CISA domain - 18% of the exam

Governance and Management of IT

Governance and Management of IT is 18% of the Certified Information Systems Auditor (CISA) (CISA) exam. These are the objectives it covers, each with practice questions and worked explanations.

Objectives in this domain

Sample question from this domain

Free sampleGovernance and Management of ITmedium

Which statement BEST distinguishes IT governance from IT management within an enterprise?

  • AIT governance is the daily oversight of IT operations by the chief information officer, while IT management is the strategic stewardship exercised by the audit committee.
  • BIT governance is performed only by external auditors providing assurance over IT, while IT management is performed by internal audit through control self-assessment.
  • CIT governance is identical to IT management once a control framework such as COBIT 2019 has been adopted across the enterprise.
  • DIT governance directs and evaluates the enterprise so that IT supports strategic objectives, while IT management plans, builds and runs IT services to deliver agreed outcomes. Correct
Distinguish IT governance from IT management as separate but linked accountabilities defined by COBIT 2019 and ISO/IEC 38500. Governance is the board-level activity of evaluating, directing and monitoring the use of IT to meet stakeholder needs, while management plans, builds, runs and monitors IT activities within the direction set by governance. COBIT 2019 codifies this split by labelling EDM objectives as governance and APO/BAI/DSS/MEA objectives as management, and ISO/IEC 38500 frames the same separation as the three governance tasks.

Why A is wrong: This inverts the recognised roles. The board and its committees govern, and the chief information officer manages; conflating the two undermines the separation of decision rights established by COBIT 2019.

Why B is wrong: Assurance providers do not govern or manage IT; they evaluate it. Treating audit as the governance function removes accountability from those charged with governance and is a common candidate trap.

Why C is wrong: Adopting a framework does not collapse the distinction. COBIT 2019 explicitly separates the governance objectives from the management objectives precisely to preserve segregation of decision rights.

Why D is correct: This reflects the ISO/IEC 38500 and COBIT 2019 distinction: governance sets direction, evaluates performance, and monitors compliance through the board, whereas management executes the plans within governance constraints.

Other domains in this exam

See also the CISA cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.