IT Governance: Exam Tips
COBIT Aligns IT With Business Objectives
COBIT provides a framework for governance and management of enterprise IT. It distinguishes between governance processes (evaluate, direct, monitor) and management processes (plan, build, run, monitor), each with distinct responsibilities.
IT Strategy Must Support Business Strategy
The IT strategic plan should be derived from and aligned with the organization's business strategy. The IS auditor should verify that the IT steering committee includes both IT and business stakeholders to ensure this alignment.
Understand the IT Balanced Scorecard Approach
The IT balanced scorecard translates IT strategy into measurable objectives across four perspectives: financial, customer, internal process, and learning and growth. It helps demonstrate how IT investments contribute to organizational value.
Risk Management Requires a Structured Framework
Enterprise risk management (ERM) integrates IT risk into the overall organizational risk profile. Risk appetite is set by the board, risk tolerance defines acceptable variation, and residual risk must be formally accepted by management.
Data Governance Establishes Ownership and Accountability
Data governance defines who is responsible for data quality, classification, and lifecycle management. The data owner (typically a business manager) determines the classification level, while the data custodian (typically IT) implements the technical controls.
Vendor Management Requires Due Diligence
Third-party risk management begins with due diligence before contract signing and continues through ongoing monitoring. The organization remains accountable for data protection and regulatory compliance regardless of outsourcing arrangements.
Regulatory Compliance Needs Continuous Monitoring
Compliance requirements should be identified, documented, and mapped to specific controls. The IS auditor should verify that the organization has a process for tracking regulatory changes and assessing their impact on IT operations.
Policies Drive the Governance Hierarchy
The governance hierarchy flows from policies (high-level intent) to standards (mandatory requirements) to procedures (step-by-step instructions) to guidelines (recommended practices). Policies should be approved by senior management and reviewed periodically.
Resource Optimization Maximizes IT Value
IT resource management covers people, infrastructure, applications, and information. The IS auditor should evaluate whether the organization has adequate succession planning, skills development, and capacity management processes in place.
Performance Measurement Validates Governance Effectiveness
Key performance indicators (KPIs) measure process efficiency, while key goal indicators (KGIs) measure outcome achievement. Maturity models help organizations assess their current capability level and plan improvements systematically.