CISA Domain 2: Governance and Management of IT, in Plain English

CISA Domain 2: Governance and Management of IT, 18% of the exam, about 27 questions

One sentence makes CISA Domain 2 smaller than it looks: the exam is asking whether IT is actually governed, not whether governance documents exist. A policy binder, a committee charter, and a risk register prove that someone wrote three documents. They prove nothing about whether decisions get made, whether anyone owns the outcome, or whether the organization would notice if the answer were no. Most Domain 2 questions are a version of that distinction.

The content behind it: Governance and Management of IT is 18% of the exam, roughly 27 of the 150 questions, tied with Domain 1 behind the two 26% domains. It comes in two halves. IT governance runs from laws and standards through organizational structure, IT strategy, the policy hierarchy, enterprise architecture, enterprise risk management, the privacy program, and data governance. IT management covers resources, vendors, performance monitoring, and quality.

What does CISA Domain 2 cover?

The governance half is about direction and accountability. It asks who decides, on what authority, against what obligations, and how those decisions get recorded and reviewed. That covers applicable laws and regulations, adopted frameworks, the board and committee structure, IT strategy and its traceability back to business strategy, the document hierarchy that turns intent into requirements, enterprise architecture, the risk program, the privacy program, and the rules for how data is owned and classified.

The management half is about execution. It asks whether IT has the people, money, capacity, and suppliers to do what governance told it to do, and whether anyone is measuring the result. That is resource management, vendor management, performance monitoring and reporting, and quality management.

Both halves are tested from the auditor's seat. You are never asked to write the policy, chair the committee, or select the vendor. You are asked what you would look at, what counts as a finding, and what to do first. If that lens is new to you, CISA domains explained walks all five domains from the same angle, and Domain 1 is where the auditor's role is established.

Governance or management: which level is the question asking about?

The most useful thing in Domain 2 is the line between governance and management. COBIT draws it cleanly; the exam follows.

Dimension Governance Management
Who Board, IT strategy committee CIO, IT management, staff
What Sets direction, approves risk appetite, monitors outcomes Executes plans, operates controls, reports performance
Accountability Final, cannot be delegated away Delegated from the governance level

A large share of Domain 2 items are "who is responsible" stems in disguise. Who ensures IT aligns with business strategy? Governance level. Who implements the IT security policy? Management. Who approves risk appetite? The board. Who accepts a risk inside tolerance? Management. Once the mapping is automatic, those take fifteen seconds each.

One pair trips people up constantly. The IT strategy committee sits at board level and looks at whether IT investment serves business direction. The IT steering committee sits at management level and coordinates priorities across business units, usually chaired by an executive such as the CIO. Similar names, different altitude, different answers.

The related idea is the three lines model. First line is operational management, who own and run the controls. Second line is risk and compliance, who set the framework and monitor without owning the controls. Third line is internal audit, providing independent assurance to the board. You are the third line, and knowing which line an option puts you in resolves a surprising number of Domain 2 stems before you have read the fourth option.

Policy, standard, procedure, guideline: which is which?

Candidates confuse these four constantly and the exam tests the distinction directly. Learn them as a chain running from broad intent to specific action, each level implementing the one above it.

A policy is a high-level statement of intent or required outcome, approved by senior leadership. It sets the what and the why, written broadly enough to stay stable for years. "All information assets must be classified according to sensitivity."

A standard is a specific, measurable requirement that implements a policy. It sets how much or what exactly, and it is mandatory. "Data classified as Confidential must be encrypted at rest using AES-256 or equivalent." Standards change more often than policies because they name technologies and thresholds.

A procedure is the step-by-step instruction for carrying out a task in line with a standard. It sets how, in what order, and by whom: which form the data owner completes, who approves it, how the label is applied.

A guideline is non-mandatory. It suggests a preferred approach or explains how to meet a standard in common situations. This is the one that costs marks. Policies, standards, and procedures bind; guidelines advise. A stem describing staff who did not follow a guideline describes a discretionary choice, not a compliance breach.

Two exam habits follow. First, if a stem describes a requirement that is specific, measurable, and mandatory, it is a standard, even if the organization titled the document a policy. Test against the definition, not the file name. Second, the auditor evaluates the hierarchy for completeness, internal consistency (lower documents must not contradict higher ones), currency (reviewed within the defined cycle), and ownership (every document has a named accountable owner).

The pitfall underneath all of this is treating a document as evidence of a control. The control is the behavior. The auditor walks from policy to standard to procedure and then tests actual practice. If the policy says privileged access requires manager approval before provisioning, sample provisioning records and check whether approvals came first. A policy violated without consequence teaches the workforce that it is optional.

What else does the governance half test?

Laws, regulations, and standards come first. You do not need to memorize regulatory text. You need three questions: has the organization identified which obligations apply, has it translated them into internal requirements, and can it evidence that those requirements are met? A gap at any step is a finding, and a compliance inventory that lives only in Legal and never reaches IT is a common one. Know what the frameworks are for rather than their internal structure: COBIT for enterprise governance of IT, ISO/IEC 27001 for a certifiable information security management system, NIST for control catalogs and the Cybersecurity Framework, ITIL for service management. Claiming alignment to any of them without evidence of implementation is itself a finding.

Nobody will ask you to read an architecture diagram. The enterprise architecture questions ask whether the architecture is governed: the organization should hold a current state, an approved target state, and a transition plan, and the auditor tests whether investments actually move toward the target and whether deviations get detected. A system bought by a business unit outside that process is an architecture failure and a shadow IT risk at once.

Enterprise risk management brings one distinction worth memorizing. Risk appetite is the amount of risk the organization is willing to accept, set by the board. Risk tolerance is the acceptable variation around that appetite in a specific area. Risks inside tolerance can be accepted by management; risks above appetite must escalate to governance. Management routinely accepting risks above appetite without board visibility is a governance failure, and the exam grades it as one. Expect ownership questions too: a risk register that lists risks without named owners fails a basic requirement.

The privacy program is tested as an operating program with evidence behind it. Look for privacy by design, evidenced by privacy impact assessments before go-live rather than after; a named accountability structure such as a Data Protection Officer or Chief Privacy Officer; a documented legal basis for each processing activity; data subject rights handled within regulatory time limits; and a breach notification procedure with defined timelines.

Data governance closes the half. The data owner is a business role accountable for classification and access decisions; the data steward is an operational role that maintains quality and applies labels day to day. Classification schemes are judged on whether the scheme is approved and communicated, whether it is actually applied to real assets, and whether the controls at each level match what the scheme demands. Data labeled Restricted sitting on an unencrypted share is exactly the gap the exam wants you to spot. Retention runs both ways: keeping data past its schedule creates liability, destroying it early breaches obligations.

What does the management half test?

Resource management is people, capacity, and sourcing. The audit angles are staffing adequate to operate the controls, key-person risk where one undocumented individual holds a critical system together, and whether resource allocation ties spending to strategy instead of ad hoc negotiation between project managers.

Vendor management carries the most weight in this half, and one sentence covers most of it: outsourcing transfers execution, not accountability. The right-to-audit clause is the recurring item. With it, the auditor can obtain direct evidence about third-party controls; without it, the organization falls back to weaker assurance such as SOC 1 or SOC 2 reports, ISO/IEC 27001 certification, or questionnaire responses. Note that ranking, because "what is the BEST evidence" stems depend on it. Also expect SLAs that are unenforceable because nothing measures them, subcontracting clauses (your vendor's vendor is your fourth party), and supply chain integrity risk where a component is compromised before it reaches you.

Performance monitoring is about whether measurement is honest. A KPI measures progress against an objective; a KRI signals rising risk exposure. The auditor checks that the underlying data is reliable, that targets were set by a governance body rather than by the function being measured, and that missing a target triggers a documented response. Treat a dashboard that is green every period without variation as a finding about the measurement itself. The balanced scorecard matters here for why it exists: it forces IT performance to be viewed from several perspectives instead of budget variance alone. Benchmarking is judged on whether the comparators are fair and whether anyone acted on the result.

Quality management closes the domain. Quality assurance is proactive and process-focused, building the process that produces good outputs. Quality control tests outputs after the fact. An organization doing only the second generates defects forever. Maturity models such as CMMI let the auditor state a current level, compare it to what the risk profile requires, and write the gap as a finding.

Where should you spend your Domain 2 study time?

Not evenly. Four things repay study time heavily: the governance and management split, the policy hierarchy, the three lines model, and vendor management with right-to-audit and the evidence ranking behind it. Those four likely carry most of the 27 questions between them, and each is a clean distinction you can drill until it is reflexive.

Framework internals repay much less. Knowing what COBIT, COSO ERM, TOGAF, and CMMI are for is enough. Memorizing the components of COSO ERM or the columns of the Zachman Framework is a poor trade against the same hour spent on the two 26% domains. Domain 2 is also the friendliest domain for non-technical candidates. If you come from audit or compliance rather than engineering, this is where you bank marks to spend on the technical half of the paper. Our CISA study guide treats Domain 2 the way the exam does, as a short list of distinctions you need reflexively right, and every practice question comes with the reasoning that separates the credited answer from its runner-up.

Domain 2 shares more vocabulary with the CISM than any other part of the CISA, so some of this will feel familiar if you have looked at both. The lens differs: CISM asks you to build and run the governance program, CISA asks you to assure it. We compare them in CISA vs CISM. For format, scoring, and eligibility, start with what the CISA exam is.

FAQ

How many questions is CISA Domain 2 on the exam?

Domain 2 is 18% of the exam. With 150 multiple-choice questions on the paper, that works out to roughly 27 questions, though ISACA does not publish an exact per-domain count for any given form. It ties Domain 1 as the second-heaviest domain, behind Domains 4 and 5 at 26% each.

What is the difference between a policy, a standard, a procedure, and a guideline?

A policy is a broad statement of intent approved by leadership. A standard is a specific, measurable, mandatory requirement that implements a policy. A procedure is the step-by-step instruction for carrying out a task in line with a standard. A guideline is advisory rather than mandatory. Policies, standards, and procedures bind; guidelines suggest.

Is CISA Domain 2 hard?

It is one of the more approachable domains, especially if your background is audit, risk, or compliance rather than engineering. The content is conceptual rather than technical, and much of it reduces to a small number of distinctions such as governance versus management and appetite versus tolerance. The difficulty is precision: the exam will punish loose use of terms it treats as distinct.

What is the most common Domain 2 mistake?

Treating the existence of a document as evidence of a control. A policy, a charter, or a risk register proves that something was written, not that anything is governed. The auditor traces from the document down to observed behavior and tests whether the requirement is communicated, implemented, and enforced.

Does Domain 2 overlap with the CISM?

Substantially, in vocabulary. Both cover governance structures, risk appetite, policy hierarchies, and third-party risk. The difference is the seat you are sitting in: CISM tests whether you can build and run the program, CISA tests whether you can independently assure it. Material from one credential is useful background for the other, but the answer patterns differ.


Looking for a plain-English CISA guide? ISACA CISA: Certified Information Systems Auditor Study Guide covers all five domains with four full-length practice exams, every answer explained.

Simply Certified is an independent publisher. CISA and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.