Available now

Domain 4: IS Operations and Business Resilience

Running IT day to day and surviving when it breaks. Joint largest domain on the exam.

26%
of the exam
15
lessons
45
exam questions
109
minutes

Start here

IT Service Management and Service Levels

  1. 1IT Service Management and Service LevelsIT run as services to the business, with a service desk as the single point of contact. The exam tests the difference between an incident and a service request, and how priority is set.7 min · 3 questions · video
  2. 2Incident ManagementThe one job of incident management is to restore service fast, not to find the cause. The exam tests that distinction, and that a workaround is a legitimate resolution.7 min · 3 questions · video
  3. 3Problem ManagementIncidents restore service; problem management removes the cause so they stop happening. The exam tests the distinction, and recognises the repeated incident as a problem to investigate.7 min · 3 questions · video
  4. 4Change ManagementThe most important operational control: no change reaches production without authorisation, testing and a way back. The exam tests emergency changes and the segregation that stops a developer approving their own work.8 min · 3 questions · video
  5. 5Configuration ManagementYou cannot control what you cannot see. Configuration management is the authoritative record of what is in production, and the baseline that lets you detect unauthorised change.7 min · 3 questions · video
  6. 6Release and Patch ManagementCode and patches reach production through separated environments and are prioritised by risk. The exam tests why dev, test and production must be kept apart, and how patches are ranked.8 min · 3 questions · video
  7. 7Job Scheduling and Automated OperationsAutomation removes manual effort, not the need for control. The exam tests exception handling, completeness of scheduled runs, and who is allowed to change the schedule.7 min · 3 questions · video
  8. 8Capacity, Performance and Database ManagementCapacity management looks forward, not back, and a DBA changing data directly bypasses every application control. The exam tests proactive capacity planning and the risk of privileged database access.7 min · 3 questions · video
  9. 9End-User Computing and Data GovernanceA spreadsheet feeding the financial statements is an application with none of an application's controls. The exam tests the risk of end-user computing and who actually owns data.7 min · 3 questions · video
  10. 10Business Impact AnalysisBefore you can recover anything, you have to know what matters and how fast. The BIA is the foundation of resilience, and the exam tests that it comes first and that the business, not IT, sets criticality.7 min · 3 questions · video
  11. 11Recovery Objectives: RPO and RTOThe two metrics the exam tests hardest. RPO is how much data you can lose; RTO is how long you can be down. Confusing them is the classic trap, and the cost rises as either shrinks.7 min · 3 questions · video
  12. 12Data Backup and RestorationA backup that has never been restored is a hope, not a control. The exam tests that restoration testing, not the backup job, is what proves recoverability, and that backups must be stored away from what they protect.8 min · 3 questions · video
  13. 13System Resilience and High AvailabilityResilience keeps a system running through a component failure; recovery brings it back after a disaster. The exam tests that distinction, and the crucial point that RAID and redundancy are not a backup.7 min · 3 questions · video
  14. 14Business Continuity PlanningThe BCP keeps the whole business running through a disruption; the DR plan is its IT subset. The exam tests that scope difference, and that a plan never tested or updated gives no assurance.7 min · 3 questions · video
  15. 15Disaster Recovery: Sites and Test TypesThe last Domain 4 lesson. Hot, warm and cold sites trade cost against recovery speed, and DR test types trade assurance against risk. The exam tests both ladders, and that an untested plan proves nothing.8 min · 3 questions · video

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Domain structure reflects the published exam content outline and is not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.