TechNuggets Academy

Governance and Management of IT

Free Certified Information Systems Auditor practice — 6 questions on Governance and Management of IT, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 2: Governance and Management of IT
An IS auditor reviewing IT governance structures at an organization finds that a committee composed of senior business unit executives and the CIO meets monthly to prioritize IT project funding and resolve resource conflicts between departments. This committee reports its decisions to executive management but does not report directly to the board of directors. Which of the following BEST describes the auditor's evaluation of this structure?
The described committee performs the classic function of an IT steering committee — tactical prioritization of projects and resource allocation at the executive/management level. An IT strategy committee, by contrast, operates at the board level and focuses on strategic alignment and value delivery oversight, not day-to-day funding decisions. Having both bodies exist separately, with the steering committee reporting to executive management rather than the board, is sound governance practice.
Question 2 of 6 · Domain 2: Governance and Management of IT
During an audit of an organization's contract with a critical cloud service provider, the IS auditor discovers that the contract does not include a right-to-audit clause, and the provider refuses to share its SOC 2 Type II report, citing confidentiality. Which of the following should the auditor recommend as the MOST appropriate course of action?
This is a proportionate, realistic remediation: obtaining an existing independent attestation (or a new one) gives assurance now, and negotiating amendments closes the governance gap for future periods. This reflects standard third-party risk management practice when direct audit access is not contractually available.
Question 3 of 6 · Domain 2: Governance and Management of IT
An organization wants to adopt a framework specifically designed to provide the board of directors with high-level principles for governing the enterprise's use of IT — covering areas such as responsibility, strategy, acquisition, performance, conformance, and human behavior — without prescribing detailed processes or control objectives. Which framework should the organization adopt?
ISO/IEC 38500 is the international standard providing high-level guiding principles for the governance of IT by directors, structured around six principles (responsibility, strategy, acquisition, performance, conformance, human behavior). It is deliberately non-prescriptive and director-focused, unlike more detailed management/process frameworks.
Question 4 of 6 · Domain 2: Governance and Management of IT
An IS auditor assesses a process as achieving Capability Level 1 under the COBIT 2019 Process Capability Model. Which statement BEST describes this rating?
COBIT 2019's Process Capability Model defines Level 1 (Performed) as a process that achieves its purpose but lacks planning, monitoring, and formal management of work products — distinguishing it from Level 2 (Managed), where these controls exist.
Question 5 of 6 · Domain 2: Governance and Management of IT
During an IT governance audit, the IS auditor notes that the enterprise risk management policy defines the acceptable variation around the amount of risk the organization is willing to accept in pursuit of its objectives, but does not separately define the maximum overall amount of risk the organization is willing to accept. Which governance gap has the auditor identified?
Risk tolerance is the acceptable level of variation around the risk appetite, while risk appetite is the broad, overall amount of risk the organization is willing to accept in pursuit of its objectives. The policy as described defines only the variation (tolerance) without establishing the overarching boundary (appetite), which is a governance gap.
Question 6 of 6 · Domain 2: Governance and Management of IT
In a RACI chart used to document IT governance roles and responsibilities for a process, what is the key difference between the 'Accountable' and 'Responsible' designations?
In standard RACI terminology, Responsible (R) identifies the person(s) who actually perform the work, while Accountable (A) identifies the single individual who owns the outcome and is ultimately answerable for it. Best practice dictates exactly one Accountable party per activity to avoid diffusion of ownership.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →