nerdexam
CompTIA

CAS-001 · Question #485

The Chief Information Officer (CIO) is focused on improving IT governance within the organization to reduce system downtime. The CIO has mandated that the following improvements be implemented…

The correct answer is B. Establish a formal change management process. A formal change management process best complements the CIO's governance mandates by controlling the highest-risk activity in IT operations - unmanaged changes - which is a primary driver of unplanned system downtime.

Integration of Computing, Communications and Business Disciplines

Question

The Chief Information Officer (CIO) is focused on improving IT governance within the organization to reduce system downtime. The CIO has mandated that the following improvements be implemented:

  • All business units must now identify IT risks and include them in

their business risk profiles.

  • Key controls must be identified and monitored.
  • Incidents and events must be recorded and reported with management

oversight.

  • Exemptions to the information security policy must be formally

recorded, approved, and managed.

  • IT strategy will be reviewed to ensure it is aligned with the

businesses strategy and objectives. In addition to the above, which of the following would BEST help the CIO meet the requirements?

Options

  • AEstablish a register of core systems and identify technical service owners
  • BEstablish a formal change management process
  • CDevelop a security requirement traceability matrix
  • DDocument legacy systems to be decommissioned and the disposal process

How the community answered

(17 responses)
  • A
    12% (2)
  • B
    65% (11)
  • C
    6% (1)
  • D
    18% (3)

Why each option

A formal change management process best complements the CIO's governance mandates by controlling the highest-risk activity in IT operations - unmanaged changes - which is a primary driver of unplanned system downtime.

AEstablish a register of core systems and identify technical service owners

Establishing a register of core systems and technical service owners improves accountability and ownership clarity but does not directly control the risk of outages caused by poorly managed changes.

BEstablish a formal change management processCorrect

Uncontrolled changes are a leading cause of system outages; a formal change management process requires documentation, impact analysis, testing, approval gates, and rollback plans before any change is applied to production systems. This directly supports the CIO's downtime reduction goal and reinforces the broader governance mandates by adding structured oversight and management visibility to change activity across all business units.

CDevelop a security requirement traceability matrix

A security requirements traceability matrix tracks security controls against compliance requirements and is primarily a compliance assurance tool, not an operational governance mechanism for reducing downtime.

DDocument legacy systems to be decommissioned and the disposal process

Documenting legacy systems for decommissioning is a bounded, one-time planning activity that does not provide the ongoing governance controls the CIO needs to address continuous operational risks.

Concept tested: Change management as an IT governance control for operational stability

Source: https://www.isaca.org/resources/cobit

Topics

#IT governance#change management#risk profiles#policy alignment

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice