nerdexam
Isaca

CISA · Question #483

Which of the following is MOST important for an IS auditor to ensure when evaluating an organization's end-user computing (EUC) policy as part of an IT governance audit?

The correct answer is B. The EUC policy identifies control procedures.. In an IT governance context, the most important element of an EUC policy is that it identifies control procedures - the specific controls (e.g., access controls, data handling, version control for spreadsheets) that govern how end-user computing tools are used. Without defined co

Submitted by brentm· Apr 18, 2026Governance and Management of IT

Question

Which of the following is MOST important for an IS auditor to ensure when evaluating an organization's end-user computing (EUC) policy as part of an IT governance audit?

Options

  • AThe EUC policy supports business objectives.
  • BThe EUC policy identifies control procedures.
  • CThe EUC policy requires signed acknowledgment by users.
  • DThe EUC policy is covered in onboarding and awareness training.

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    83% (43)
  • C
    6% (3)
  • D
    10% (5)

Explanation

In an IT governance context, the most important element of an EUC policy is that it identifies control procedures - the specific controls (e.g., access controls, data handling, version control for spreadsheets) that govern how end-user computing tools are used. Without defined controls, governance cannot be enforced or audited. Alignment with business objectives (A) is important but is a governance design concern, not specific to EUC policy evaluation. Signed acknowledgment (C) and training coverage (D) are implementation and awareness concerns, but control procedures are the substantive core of the policy.

Topics

#End-User Computing (EUC)#IT Governance Audit#Control Identification#IS Auditor Role

Community Discussion

No community discussion yet for this question.

Full CISA Practice