IT Strategy and Business Alignment
An IT strategy that does not trace back to a business objective is a wish list. The exam tests whether IT investment is driven by the business or by the technology.
What this makes you able to do
Evaluate whether the IT strategy is aligned with, and traceable to, the organisation's business strategy.
By the end you can
- Explain what business-IT alignment means and how an auditor tests for it.
- Distinguish the roles of the IT strategy committee and the IT steering committee.
- Recognise when IT investment is technology-driven rather than business-driven.
Transcript
I-T strategy and business alignment. This lesson is about a simple test the exam applies to any I-T strategy: does it actually serve the business, or does it serve the technology.
Picture a strategy document that is genuinely impressive. Cloud migration, a data platform, an A-I roadmap, all current, all ambitious. You are inclined to call it strong. Then you ask a plain question of each initiative, what business objective does this serve, and the answers get vague. That vagueness is the finding.
Because alignment, stripped of jargon, is traceability. Every significant I-T initiative should trace back to a business objective it advances. I-T does not exist to be modern. It exists to help the enterprise meet its goals.
So the auditor’s test for alignment is not, is this strategy ambitious. It is, can each initiative be tied to a business need. A cloud migration that cuts the cost of a service the business is trying to scale is aligned. The same migration done just because the platform is old, with no business case, is maintenance wearing a strategy’s clothes. A plain strategy where every line serves a goal beats a dazzling one that serves the technology.
Two committees appear all through Domain 2, and the exam expects you to tell them apart. The I-T strategy committee operates at board level. It advises the board on the future direction of I-T and on whether I-T strategy supports the business strategy. It is about direction. The I-T steering committee operates below the board. It turns that direction into prioritised, resourced execution: which initiatives proceed, in what order, with what budget. It is about delivery.
Now the clearest sign of misalignment, and it shows up in the order decisions get made. When the I-T department selects projects on technical merit, and consults the business units only after approval, selection is technology-driven. The business need never shaped what was chosen.
And that is why the most significant risk is not old technology or an overspend. It is that the investment does not deliver business value, however well it is built. Business-driven selection reverses the order: the business states a need, and I-T proposes how to meet it. Alignment is as much about sequence as it is about content.
So hold on to what business-driven selection looks like. A stated business need comes first.
Then I-T proposes how to meet that need. The direction of travel runs from the business to the technology, not the other way.
What it is not: I-T picking the project and telling the business afterwards. And what it is not: a project chosen because the technology is current and interesting. Both of those are the technology leading, and both are the trap.
Which is the instinct that costs marks. An auditor impressed by the roadmap asks whether the technology is good. The exam asks whether the technology serves the business. Do not admire the strategy on its own terms.
So carry this away. Judge an I-T strategy by its traceability to business objectives, not by how advanced or ambitious it looks. The plain aligned strategy wins.
1.An IS auditor is assessing IT strategy. Which of the following provides the BEST evidence that IT is aligned with the business?
2.Which body is PRIMARILY responsible for advising the board on the future direction of IT and whether IT strategy supports the business strategy?
3.An IS auditor finds that IT projects are selected by the IT department based on technical merit, with business units consulted only after approval. What is the MOST significant risk?
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
