed it into policies, budgets and decision criteria. A documented risk appetite provides clear governance direction and aligns IT decisions with organizational strategy and acceptable risk levels. Option 1 (automated scanning) improves technical controls and detection but does not provide governance guidance or align decisions at the board level. Option 2 (annual policy updates without governance change) may keep documents current but fails to create the executive mandate or escalation needed for consistent decision-making. Option 4 (committee reporting to the CIO) concentrates authority within management and lacks independent board endorsement, weakening enterprise governance.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
