CISA - Governance and Management of IT (18% of the exam) - Section 2.2

Evaluate IT resource management and IT vendor management practices.

Describe how IT resource management ensures that people, hardware and software assets are acquired, deployed and retired in a controlled manner. Evaluate IT vendor management and outsourcing arrangements to confirm that third-party risks are identified and contractually mitigated.

IT resource managementIT vendor managementthird-party managementoutsourcing

Practice question for this objective

Free sampleGovernance and Management of ITmedium

Which statement BEST distinguishes IT vendor management from third-party risk management as the IS auditor would evaluate them?

  • AVendor management is concerned with cyber risk only, whereas third-party risk management covers the wider commercial relationship with each strategic supplier of the organisation.
  • BVendor management is a board-level oversight activity, while third-party risk management is delegated to procurement to negotiate price reductions and renewal terms with suppliers.
  • CVendor management focuses on commercial performance against service-level targets, while third-party risk management focuses on the residual risk the relationship introduces across the enterprise. Correct
  • DVendor management addresses only outsourced data centres, while third-party risk management addresses software-as-a-service and other cloud arrangements that bypass classical procurement.
Distinguish IT vendor management from third-party risk management by their respective focus on commercial performance and on residual enterprise risk. Vendor management is a performance and contractual discipline that tracks service levels, deliverables and commercial value, while third-party risk management is an enterprise risk discipline that evaluates how each supplier relationship affects information security, resilience, regulatory and concentration risk. ISACA guidance and ISO/IEC 27036 treat them as complementary but distinct, which is why an IS auditor expects separate but linked governance artefacts.

Why A is wrong: This inverts the disciplines, since vendor management is the broader commercial discipline and third-party risk management is the risk-focused overlay; an auditor would mark this confusion as incorrect.

Why B is wrong: This is tempting because procurement does sit close to vendors, but governance of third-party risk sits with senior management and the board, not the procurement desk; this misallocates accountability.

Why C is correct: This captures the recognised split: vendor management is performance and contract-led, while third-party risk management is risk-led and covers information security, resilience, compliance and concentration exposure across the supplier portfolio.

Why D is wrong: This narrow framing is plausible to a candidate thinking only of hosting, but both disciplines apply across the whole supplier portfolio regardless of delivery model, so the scope claim is wrong.

See more CISA practice questions, answers explained.

Exam traps in Governance and Management of IT

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • Operating budget rather than capital budget is used, which prevents the assets from being depreciated over their useful economic life.

    Why it is wrong: The accounting classification of the spend is a finance matter and is not itself an IT governance failure; the auditor's concern is whether resources are aligned to business demand and the investment plan, not which budget line they are charged to.

  • Resource management is a management objective limited to forecasting cloud infrastructure spend within the technology operations function on a rolling twelve-month horizon.

    Why it is wrong: This is tempting because cloud spend dominates current practice, but COBIT treats resource management as a governance-level objective covering all IT resources, not a narrow operations forecast.

  • Negotiate volume-based pricing tiers with the vendor to ensure the unit cost of subscriptions decreases as the customer base grows over the contract term.

    Why it is wrong: Commercial optimisation is a procurement objective and may form part of the negotiation, but it does not address the principal risk to the organisation before signing, which is whether the vendor can meet the security, availability and confidentiality requirements of the service.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.