nerdexam
Isaca

CISA · Question #174

Which of the following is the BEST approach to help organizations address risks associated with shadow IT?

The correct answer is D. Conducting regular security assessments to identify unauthorized systems and solutions. Shadow IT refers to systems, software, or services used by employees without explicit IT approval. You cannot manage what you cannot see, so conducting regular security assessments to identify unauthorized systems (D) is the most effective approach - it surfaces what shadow IT ac

Submitted by anna_se· Apr 18, 2026Protection of Information Assets

Question

Which of the following is the BEST approach to help organizations address risks associated with shadow IT?

Options

  • AImplementing policies that prohibit the use of unauthorized systems and solutions
  • BTraining employees on information security and conducting routine follow-ups
  • CProviding employees with access to necessary systems and unlimited software licenses
  • DConducting regular security assessments to identify unauthorized systems and solutions

How the community answered

(61 responses)
  • A
    7% (4)
  • B
    11% (7)
  • C
    3% (2)
  • D
    79% (48)

Explanation

Shadow IT refers to systems, software, or services used by employees without explicit IT approval. You cannot manage what you cannot see, so conducting regular security assessments to identify unauthorized systems (D) is the most effective approach - it surfaces what shadow IT actually exists so the organization can evaluate, remediate, or formally adopt those solutions. Policies prohibiting unauthorized systems (A) are necessary but unenforceable without detection mechanisms. Training (B) raises awareness but does not discover existing shadow IT. Providing unlimited software licenses (C) is impractical, costly, and does not address the underlying governance or security risks.

Topics

#Shadow IT#Risk Management#Security Assessments#Information Asset Protection

Community Discussion

No community discussion yet for this question.

Full CISA Practice