nerdexam
Isaca

CISA · Question #646

An organization-wide review shows poor employee adherence to IT access control policies. Which of the following is PRIMARILY responsible for establishing the appropriate control culture?

The correct answer is D. Senior leadership. Organizational culture - including a culture of compliance and controls - flows from the top down. Senior leadership sets the tone by visibly championing policies, allocating resources, and enforcing accountability. When adherence is poor organization-wide, it reflects a failure

Submitted by weili_xi· Apr 18, 2026Governance and Management of IT

Question

An organization-wide review shows poor employee adherence to IT access control policies. Which of the following is PRIMARILY responsible for establishing the appropriate control culture?

Options

  • ASystem users
  • BIS audit department
  • CInformation security department
  • DSenior leadership

How the community answered

(32 responses)
  • A
    6% (2)
  • C
    3% (1)
  • D
    91% (29)

Explanation

Organizational culture - including a culture of compliance and controls - flows from the top down. Senior leadership sets the tone by visibly championing policies, allocating resources, and enforcing accountability. When adherence is poor organization-wide, it reflects a failure of leadership to embed controls into the culture, not just a technical or departmental issue. System users (A) are responsible for following policies, not establishing culture. IS audit (B) assesses and advises but does not set culture. Information security (C) designs and enforces controls but lacks the organizational authority to drive culture change without executive sponsorship.

Topics

#Control culture#Tone at the top#IT governance#Organizational responsibility

Community Discussion

No community discussion yet for this question.

Full CISA Practice