nerdexam
Isaca

CISA · Question #30

Which of the following findings should be of GREATEST concern to an IS auditor assessing the risk associated with end-user computing (EUC) in an organization?

The correct answer is C. Insufficient processes to track ownership of each EUC application. The greatest concern for an IS auditor regarding EUC risk is the insufficient tracking of ownership for each EUC application, as it creates a lack of accountability and clear responsibility for managing associated risks.

Submitted by emma.c· Apr 18, 2026Governance and Management of IT

Question

Which of the following findings should be of GREATEST concern to an IS auditor assessing the risk associated with end-user computing (EUC) in an organization?

Options

  • ALack of defined criteria for EUC applications
  • BLack of awareness training for EUC users
  • CInsufficient processes to track ownership of each EUC application
  • DInsufficient processes to test for version control

How the community answered

(42 responses)
  • A
    10% (4)
  • B
    17% (7)
  • C
    69% (29)
  • D
    5% (2)

Why each option

The greatest concern for an IS auditor regarding EUC risk is the insufficient tracking of ownership for each EUC application, as it creates a lack of accountability and clear responsibility for managing associated risks.

ALack of defined criteria for EUC applications

Lack of defined criteria for EUC applications is a governance weakness, but having clear ownership is a foundational element that helps establish and enforce those criteria.

BLack of awareness training for EUC users

Lack of awareness training is a risk factor, but clear ownership would help ensure that the need for such training is identified and implemented for EUC users.

CInsufficient processes to track ownership of each EUC applicationCorrect

Without clear ownership, there is no single individual or department accountable for the development, maintenance, security, and accuracy of an EUC application. This lack of accountability significantly elevates risks such as data errors, security vulnerabilities, unmanaged changes, and compliance issues, making it difficult to establish proper controls and manage the lifecycle of these critical tools effectively.

DInsufficient processes to test for version control

Insufficient version control testing is a significant technical risk for EUC applications, but having clear ownership is fundamental to implementing and enforcing robust version control processes and testing effectively.

Concept tested: EUC risk and accountability

Source: https://www.isaca.org/resources/isaca-journal/2007/volume-3/effective-control-and-management-of-end-user-computing

Topics

#End-User Computing (EUC)#Risk Management#IT Governance#Accountability

Community Discussion

No community discussion yet for this question.

Full CISA Practice