The correct answer is B. Key performance indicators (KPIs).
The governance model has a specific performance objective: ensuring that network-related findings are remediated within the SLA. To assess whether that objective is being achieved, the IS auditor should review KPIs, such as percentage of findings remediated within SLA, average remediation time, overdue findings, aging of open findings, and trend of SLA compliance.
ISACA defines a KPI as a type of performance measurement. ISACA also defines performance indicators as metrics designed to measure the extent to which performance objectives are being achieved on an ongoing basis. The CISA Exam Content Outline also includes evaluating the monitoring and reporting of IT KPIs and KRIs under Governance and Management of IT.
Option A is not the best answer because key process controls help determine whether the process is controlled, but they do not directly measure whether the governance model is achieving its remediation SLA. Option C is not the best answer because KRIs indicate increasing risk exposure, such as growth in overdue critical findings, but the question asks how to assess the capability/performance of the governance model. Option D is incorrect because key data elements are data fields, not performance measures.
This question maps mainly to Governance and Management of IT because it addresses governance performance, accountability, SLA oversight, and remediation monitoring.
[References: ISACA CISA Exam Content Outline, Domain 2; ISACA Interactive Glossary, “Key performance indicator,” “Key risk indicator,” and “Performance indicators.”, ===================, ]
Submit