Which of the following is the best example of IT governance controls?
A.
Controls that focus on segregation of duties, financial, and change management,
B.
Personnel policies that define and enforce conditions for staff in sensitive IT areas.
C.
Standards that support IT policies by more specifically defining required actions
D.
Controls that focus on data structures and the minimum level of documentation required
The Answer Is:
A
This question includes an explanation.
Explanation:
IT governance controls ensure that an organization's IT systems align with business objectives, manage risks, and comply with regulatory requirements. These controls cover areas such as security, financial oversight, change management, and operational efficiency.
Let’s analyze each option:
Option A: Controls that focus on segregation of duties, financial, and change management.
Correct.
Segregation of duties (SoD) prevents conflicts of interest and reduces fraud risk.
Financial controls ensure IT expenditures align with budgets and policies.
Change management controls ensure system modifications follow formal approval and testing procedures.
These areas are core components of IT governance, ensuring security, compliance, and efficiency.
IIA Reference: Internal auditors evaluate IT governance using frameworks like COBIT (Control Objectives for Information and Related Technologies) and ISO 27001. (IIA GTAG: Auditing IT Governance)
Option B: Personnel policies that define and enforce conditions for staff in sensitive IT areas.
Incorrect.
While personnel policies support IT security, they do not fully represent IT governance controls. IT governance is broader and includes risk management, compliance, and operational efficiency.
Option C: Standards that support IT policies by more specifically defining required actions.
Incorrect.
Standards are part of IT governance but are not controls themselves. IT governance requires enforcement mechanisms like segregation of duties and change management to ensure compliance.
Option D: Controls that focus on data structures and the minimum level of documentation required.
Incorrect.
While data governance is a subset of IT governance, IT governance includes wider financial, security, and operational controls.
Thus, the verified answer is A. Controls that focus on segregation of duties, financial, and change management.
IIA-CIA-Part3 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 70% Discount on All Products,
Use Coupon: "coponace"