is-operations10 min read

CISA Domain 4 Study Guide: Operations and Resilience

A comprehensive study guide for CISA Domain 4 covering IT operations, service management, business continuity, and disaster recovery concepts.

CISAPractice|

Domain 4 Overview

CISA Domain 4, Information Systems Operations and Business Resilience, focuses on the processes and controls that ensure IT services operate effectively and can withstand disruptions. This domain typically represents approximately 23% of the CISA exam, making it one of the most heavily weighted areas. Candidates must understand IT operations management, service level management, business continuity, and disaster recovery from an auditor's perspective.

IT Operations Management

Key Concepts

IT operations management encompasses the day-to-day activities required to deliver and support IT services. Important areas for exam preparation include:

  • IT service management frameworks: ITIL processes including incident, problem, change, release, and configuration management
  • Operations monitoring: Tools, techniques, and procedures for monitoring infrastructure and application health
  • Job scheduling: Batch processing, job dependencies, and automated workflow management
  • Help desk and support: Tiered support models, ticket management, and knowledge base maintenance
  • Capacity and performance management: Planning for growth, optimizing resource utilization, and trend analysis

Service Level Management

Service level management involves defining, negotiating, documenting, and monitoring agreements between IT and its customers. Auditors should understand:

  • The difference between SLAs (with external customers), OLAs (between internal teams), and underpinning contracts (with vendors)
  • How to evaluate whether SLA metrics are meaningful, measurable, and aligned with business objectives
  • The process for reporting on SLA performance and handling breaches

Business Continuity and Disaster Recovery

Planning Process

The business continuity planning process follows a structured lifecycle: risk assessment, business impact analysis, strategy development, plan development, testing, and maintenance. Candidates should understand each phase and the auditor's role in evaluating the maturity and effectiveness of the overall program.

Recovery Concepts

Key recovery concepts that frequently appear on the exam include RTO, RPO, MTD, and the relationship between these objectives and recovery strategy selection. Candidates should be able to evaluate whether an organization's chosen recovery strategy aligns with its stated objectives and business requirements.

Infrastructure and Operations Controls

This section covers controls over hardware, software, network infrastructure, and data center operations. Important topics include:

  • Data center design: Physical security, environmental controls, redundancy, and site selection criteria
  • Network infrastructure: Architecture, segmentation, monitoring, and performance optimization
  • Media management: Handling, storage, transportation, and disposal of backup media
  • Problem and incident management: Root cause analysis, trending, and corrective action tracking

Study Tips for Domain 4

When preparing for Domain 4, focus on understanding the auditor's role in evaluating controls rather than memorizing technical details. Practice identifying control weaknesses in scenario-based questions, and ensure you understand how different operational processes interrelate. Review the concepts of service management, continuity planning, and infrastructure controls through the lens of risk and governance.

Related Tags

CISA ExamStudy GuideIT OperationsBusiness ContinuityDisaster Recovery

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free