nerdexam
Isaca

CGEIT · Question #50

Which of the following is the MOST effective way for a CIO to govern business unit deployment of shadow IT applications in a cloud environment?

The correct answer is B. Educate the executive team about the risk associated with shadow IT applications. To effectively govern shadow IT in a cloud environment, the CIO must first ensure executive leadership understands the associated risks, enabling top-down support for policies and controls.

Submitted by joshua94· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following is the MOST effective way for a CIO to govern business unit deployment of shadow IT applications in a cloud environment?

Options

  • AImplement controls to block the installation of unapproved applications.
  • BEducate the executive team about the risk associated with shadow IT applications.
  • CProvide training to the help desk to identify shadow IT applications.
  • DReview and update the application implementation process.

How the community answered

(53 responses)
  • A
    8% (4)
  • B
    43% (23)
  • C
    34% (18)
  • D
    15% (8)

Why each option

To effectively govern shadow IT in a cloud environment, the CIO must first ensure executive leadership understands the associated risks, enabling top-down support for policies and controls.

AImplement controls to block the installation of unapproved applications.

Implementing controls to block applications is a technical enforcement measure that is often reactive and can be circumvented if the underlying governance and executive support are not in place.

BEducate the executive team about the risk associated with shadow IT applications.Correct

Executive education is crucial because gaining buy-in from the highest level of leadership empowers the CIO to enforce policies, allocate resources for controls, and establish a risk-aware culture across the organization. This foundational understanding at the executive level ensures strategic alignment and support for managing shadow IT, rather than just tactical enforcement.

CProvide training to the help desk to identify shadow IT applications.

Training the help desk to identify shadow IT is a detection and response mechanism, but it doesn't address the root cause of shadow IT or provide a comprehensive governance framework.

DReview and update the application implementation process.

Reviewing and updating the application implementation process is a procedural improvement, but without executive understanding and support regarding shadow IT risks, such updates may lack the necessary organizational mandate for effective enforcement.

Concept tested: Shadow IT governance and executive advocacy

Topics

#Shadow IT#IT Governance#Risk Management#Executive Education

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice