CISA Certified Information Systems Auditor – Question2728

When reviewing the IT strategic planning process, an IS auditor should ensure that the plan:

A.
incorporates state of the art technology.
B. addresses the required operational controls.
C. articulates the IT mission and vision.
D. specifies project management practices.

Correct Answer: C

Explanation:

Explanation:
The IT strategic plan must include a clear articulation of the IT mission and vision. The plan need not address the technology, operational controls or project management practices.

CISA Certified Information Systems Auditor – Question2727

To aid management in achieving IT and business alignment, an IS auditor should recommend the use of:

A.
control self-assessments.
B. a business impact analysis.
C. an IT balanced scorecard.
D. business process reengineering.

Correct Answer: C

Explanation:

Explanation:
An IT balanced scorecard (BSC) provides the bridge between IT objectives and business objectives by supplementing the traditional financial evaluation with measures to evaluate customer satisfaction, internal processes and the ability to innovate. Control selfassessment
(CSA), business impact analysis (BIA) and business process reengineering (BPR) are insufficient to align IT with organizational objectives.

CISA Certified Information Systems Auditor – Question2726

In an organization, the responsibilities for IT security are clearly assigned and enforced and an IT security risk and impact analysis is consistently performed. This represents which level of ranking in the information security governance maturity model?

A.
Optimized
B. Managed
C. Defined
D. Repeatable

Correct Answer: B

Explanation:

Explanation:
Boards of directors and executive management can use the information security governance maturity model to establish rankings for security in their organizations. The ranks are nonexistent, initial, repeatable, defined, managed and optimized. When the responsibilities for IT security in an organization are clearly assigned and enforced and an IT security risk and impact analysis is consistently performed, it is said to be ‘managed and measurable.’

CISA Certified Information Systems Auditor – Question2725

When reviewing IS strategies, an IS auditor can BEST assess whether IS strategy supports the organizations’ business objectives by determining if IS:

A.
has all the personnel and equipment it needs.
B. plans are consistent with management strategy.
C. uses its equipment and personnel efficiently and effectively.
D. has sufficient excess capacity to respond to changing directions.

Correct Answer: B

Explanation:

Explanation:
Determining if the IS plan is consistent with management strategy relates IS/IT planning to business plans. Choices A, C and D are effective methods for determining the alignment of IS plans with business objectives and the organization’s strategies.

CISA Certified Information Systems Auditor – Question2724

An IS auditor reviewing an organization's IT strategic plan should FIRST review:

A.
the existing IT environment.
B. the business plan.
C. the present IT budget.
D. current technology trends.

Correct Answer: B

Explanation:

Explanation:
The IT strategic plan exists to support the organization’s business plan. To evaluate the IT strategic plan, an IS auditor would first need to familiarize themselves with the business plan.

CISA Certified Information Systems Auditor – Question2723

Which of the following would an IS auditor consider to be the MOST important when evaluating an organization's IS strategy? That it:

A.
has been approved by line management.
B. does not vary from the IS department's preliminary budget.
C. complies with procurement procedures.
D. supports the business objectives of the organization.

Correct Answer: D

Explanation:

Explanation:
Strategic planning sets corporate or department objectives into motion. Both long-term and short- term strategic plans should be consistent with the organization’s broader plans and business objectives for attaining these goals. Choice A is incorrect since line management prepared the plans.

CISA Certified Information Systems Auditor – Question2722

Which of the following goals would you expect to find in an organization's strategic plan?

A.
Test a new accounting package.
B. Perform an evaluation of information technology needs.
C. Implement a new project planning system within the next 12 months.
D. Become the supplier of choice for the product offered.

Correct Answer: D

Explanation:

Explanation:
Strategic planning sets corporate or departmental objectives into motion. Comprehensive planning helps ensure an effective and efficient organization. Strategic planning is time- and project-oriented, but also must address and help determine priorities to meet business needs. Long- and short-range plans should be consistent with the organization’s broader plans for attaining their goals. Choice D represents a business objective that is intended to focus the overall direction of the business and would thus be a part of the organization’s strategic plan. The other choices are project-oriented and do not address business objectives.

CISA Certified Information Systems Auditor – Question2721

Which of the following would an IS auditor consider the MOST relevant to short-term planning for an IS department?

A.
Allocating resources
B. Keeping current with technology advances
C. Conducting control self-assessment
D. Evaluating hardware needs

Correct Answer: A

Explanation:

Explanation:
The IS department should specifically consider the manner in which resources are allocated in the short term. Investments in IT need to be aligned with top management strategies, rather than focusing on technology for technology’s sake. Conducting control self-assessments and evaluating hardware needs are not as critical as allocating resources during short-term planning for the IS department.

CISA Certified Information Systems Auditor – Question2720

In reviewing the IS short-range (tactical) plan, an IS auditor should determine whether:

A.
there is an integration of IS and business staffs within projects.
B. there is a clear definition of the IS mission and vision.
C. a strategic information technology planning methodology is in place.
D. the plan correlates business objectives to IS goals and objectives.

Correct Answer: A

Explanation:

Explanation:
The integration of IS and business staff in projects is an operational issue and should be considered while reviewing the short-range plan. A strategic plan would provide a framework for the IS short-range plan. Choices B, C and D are areas covered by a strategic plan.

CISA Certified Information Systems Auditor – Question2719

To support an organization's goals, an IS department should have:

A.
a low-cost philosophy.
B. long- and short-range plans.
C. leading-edge technology.
D. plans to acquire new hardware and software.

Correct Answer: B

Explanation:

Explanation:
To ensure its contribution to the realization of an organization’s overall goals, the IS department should have long- and short-range plans that are consistent with the organization’s broader plans for attaining its goals. Choices A and C are objectives, and plans would be needed to delineate how each of the objectives would be achieved. Choice D could be a part of the overall plan but would be required only if hardware or software is needed to achieve the organizational goals.