CISA - Governance and Management of IT - Section 2.2

Assess IT performance monitoring and reporting and IT quality assurance and management.

Understand how IT performance monitoring and reporting translate operational metrics into management information for governance decisions. Assess quality assurance and quality management practices to confirm that IT services consistently meet defined standards.

IT performance monitoringperformance reportingquality assurancequality management

Practice question for this objective

Free sampleGovernance and Management of ITeasy

An IS auditor is examining how the IT quality function is positioned within a software development organisation. What is the PRIMARY conceptual difference between quality assurance and quality control as defined in established quality management literature?

  • AQuality assurance inspects finished deliverables to identify defects, whereas quality control defines the policies and standards that the deliverables are produced under in the first place.
  • BQuality assurance is performed only by external auditors as part of certification work, whereas quality control is performed by internal staff during day-to-day operations.
  • CQuality assurance focuses on preventing defects by improving the process used to produce work, whereas quality control focuses on detecting defects in the work product itself. Correct
  • DQuality assurance applies only to bespoke software development, whereas quality control applies to all hardware, infrastructure and outsourced services delivered to the business.
Differentiate quality assurance from quality control in an IT delivery context as part of the quality management body of knowledge. ISO 9001 and the PMBOK Guide draw a clear line: quality assurance is a process activity that seeks to prevent defects by ensuring the right method is followed, while quality control is a product activity that inspects the deliverable and detects defects. Confusing the two leads to misallocated effort and weak audit conclusions.

Why A is wrong: Tempting because the two terms are commonly swapped in conversation, but this reverses the standard definitions used in ISO 9001 and PMI literature.

Why B is wrong: Plausible because external certification bodies do review quality systems, but both functions are routinely performed by internal staff; the difference is what they target, not who performs them.

Why C is correct: This is the canonical ISO 9001 distinction: assurance is process-centric and preventive, while control is product-centric and detective, with both functions feeding continual improvement.

Why D is wrong: Misleading because both concepts apply across all delivery types in an IT organisation, not only to software or only to infrastructure.

See more CISA practice questions, answers explained.

More in this domain

Back to all Governance and Management of IT objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.