CISA - Governance and Management of IT (18% of the exam) - Section 2.2

Assess IT performance monitoring and reporting and IT quality assurance and management.

Understand how IT performance monitoring and reporting translate operational metrics into management information for governance decisions. Assess quality assurance and quality management practices to confirm that IT services consistently meet defined standards.

IT performance monitoringperformance reportingquality assurancequality management

Practice question for this objective

Free sampleGovernance and Management of ITeasy

An IS auditor is examining how the IT quality function is positioned within a software development organisation. What is the PRIMARY conceptual difference between quality assurance and quality control as defined in established quality management literature?

  • AQuality assurance inspects finished deliverables to identify defects, whereas quality control defines the policies and standards that the deliverables are produced under in the first place.
  • BQuality assurance is performed only by external auditors as part of certification work, whereas quality control is performed by internal staff during day-to-day operations.
  • CQuality assurance focuses on preventing defects by improving the process used to produce work, whereas quality control focuses on detecting defects in the work product itself. Correct
  • DQuality assurance applies only to bespoke software development, whereas quality control applies to all hardware, infrastructure and outsourced services delivered to the business.
Differentiate quality assurance from quality control in an IT delivery context as part of the quality management body of knowledge. ISO 9001 and the PMBOK Guide draw a clear line: quality assurance is a process activity that seeks to prevent defects by ensuring the right method is followed, while quality control is a product activity that inspects the deliverable and detects defects. Confusing the two leads to misallocated effort and weak audit conclusions.

Why A is wrong: Tempting because the two terms are commonly swapped in conversation, but this reverses the standard definitions used in ISO 9001 and PMI literature.

Why B is wrong: Plausible because external certification bodies do review quality systems, but both functions are routinely performed by internal staff; the difference is what they target, not who performs them.

Why C is correct: This is the canonical ISO 9001 distinction: assurance is process-centric and preventive, while control is product-centric and detective, with both functions feeding continual improvement.

Why D is wrong: Misleading because both concepts apply across all delivery types in an IT organisation, not only to software or only to infrastructure.

See more CISA practice questions, answers explained.

Exam traps in Governance and Management of IT

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • A KPI is always reported quarterly to the board, whereas a KRI is reported only when a control failure has actually occurred during the period.

    Why it is wrong: Tempting because governance committees do receive periodic packs, but reporting frequency is set by policy and does not define either indicator; KRIs are predictive, not post-event.

  • The arrangement is acceptable because consolidating security under the chief information officer simplifies decision-making and reduces operational friction during incidents that span multiple business units.

    Why it is wrong: Operational simplicity does not cure a structural conflict. CISA reasoning treats the lack of independent reporting as a governance weakness, regardless of how decisively the combined function appears to operate day to day.

  • IT governance is the daily oversight of IT operations by the chief information officer, while IT management is the strategic stewardship exercised by the audit committee.

    Why it is wrong: This inverts the recognised roles. The board and its committees govern, and the chief information officer manages; conflating the two undermines the separation of decision rights established by COBIT 2019.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.