nerdexam
(ISC)2

CISSP · Question #1193

Which of the following has the responsibility of information technology (IT) governance?

The correct answer is C. Board of Directors. IT governance is a board-level responsibility that ensures IT strategy aligns with organizational objectives and risk tolerance. The Board of Directors holds ultimate accountability for governance frameworks.

Submitted by devops_kid· Mar 5, 2026Security and Risk Management

Question

Which of the following has the responsibility of information technology (IT) governance?

Options

  • AChief Information Officer (CIO)
  • BSenior IT Management
  • CBoard of Directors
  • DChief Information Security Officer (CISO)

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    88% (29)
  • D
    3% (1)

Why each option

IT governance is a board-level responsibility that ensures IT strategy aligns with organizational objectives and risk tolerance. The Board of Directors holds ultimate accountability for governance frameworks.

AChief Information Officer (CIO)

The CIO is responsible for IT management and strategy execution, not governance itself; the CIO reports upward to governance bodies rather than owning the governance function.

BSenior IT Management

Senior IT Management handles operational and tactical IT decisions and implements governance directives, but they do not own the governance responsibility that resides at the board level.

CBoard of DirectorsCorrect

The Board of Directors holds ultimate responsibility for IT governance because governance is a strategic, enterprise-wide function concerned with accountability, oversight, and alignment of IT with business goals. Frameworks like COBIT and ISO 38500 explicitly assign IT governance responsibility to the board or executive leadership, not operational or managerial roles. This distinguishes governance (board-level oversight) from IT management (day-to-day execution).

DChief Information Security Officer (CISO)

The CISO is responsible for information security strategy and risk management within IT, which is a subset of governance, not the governance function itself.

Concept tested: IT governance ownership and board-level accountability

Source: https://www.isaca.org/resources/cobit

Topics

#IT governance#organizational roles#Board of Directors

Community Discussion

No community discussion yet for this question.

Full CISSP Practice