CISA Domain 2 Study Guide: Governance Essentials
A comprehensive study guide covering the essential IT governance concepts tested in CISA Domain 2, including frameworks, structures, and audit considerations.
CISA Domain 2, Governance and Management of IT, covers the frameworks, structures, and processes that ensure IT supports organizational objectives. This study guide summarizes the essential concepts candidates should master for exam success.
IT Governance Frameworks
Understanding the major governance frameworks is foundational for Domain 2.
- COBIT: A comprehensive framework for IT governance and management that defines processes, control objectives, and maturity models. COBIT separates governance (evaluate, direct, monitor) from management (plan, build, run, monitor).
- ISO 38500: The international standard for corporate governance of IT, built on six principles: responsibility, strategy, acquisition, performance, conformance, and human behavior.
- ITIL: A service management framework that defines best practices for delivering IT services, organized around the service lifecycle.
Governance Structures
Candidates should understand the key governance structures and their roles.
Board and Senior Management
The board provides strategic direction and oversight, while senior management executes the IT strategy. Key roles include the CIO, CISO, and CTO. IS auditors evaluate whether these structures provide effective governance.
IT Steering Committee
A cross-functional governance body that aligns IT priorities with business objectives, approves major investments, and monitors IT performance. Auditors should assess committee composition, charter, and decision-making effectiveness.
Key Governance Processes
IT Strategy and Planning
The IT strategic plan should align with the business strategy, define priorities, allocate resources, and include measurable objectives. Auditors evaluate alignment, completeness, and whether the plan is actively used to guide decisions.
Risk Management
IT risk management involves identifying, assessing, treating, and monitoring risks to information systems. Candidates should understand risk assessment methodologies, risk treatment options (accept, mitigate, transfer, avoid), and the role of risk appetite in governance decisions.
Performance Measurement
Tools such as the Balanced Scorecard, KPIs, and maturity models help organizations measure IT performance. Auditors assess whether metrics are meaningful, regularly reviewed, and used to drive improvement.
Compliance and Regulatory Considerations
IS auditors must evaluate how organizations manage compliance with laws, regulations, and standards. Key areas include regulatory inventories, gap analyses, compliance monitoring, and reporting to management.
Important Regulations
- SOX for financial reporting controls
- GDPR for data protection
- HIPAA for healthcare information
- PCI DSS for payment card data
IT Resource Management
Domain 2 covers how organizations manage IT resources, including financial management (budgeting, TCO, ROI), human resource management (skills, training, succession planning), and vendor management (selection, monitoring, contracts).
Audit Considerations
IS auditors should focus on several key areas when evaluating IT governance.
- Whether governance structures are formally established and documented
- Whether IT strategy aligns with business objectives
- Whether risk management processes are mature and effective
- Whether performance is measured and reported to stakeholders
- Whether compliance programs address all applicable requirements
- Whether resource management supports organizational needs
Exam Tips
When answering Domain 2 questions, remember that governance is about direction and oversight (what the board and senior management do), while management is about execution (what IT leadership and staff do). The IS auditor's role is to provide independent assurance on governance effectiveness, not to implement or manage controls. Focus on understanding why controls exist and what risks they address, not just the technical details of how they work.