nerdexam
CompTIA

CAS-002 · Question #290

The Chief Information Officer (CIO) is focused on improving IT governance within the organization to reduce system downtime. The CIO has mandated that the following improvements be implemented…

The correct answer is B. Establish a formal change management process. Establishing a formal change management process is a foundational IT governance control that reduces system downtime by ensuring all changes are reviewed, approved, and tracked before implementation.

Integration of Computing, Communications and Business Disciplines

Question

The Chief Information Officer (CIO) is focused on improving IT governance within the organization to reduce system downtime. The CIO has mandated that the following improvements be implemented:

  • All business units must now identify IT risks and include them in

their business risk profiles.

  • Key controls must be identified and monitored.
  • Incidents and events must be recorded and reported with management

oversight.

  • Exemptions to the information security policy must be formally

recorded, approved, and managed.

  • IT strategy will be reviewed to ensure it is aligned with the

businesses strategy and objectives. In addition to the above, which of the following would BEST help the CIO meet the requirements?

Options

  • AEstablish a register of core systems and identify technical service owners
  • BEstablish a formal change management process
  • CDevelop a security requirement traceability matrix
  • DDocument legacy systems to be decommissioned and the disposal process

How the community answered

(16 responses)
  • A
    6% (1)
  • B
    88% (14)
  • C
    6% (1)

Why each option

Establishing a formal change management process is a foundational IT governance control that reduces system downtime by ensuring all changes are reviewed, approved, and tracked before implementation.

AEstablish a register of core systems and identify technical service owners

A register of core systems and technical service owners improves visibility and accountability but does not address the specific governance controls for risk profiles, policy exemptions, or incident reporting mandated by the CIO.

BEstablish a formal change management processCorrect

A formal change management process directly addresses the CIO's goal of reducing downtime by ensuring modifications to systems are controlled, documented, and approved before being applied. It complements the other mandated improvements by providing an oversight mechanism that enforces accountability and risk review for every change. Frameworks such as ITIL and COBIT treat change management as a core governance discipline that ties together risk identification, control monitoring, and incident reduction.

CDevelop a security requirement traceability matrix

A security requirements traceability matrix maps security requirements to controls within a project or system development context and is too narrow to serve as a broad IT governance improvement across all business units.

DDocument legacy systems to be decommissioned and the disposal process

Documenting legacy systems for decommissioning is a tactical, one-time asset lifecycle activity that does not broadly improve governance processes or reduce operational downtime across the organization.

Concept tested: IT governance controls and change management process

Source: https://www.isaca.org/resources/cobit

Topics

#IT governance#change management#risk management#ITIL

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice