nerdexam
Isaca

CGEIT · Question #69

The board and senior management of a new enterprise recently met to formalize an IT governance framework. The board of directors' FIRST step in implementing IT governance is to ensure that:

The correct answer is C. IT roles and responsibilities are established. The board's initial step in implementing an IT governance framework is to establish clear IT roles and responsibilities to define accountability and authority.

Submitted by andres_qro· Apr 18, 2026Governance of Enterprise IT

Question

The board and senior management of a new enterprise recently met to formalize an IT governance framework. The board of directors' FIRST step in implementing IT governance is to ensure that:

Options

  • Aan IT balanced scorecard is implemented.
  • Ba portfolio of IT-enabled investments is developed.
  • CIT roles and responsibilities are established.
  • DIT policies and procedures are defined.

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    4% (1)
  • C
    89% (25)

Why each option

The board's initial step in implementing an IT governance framework is to establish clear IT roles and responsibilities to define accountability and authority.

Aan IT balanced scorecard is implemented.

Implementing an IT balanced scorecard is a measurement and reporting tool that comes after the fundamental governance structure, including roles and responsibilities, has been established.

Ba portfolio of IT-enabled investments is developed.

Developing a portfolio of IT-enabled investments is an output of IT strategy and planning, which relies on an established governance framework and defined roles to guide investment decisions.

CIT roles and responsibilities are established.Correct

Establishing clear roles and responsibilities is foundational for IT governance, as it defines who is accountable for what decisions and actions, ensuring effective oversight and control within the organization and enabling subsequent governance activities.

DIT policies and procedures are defined.

Defining IT policies and procedures is a critical part of operationalizing governance, but these documents are typically developed and enforced based on the established roles and responsibilities and overall governance structure.

Concept tested: IT Governance Implementation Phases

Source: https://www.isaca.org/resources/cobit/cobit-2019-framework-governance-and-management-objectives

Topics

#IT Governance Framework#Board Responsibilities#Roles and Responsibilities#Governance Implementation

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice