Best Enabler for Balancing Value Delivery and Risk Management
Which of the following BEST enables an organization to balance value delivery and risk management?
Community Votes
66% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests ISACA's governance doctrine that an IT governance framework integrates strategic planning, risk management, and performance measurement; many candidates mistakenly choose the isolated activity of risk assessment instead of the overarching framework.
In CISA exam scenarios, an IT governance framework is the key mechanism that aligns strategic objectives with IT value delivery while embedding risk management. This study page explains why option A is the correct answer and examines the community debate over risk assessments.
Choosing C, performing risk assessments, because risk assessment is a visible, familiar activity; however, it is only a component within a broader IT governance framework and does not by itself balance value delivery with risk.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A is correct because an IT governance framework, such as COBIT, provides a structured integration of value delivery, strategic alignment, risk management, and performance management. ISACA positions governance as the process that evaluates stakeholder needs and conditions to determine balanced enterprise objectives, making a framework the best mechanism to balance value delivery with risk management. The other options are operational tools that support, but do not replace, an IT governance framework.
Why the Other Options Are Wrong
Option B is incorrect because gap assessments against a capability maturity model identify differences between current and desired capabilities; they do not by themselves balance value delivery and risk. Option C is incorrect because performing risk assessments is a focused activity that addresses threats and vulnerabilities, while value delivery remains outside its typical scope. Option D is incorrect because dashboards and management reporting communicate and monitor performance but do not provide the integrative governance approach needed to balance competing objectives.
Community Comment Notes
As PurpleParrot noted, an IT governance framework integrates strategic planning, risk management, and performance measurement into a cohesive approach, adding that candidates should "always think from ISACA's point of view." RS66 selected a maturity model gap assessment, but that is an evaluation rather than an overarching governance mechanism. Swallows argued that risk assessment is needed to demonstrate the balance, yet a governance framework incorporates risk assessment while also addressing value delivery, so option A remains the best enabler.
Official Reference
Exam Strategy
For ISACA questions, identify the broadest governance-level concept. When the question asks what best enables a balance between value delivery and risk, select the mechanism that integrates multiple disciplines—such as an IT governance framework—rather than a single-point activity like risk assessment or reporting.
Frequently Asked Questions
Why is performing a risk assessment insufficient for balancing value and risk?
A risk assessment focuses on threats and vulnerabilities and does not integrate business objectives and value delivery; it is one component inside a governance framework.
Are capability maturity model gap assessments useful for this governance goal?
Yes, they identify process capability gaps, but they do not decide how to balance competing priorities; an IT governance framework provides the overarching mechanism.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →