Best Enabler for Balancing Value Delivery and Risk Management

IT Governance Frameworks
Answer Correct answer: A — an IT governance framework integrates value delivery and risk management into a single, coherent governance mechanism.

Which of the following BEST enables an organization to balance value delivery and risk management?

  1. Utilizing an IT governance framework Correct Answer
  2. Executing gap assessments against a capability maturity model
  3. Performing risk assessments
  4. Developing dashboards and management reporting

Community Votes

A
66%
C
17%
B
17%

66% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests ISACA's governance doctrine that an IT governance framework integrates strategic planning, risk management, and performance measurement; many candidates mistakenly choose the isolated activity of risk assessment instead of the overarching framework.

In CISA exam scenarios, an IT governance framework is the key mechanism that aligns strategic objectives with IT value delivery while embedding risk management. This study page explains why option A is the correct answer and examines the community debate over risk assessments.

Choosing C, performing risk assessments, because risk assessment is a visible, familiar activity; however, it is only a component within a broader IT governance framework and does not by itself balance value delivery with risk.

Community Discussion (4 comments)

choboanon 👍 1 Selected: A
Answer is A
PurpleParrot 👍 3 Selected: A
An IT governance framework integrates strategic planning, risk management, and performance measurement into a cohesive approach, making it the most effective method for balancing value delivery with risk management. Always think from ISACA's point of view.
RS66 👍 1 Selected: B
B. Executing gap assessments against a capability maturity model
Swallows 👍 1 Selected: C
An IT governance framework (option A) is important, but without a specific risk assessment, it is difficult to show specifically how to achieve a balance. An IT governance framework provides guidelines and processes to support risk management, but its effectiveness is based on a risk assessment. Therefore, the most effective way for an organization to balance value delivery and risk management is to first conduct a risk assessment and then develop a strategy based on the results.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A is correct because an IT governance framework, such as COBIT, provides a structured integration of value delivery, strategic alignment, risk management, and performance management. ISACA positions governance as the process that evaluates stakeholder needs and conditions to determine balanced enterprise objectives, making a framework the best mechanism to balance value delivery with risk management. The other options are operational tools that support, but do not replace, an IT governance framework.

Why the Other Options Are Wrong

Option B is incorrect because gap assessments against a capability maturity model identify differences between current and desired capabilities; they do not by themselves balance value delivery and risk. Option C is incorrect because performing risk assessments is a focused activity that addresses threats and vulnerabilities, while value delivery remains outside its typical scope. Option D is incorrect because dashboards and management reporting communicate and monitor performance but do not provide the integrative governance approach needed to balance competing objectives.

Community Comment Notes

As PurpleParrot noted, an IT governance framework integrates strategic planning, risk management, and performance measurement into a cohesive approach, adding that candidates should "always think from ISACA's point of view." RS66 selected a maturity model gap assessment, but that is an evaluation rather than an overarching governance mechanism. Swallows argued that risk assessment is needed to demonstrate the balance, yet a governance framework incorporates risk assessment while also addressing value delivery, so option A remains the best enabler.

Official Reference

Exam Strategy

For ISACA questions, identify the broadest governance-level concept. When the question asks what best enables a balance between value delivery and risk, select the mechanism that integrates multiple disciplines—such as an IT governance framework—rather than a single-point activity like risk assessment or reporting.

Frequently Asked Questions

Why is performing a risk assessment insufficient for balancing value and risk?

A risk assessment focuses on threats and vulnerabilities and does not integrate business objectives and value delivery; it is one component inside a governance framework.

Are capability maturity model gap assessments useful for this governance goal?

Yes, they identify process capability gaps, but they do not decide how to balance competing priorities; an IT governance framework provides the overarching mechanism.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide