← All Study Guides

D2: Governance and Management of IT

CISA (ISACA) study guide

CISA D2: Governance and Management of IT

Domain 2 (18% of the exam) covers how IT is directed and controlled: IT governance, organizational structure and IT strategy, policies, standards and procedures, enterprise architecture, enterprise risk management, privacy and data governance, IT resource and vendor management, performance monitoring and reporting, and quality management. A useful lens for this domain: not "what should the security manager do," but "is there evidence that governance is designed and operating effectively, and what should the auditor report if it isn't."

Key Concepts
  • Governance vs. management in COBIT 2019

    COBIT 2019 organizes its 40 objectives into five domains: EDM (Evaluate, Direct and Monitor), APO (Align, Plan and Organize), BAI (Build, Acquire and Implement), DSS (Deliver, Service and Support) and MEA (Monitor, Evaluate and Assess). EDM is the domain focused on governance activities at the highest level. ISACA's glossary draws the line: governance evaluates stakeholder needs, sets direction and monitors performance and compliance, and in most enterprises is the responsibility of the board; management plans, builds, runs and monitors activities in line with the direction the governance body sets. Each governance objective relates to a governance process and each management objective to a management process; boards and executive management are typically accountable for governance processes, while management processes are the domain of senior and middle management.

  • IT strategy alignment

    IT strategy should flow from business strategy. The IT strategic plan is a long-term plan (roughly three to five years) in which business and IT management together describe how IT resources will contribute to the enterprise's strategic objectives. COBIT's goals cascade makes the same point: stakeholder drivers and needs are translated into enterprise goals, and alignment goals, which emphasize aligning all IT efforts with business objectives, relate to those enterprise goals and link them to the governance and management objectives. A plan built from technical wish lists with no link to business goals is a finding.

  • Segregation of duties (SoD)

    No single person should control every stage of a transaction: initiating it, recording it, holding custody of the related assets, and reconciling it. In IT, the same principle keeps any one person from introducing fraudulent or malicious code without detection, and keeps staff who administer access control from also administering audit functions. Where headcount makes full SoD impossible, compensating controls (more frequent auditing, targeted training, stronger personnel screening) are the recognized practice.

  • Outsourcing and third-party assurance

    Outsourcing a function does not outsource accountability, which stays with the board. Contracts should define service levels, establish the right to audit, and state which audit reports (such as SOC reports) the provider must supply. To evaluate the provider's controls, the auditor can test them at the service organization or obtain a service auditor's report on their operating effectiveness.

  • Policies, procedures and guidelines

    A policy communicates required and prohibited activities and behaviors. A procedure gives the detailed steps to perform specific operations in line with applicable standards. A guideline describes a way of accomplishing something and is less prescriptive than a procedure. Whatever the level, the auditor checks that policies and procedures are developed, documented, disseminated to the people who need them, and reviewed and updated on a defined schedule.

  • IT performance monitoring

    A balanced scorecard organizes performance measures into financial, customer, internal business process, and learning and growth perspectives. Performance indicators are metrics that measure the extent to which performance objectives are being achieved on an ongoing basis. Auditors look for metrics that track progress against a set target, are reported with enough context (risk, fit with risk appetite), and lead to action or decisions when targets are missed.

Confusable Pairs
  • IT strategy committee vs. IT steering committee

    The IT strategy committee operates at board level, ensuring the board is involved in major IT matters and decisions. The IT steering committee is an executive management group that assists in delivering the IT strategy, oversees day-to-day management of IT service delivery and IT projects, and focuses on implementation.

  • SOC 1 vs. SOC 2, Type 1 vs. Type 2

    SOC 1 reports cover controls at a service organization likely to be relevant to user entities' internal control over financial reporting; SOC 2 reports address security, availability, processing integrity, confidentiality, and privacy. A type 1 report covers whether the service organization's description of its system is fairly presented and whether controls were suitably designed as at a specified date; a type 2 report also covers whether the controls operated effectively throughout a specified period, and includes the service auditor's tests of controls and their results. That test evidence is what an auditor needs to evaluate operating effectiveness, which makes the type 2 report the stronger evidence.

  • EDM monitoring vs. MEA monitoring

    Both involve monitoring, which is why they get confused. EDM is the governance domain: leadership sets I&T objectives, goals and strategy, and regularly monitors performance to judge whether technology is performing as expected and delivering the intended value. MEA focuses on evaluating the effectiveness of systems and governance structures through regular performance assessments and governance evaluations, feeding continuous improvement. ISACA's glossary places monitoring by the board, as the governance body, in governance, and the monitoring of activities in line with the direction governance sets in management.

Sources
  1. [1]
  2. [2]
  3. [3]
  4. [4]
  5. [5]
  6. [6]
  7. [7]
  8. [8]
  9. [9]
  10. [10]
  11. [11]
  12. [12]
  13. [13]
  14. [14]
  15. [15]
  16. [16]
  17. [17]
  18. [18]
  19. [19]
  20. [20]
  21. [21]
  22. [22]
  23. [23]
  24. [24]
  25. [25]
  26. [26]
  27. [27]
  28. [28]

Practice D2 questions with instant feedback, free to start, no card required.

Start Free
Your cookie choices
We use essential cookies to run this site, and, only with your consent, advertising cookies from Google, LinkedIn, and Reddit to measure ad performance. See our for details.