Does an IT Strategic Plan Identify Major Initiatives or Tactical Links?
In reviewing the IT strategic plan, the IS auditor should consider whether it identifies the:
Community Votes
57% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Auditors verify that the strategic plan outlines major IT initiatives driving business objectives, not operational details that belong in lower-level tactical documents.
This CISA question tests your understanding of an IT strategic plan’s core purpose during an audit. While alignment is critical, the plan itself must explicitly identify major IT initiatives to guide long-term value delivery.
Candidates frequently select D, confusing hierarchical planning levels by assuming the strategic plan must explicitly map to operational or tactical plans rather than directing them.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An IT strategic plan serves as a long-term roadmap designed to align information technology investments with overarching business objectives. During an audit, ISACA guidelines require the auditor to verify that the document explicitly identifies major IT initiatives, as these represent the core projects and transformations necessary to achieve strategic goals. Identifying these initiatives allows the auditor to assess feasibility, resource alignment, and direct contribution to enterprise value. Consequently, option C directly addresses the fundamental purpose of a strategic plan within an audit framework.Why the Other Options Are Wrong
Option A focuses on project management methodologies, which belong in implementation or governance frameworks rather than high-level strategy. Option B addresses staffing allocation, a tactical resource planning detail that emerges after strategic initiatives are defined. Option D incorrectly assumes the strategic plan must map to operational or tactical plans; in reality, the planning hierarchy flows downward, meaning tactical and operational plans derive their directives from the strategic plan rather than the reverse. Auditors recognize this structural distinction when evaluating documentation completeness.Community Comment Notes
The voting split reflects a common conceptual hurdle regarding planning hierarchies. As highlighted in highly upvoted discussions, several candidates initially selected D, arguing that cross-functional alignment is essential for audit rigor. However, other contributors correctly pointed out that strategic documents outline forward-looking initiatives rather than mapping downstream operational linkages. Veteran reviewers consistently stress that while tactical plans cascade from strategy, the auditor’s primary validation step remains confirming the presence of major IT initiatives. This collective feedback solidifies why C remains the definitive choice.Official Reference
Exam Strategy
When analyzing planning documents, always distinguish between strategic direction and tactical execution; strategic plans set the agenda, while lower-level plans handle implementation details. Practice mapping organizational hierarchies to quickly eliminate distractors that invert documentation workflows.
Frequently Asked Questions
Why isn't linking to tactical plans required in a strategic document?
Strategic plans set long-term direction; tactical and operational plans are derived from them, so the hierarchy flows downward rather than upward.
How do auditors validate IT initiatives in a strategic plan?
Auditors cross-reference proposed initiatives against business goals, budget constraints, and risk appetite to ensure feasible, value-driven execution.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →