Available now

Domain 2: Governance and Management of IT

How the organisation directs and controls IT, and what an auditor looks for when it does not.

18%
of the exam
11
lessons
33
exam questions
84
minutes

Start here

IT Governance and the Board's Role

  1. 1IT Governance and the Board's RoleGovernance sets direction and holds management to account; management runs IT within it. Confusing the two is the fastest way to answer a Domain 2 question wrong.8 min · 3 questions · video
  2. 2IT Strategy and Business AlignmentAn IT strategy that does not trace back to a business objective is a wish list. The exam tests whether IT investment is driven by the business or by the technology.8 min · 3 questions · video
  3. 3Policies, Standards, Procedures and GuidelinesFour documents that candidates blur together. The exam tests which is mandatory, which is specific, and which one management can change without going back to the board.7 min · 3 questions · video
  4. 4Organisational Structure and Segregation of DutiesThe one person who can request, approve, make and review a change is a control failure with a job title. How the exam tests segregation of duties in IT.8 min · 3 questions · video
  5. 5Enterprise ArchitectureEnterprise architecture is the map that keeps IT aligned with the business as both change. Auditors test whether the map is followed, not whether it is beautiful.7 min · 3 questions · video
  6. 6IT Risk Management: Identification, Assessment and ResponseIdentify, assess, respond, monitor. The exam tests the order, the vocabulary of the four responses, and who is actually allowed to choose.9 min · 3 questions · video
  7. 7Risk Appetite, Tolerance and AcceptanceHow much risk the organisation will carry is a board decision, not an IT one. The exam tests who sets appetite, who may accept a risk, and at what level.7 min · 3 questions · video
  8. 8Third-Party and Vendor ManagementYou can outsource the work but not the accountability. The exam tests the right to audit, what a contract must fix before signing, and who still owns the risk.8 min · 3 questions · video
  9. 9Service Level Agreements and Performance MonitoringAn SLA nobody measures is a paragraph, not a control. The exam tests what makes a service level meaningful and how an auditor knows it is actually met.7 min · 3 questions · video
  10. 10Performance Measurement and the IT Balanced ScorecardA KPI looks back at what happened; a KRI warns before it does. The exam tests the difference, and why the IT balanced scorecard refuses to measure IT by cost alone.7 min · 3 questions · video
  11. 11Laws, Regulations and Compliance ManagementThe final Domain 2 lesson. How an organisation knows which obligations apply, proves it meets them, and why the auditor reports non-compliance rather than fixing it.8 min · 3 questions · video

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Domain structure reflects the published exam content outline and is not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.