CGEIT · Question #535
An enterprise learns that some of its business divisions have been approaching technology vendors for cloud services, resulting in duplicate support contracts and underutilization of IT services. Whic
The correct answer is A. Review the enterprise IT procurement policy.. To address issues of duplicate cloud service contracts and underutilization caused by shadow IT procurement, the first step is to review the enterprise IT procurement policy.
Question
An enterprise learns that some of its business divisions have been approaching technology vendors for cloud services, resulting in duplicate support contracts and underutilization of IT services. Which of the following should be done FIRST to address this issue?
Options
- AReview the enterprise IT procurement policy.
- BRe-negotiate contracts with vendors to request discounts.
- CRequire updates to the IT procurement process.
- DConduct an audit to investigate utilization of cloud services.
How the community answered
(62 responses)- A81% (50)
- B11% (7)
- C3% (2)
- D5% (3)
Why each option
To address issues of duplicate cloud service contracts and underutilization caused by shadow IT procurement, the first step is to review the enterprise IT procurement policy.
The FIRST action to address shadow IT procurement leading to duplicate contracts and underutilization is to review the existing enterprise IT procurement policy. This step is crucial for identifying the deficiencies or lack of enforcement in current policies that permitted individual business divisions to independently acquire cloud services without central oversight, thereby creating the problem. Understanding the policy gaps is foundational to establishing effective controls.
Re-negotiating contracts is a reactive measure to manage existing duplicate contracts; it does not address the root cause of why business divisions are bypassing central procurement in the first place, which is a policy issue.
Requiring updates to the IT procurement process is a valid solution, but it logically follows after reviewing the existing policy to understand what specifically needs to be updated and why, based on identified gaps or failures.
Conducting an audit to investigate utilization is important for understanding the scope of the problem, but it comes after identifying the governance breakdown (via policy review) that allowed the uncontrolled procurement to occur. The audit helps quantify the impact, but the policy review addresses the "how" and "why" it happened.
Concept tested: IT procurement policy enforcement and review
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/manage-costs/organization-alignment#it-procurement-policies
Topics
Community Discussion
No community discussion yet for this question.