Question 1 of 25
A regulatory audit assessed an enterprise's main transactional application as noncompliant. In addition to fines and required corrections, an agreement was reached to implement a set of governance controls over IT. Accountability for these controls is BEST assigned to which of the following?
Show answer
How others answered
- B100%
Explanation
B. CIO. As the main transactional application is an IT system, it is the responsibility of the Chief Information Officer (CIO) to ensure that governance controls are implemented effectively. The CIO is responsible for managing the enterprise's IT infrastructure, ensuring that it complies with regulations, and managing risks associated with IT systems. Therefore, accountability for the controls is best assigned to the CIO. While the internal audit director may provide oversight and ensure that controls are operating effectively, the ultimate responsibility lies with the CIO who has a more comprehensive understanding of the enterprise's IT infrastructure and systems. The board of directors provides governance oversight but is not typically responsible for day-to-day operational matters. Application users are typically responsible for using the system appropriately, but not for implementing or managing governance controls
Adapted from community discussion by Frank1480 · 2023-09-08 · 2 community upvotes. Third-party contribution; reviewed by our quality filter, not independently verified.