CISA Question of the Day: IT Strategic Alignment Metrics

CISA exam practice question — CISA Question of the Day: IT Strategic Alignment Metrics

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Governance and Management of IT.

Question

An IT auditor reviews the executive IT performance dashboard and finds it dominated by technical metrics (server uptime, patch counts, mean time to repair) with no direct measures of business outcomes. Which recommendation most effectively strengthens IT governance and demonstrates IT's contribution to enterprise objectives?

  • A. Define and report business‑outcome aligned IT performance metrics with targets, ownership, and executive reporting to link IT activities to strategic objectives.
  • B. Increase the frequency of technical metric reporting so executives receive real‑time operational visibility and can respond faster to issues.
  • C. Add more granular technical indicators to the dashboard to improve operational diagnostics and root cause analysis for incidents.
  • D. Implement formal service level agreements (SLAs) with internal customers to document agreed technical service levels and escalation procedures.
Show the answer and explanation

Correct answer: A. Define and report business‑outcome aligned IT performance metrics with targets, ownership, and executive reporting to link IT activities to strategic objectives.

Option 1 is best because governance requires measurable alignment between IT performance and business objectives; defining outcome‑linked metrics (with targets and accountable owners and executive reporting) makes IT contribution visible to leadership and supports decision making. Option 2 is weak because increasing reporting frequency does not change what is measured — visibility alone won’t demonstrate business value. Option 3 still emphasizes technical detail and misses the need to tie measures to business outcomes. Option 4 helps clarify service expectations but focuses on operational service levels rather than demonstrating how IT activities impact strategic business results.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.