組織のエンタープライズ アーキテクチャ (EA) プログラムをレビューする IS 監査人にとって、次の観察事項のうちどれが最も重要であるでしょうか。
正解:B
IT application owners having sole responsibility for architecture approval (B) is a major concern because it indicates a lack of oversight and segregation of duties. EA decisions should be reviewed by a cross-functional governance body to ensure alignment with security, compliance, and business objectives. Other options: The CIO chairing the review board (A) may indicate centralized leadership but is not inherently a risk. EA governing non-IT projects (C) may indicate scope expansion but is not a security risk. Security requirements being reviewed (D) is a best practice and not a concern. Reference: ISACA CISA Review Manual, IT Governance and Management of IT