🇺🇸 Certified Information Systems Auditor (CISA) · subject
Certified Information Systems Auditor (CISA) Governance and Management of IT Syllabus
Every chapter and topic of Governance and Management of IT examined in Certified Information Systems Auditor (CISA) — 6 chapters, 25 topics and 9 sub-topics, plus 69 flashcards written against it.
Governance and Management of IT syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Governance and Management of IT in Certified Information Systems Auditor (CISA), not a summary of it.
-
IT Governance Frameworks
5 topics- Enterprise governance of IT (EGIT) concepts
- COBIT framework principles and components
- Governance vs. management objectives
- Goals cascade and design factors
- Board and executive responsibilities for IT
- IT balanced scorecard and performance metrics
- Aligning IT strategy with business objectives
-
IT Strategy, Policies, and Standards
4 topics- IT strategic and tactical planning
- Policies, standards, procedures, and guidelines hierarchy
- IT steering committee and decision rights
- Enterprise architecture management
-
Organizational Structure and HR Management
4 topics- IT roles, responsibilities, and reporting lines
- Segregation of duties within IT
- Conflicting duties and compensating controls
- Human resource controls
- Hiring, background checks, and onboarding
- Job rotation, mandatory vacation, and termination procedures
- Sourcing strategies and outsourcing governance
-
Risk Management
4 topics- Risk management lifecycle
- Identification, assessment, response, and monitoring
- Risk appetite, tolerance, and capacity
- Risk treatment options
- Avoid, mitigate, transfer, and accept
- Maintaining a risk register and KRIs
- Risk management lifecycle
-
Third-Party and Vendor Management
4 topics- Vendor selection and due diligence
- Service level agreements and contract management
- Right-to-audit clauses and penalties
- Ongoing monitoring of service providers
- Cloud and managed service governance considerations
-
Compliance, Privacy, and Performance Management
4 topics- Legal, regulatory, and contractual compliance management
- Privacy program governance and data protection laws
- GDPR, CCPA/CPRA, and sectoral US regulations
- Maturity models and process capability assessment
- Quality management systems for IT
Governance and Management of IT flashcards for Certified Information Systems Auditor (CISA)
25 of 69 cards from the Governance and Management of IT deck — real questions with worked answers.
What is Enterprise Governance of IT (EGIT)?
A governance framework, integrated into overall corporate/enterprise governance, that ensures IT enables and sustains the enterprise's strategy and objectives by directing and controlling IT decisions, value delivery, and risk.
What is the primary difference between IT governance and IT management?
Governance (the board's responsibility) evaluates, directs, and monitors to set direction and ensure objectives are met; management (executives) plans, builds, runs, and monitors activities in alignment with that direction. Governance ensures the right things happen; management makes them happen.
What are the five governance objectives that make up the value proposition delivered by EGIT?
Strategic alignment, value delivery, risk management, resource management (optimization), and performance measurement.
What is COBIT and who publishes it?
COBIT (Control Objectives for Information and Related Technologies) is a comprehensive framework for the governance and management of enterprise IT, published by ISACA.
In COBIT 2019, what is the key distinction between Governance and Management objectives?
Governance objectives are in the EDM domain (Evaluate, Direct, Monitor) and are the board's responsibility; Management objectives (APO, BAI, DSS, MEA) are the responsibility of executive management who plan, build, run, and monitor.
Name the five domains of COBIT 2019.
EDM (Evaluate, Direct and Monitor); APO (Align, Plan and Organize); BAI (Build, Acquire and Implement); DSS (Deliver, Service and Support); and MEA (Monitor, Evaluate and Assess).
What are the six governance system principles in COBIT 2019?
1) Provide stakeholder value; 2) Holistic approach; 3) Dynamic governance system; 4) Governance distinct from management; 5) Tailored to enterprise needs; 6) End-to-end governance system.
What is a COBIT 2019 'governance/management objective' and how does it map to components?
Each objective is supported by a process and a set of related components (such as organizational structures, information flows, policies, culture, skills, services/infrastructure) needed to achieve the objective.
What are the seven components (formerly 'enablers') of a COBIT governance system?
1) Processes; 2) Organizational structures; 3) Principles, policies and frameworks; 4) Information; 5) Culture, ethics and behavior; 6) People, skills and competencies; 7) Services, infrastructure and applications.
What are 'design factors' in COBIT 2019?
Factors (such as enterprise strategy, goals, risk profile, IT-related issues, threat landscape, compliance requirements, role of IT, sourcing model, and enterprise size) used to tailor and prioritize a customized governance system for the enterprise.
What is the board of directors' primary IT governance responsibility?
To provide oversight and strategic direction—evaluating, directing, and monitoring IT to ensure it supports business objectives, delivers value, and that IT risk is managed within acceptable limits; the board sets the 'tone at the top.'
What is an IT balanced scorecard (BSC)?
A performance management tool that translates IT strategy into measurable objectives across multiple perspectives, providing a balanced view beyond financial measures to evaluate IT's contribution to the business.
What are the four classic perspectives of an IT balanced scorecard?
Corporate/business contribution (value), customer/user orientation, operational excellence (internal processes), and future orientation (learning, growth, innovation).
Why use a balanced scorecard instead of purely financial metrics for IT?
Financial measures are lagging indicators; the BSC adds leading indicators across customer, process, and learning perspectives to give a forward-looking, balanced assessment of how IT creates value and supports strategy.
What is the difference between a Key Performance Indicator (KPI) and a Key Goal Indicator (KGI)?
A KPI is a leading measure of how well a process is performing (likelihood of meeting a goal); a KGI is a lagging measure indicating whether a goal/outcome was actually achieved.
What does it mean to align IT strategy with business objectives (strategic alignment)?
Ensuring the IT strategy, investments, and operations directly support and enable enterprise goals, so IT plans are derived from and traceable to the business strategy rather than developed in isolation.
What is the difference between IT strategic planning and IT tactical (operational) planning?
Strategic planning is long-term (typically 3-5 years), sets overall IT direction aligned to business goals; tactical/operational planning is short-term (typically 1 year or less), detailing specific projects, budgets, and actions to execute the strategy.
Who is primarily responsible for ensuring IT strategy aligns with business strategy?
The board and senior/executive management (often via an IT strategy committee at board level), with the CIO translating business strategy into IT strategy.
Define the hierarchy: policies, standards, procedures, and guidelines.
Policies = high-level management intent/direction (mandatory 'what/why'); Standards = mandatory specific rules/technologies supporting policy ('what specifically'); Procedures = mandatory step-by-step instructions ('how'); Guidelines = recommended, non-mandatory best-practice advice.
Which of policies, standards, procedures, and guidelines are mandatory versus discretionary?
Policies, standards, and procedures are mandatory; guidelines are discretionary (recommended, not enforced).
A security policy states passwords must be 'strong.' A document specifying minimum 12 characters with complexity is which type of document?
A standard (it provides the mandatory, specific, measurable requirement that supports the policy).
What is the purpose of an IT steering committee?
A management-level committee (cross-functional) that oversees major IT initiatives, prioritizes and approves IT investments/projects, allocates resources, and ensures IT operations align with business needs.
What is the difference between an IT strategy committee and an IT steering committee?
The IT strategy committee operates at board level advising on strategic direction and governance; the IT steering committee operates at executive/management level overseeing implementation, project prioritization, and resource allocation.
What are 'decision rights' in IT governance?
The formal assignment of who has authority and accountability to make and provide input on specific IT decisions (e.g., IT principles, architecture, infrastructure, business application needs, and investment/prioritization).
What is enterprise architecture (EA)?
A holistic blueprint and discipline describing the structure and integration of an organization's business processes, information, applications, and technology infrastructure, used to guide IT toward the target (future) state in alignment with strategy.
Planning Governance and Management of IT for Certified Information Systems Auditor (CISA)
Governance and Management of IT is about 21% of the Certified Information Systems Auditor (CISA) syllabus by topic count — 25 of 119 topics, spread over 6 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 20 hours.
The heaviest chapters are IT Governance Frameworks (5 topics), IT Strategy, Policies, and Standards (4 topics), Organizational Structure and HR Management (4 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Governance and Management of IT (Certified Information Systems Auditor (CISA)) FAQ
What is in the Certified Information Systems Auditor (CISA) Governance and Management of IT syllabus?
Governance and Management of IT is split into 6 chapters — IT Governance Frameworks, IT Strategy, Policies, and Standards, Organizational Structure and HR Management, Risk Management, Third-Party and Vendor Management and Compliance, Privacy, and Performance Management, containing 25 topics and 9 sub-topics in total.
How is Governance and Management of IT structured in the Certified Information Systems Auditor (CISA) syllabus?
6 chapters. Governance and Management of IT accounts for about 21% of the topics in the whole Certified Information Systems Auditor (CISA) syllabus (25 of 119).
How long should I spend on Governance and Management of IT for Certified Information Systems Auditor (CISA)?
Budget around 20 hours for a first pass through Governance and Management of IT — about 45 minutes per topic plus 12 minutes per sub-topic across its 25 topics. Add revision cycles on top.
Are there flashcards for Certified Information Systems Auditor (CISA) Governance and Management of IT?
Yes — a 69-card Governance and Management of IT deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.