CISA D2: Governance and Management of IT
Domain 2 (18% weight) covers how IT is directed and controlled: governance structures, IT strategy, policies and standards, enterprise architecture, risk management, resource and vendor management, performance monitoring, and quality management. It overlaps heavily with CISM Domain 1, but CISA asks a different question. Not "what should the security manager do," but "is there evidence that governance is designed and operating effectively, and what should the auditor report if it isn't."
Governance vs. management in COBIT 2019
COBIT 2019 separates one governance domain, EDM (Evaluate, Direct and Monitor), owned by the board, from four management domains: APO (Align, Plan and Organize), BAI (Build, Acquire and Implement), DSS (Deliver, Service and Support), and MEA (Monitor, Evaluate and Assess). Governance sets direction; management plans, builds, runs, and monitors against it.
IT strategy alignment
IT strategy should flow from business strategy. An auditor reviewing an IT strategic plan checks that it maps to business objectives, has executive sponsorship, and is revisited as the business changes. A plan built from technical wish lists with no link to business goals is a finding.
Segregation of duties (SoD)
No single person should control every stage of a transaction: authorization, custody of assets, recording, and reconciliation. Classic IT conflicts include developers with production access and administrators who can approve their own access changes. Where headcount makes full SoD impossible, compensating controls (supervisory review, log review, reconciliation) are the expected answer.
Outsourcing and third-party assurance
Outsourcing a function does not outsource accountability. Contracts should include SLAs, security requirements, and a right-to-audit clause. When auditing the provider directly is impractical, independent assurance reports such as SOC 1 or SOC 2 become the auditor's primary evidence.
Policy development: top-down vs. bottom-up
Top-down policy starts from enterprise objectives and guarantees alignment with strategy. Bottom-up starts from operational risk assessments and guarantees practicality. Either way, the auditor checks that policies are approved by management, communicated, periodically reviewed, and actually followed.
IT performance monitoring
IT balanced scorecards and KPIs measure whether IT delivers business value, not just whether systems are up. Auditors look for metrics that are defined, owned, reported to the right level, and acted on when targets are missed.
IT strategy committee vs. IT steering committee
The IT strategy committee operates at board level, advising the board on IT's strategic direction and value. The IT steering committee is a senior management group that oversees execution: approving and prioritizing projects, allocating resources, and tracking delivery. A question about prioritizing projects points to the steering committee.
SOC 1 vs. SOC 2, Type 1 vs. Type 2
SOC 1 reports cover controls relevant to a customer's financial reporting; SOC 2 reports cover the Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). A Type 1 report describes control design at a point in time; a Type 2 report also tests operating effectiveness over a period, which makes it the stronger evidence.
EDM monitoring vs. MEA monitoring
Both involve monitoring, which is why they get confused. EDM is the board overseeing whether IT as a whole meets enterprise objectives (governance). MEA is management monitoring its own performance and internal controls (management). Board-level oversight is always EDM.
Sources: ; ;
CISA practice exams are in development. Get every CISA domain in one printable guide, free with an account.
Get the Complete Guide