Certified Information Systems Auditor (CISA) — Question 355
Which of the following should be of GREATEST concern to an IS auditor reviewing an organization’s newly established enterprise architecture (EA)?
Answer options
- A. The business leaders were not consulted when designing the IT architecture.
- B. Standard architecture methodology was not adopted for designing the IT architecture.
- C. Staff responsible for designing the IT architecture do not hold a related certification.
- D. External experts were not consulted when designing the IT architecture.
Correct answer: A
Explanation
The correct answer is A because consulting business leaders ensures that the IT architecture aligns with business goals and needs, which is critical for success. Options B, C, and D are concerns but do not directly impact the alignment of IT initiatives with business strategy as significantly as the lack of involvement from business leaders.