CISA · Domain 2
Governance and Management of IT
About 18% of the exam
Governance vs management
- Governance
- evaluate, direct, monitor
- Management
- plan, build, run, monitor
- Board
- ultimate accountability for IT governance
- Executives
- execute the direction set
- Stakeholder value
- benefits, risk, resources balanced
- Outsourcing
- accountability never transfers
Governance asks whether the right things are done; management makes sure things are done right
Roles and committees
- Board of directors
- sets appetite, oversees, approves
- IT steering committee
- prioritizes initiatives, aligns to strategy
- IT strategy committee
- advises the board on IT
- CIO
- delivers IT services and strategy
- CISO
- security program, reports risk
- Data owner
- classifies, decides who accesses
- Data custodian
- implements the owner's decisions
- Data steward
- quality, needs authority to matter
Strategy and alignment
- IT strategic plan follows the business plan
- Portfolio view balances value, cost, risk
- Business case before every investment
- Benefits realization, not just on-time delivery
- Enterprise architecture links systems to strategy
- Shadow IT signals a governance gap
- Cloud shifts governance to shared responsibility
Delivered on time and under budget but no business value is a governance failure
COBIT
- Framework for governance and management of I&T
- Governance objectives: evaluate, direct, monitor
- Management domains: align, build, deliver, monitor
- Seven components: processes, structures, policies, information, culture, skills, infrastructure
- Design factors tailor it to the enterprise
- Capability levels 0 to 5
- Level 3: defined and standardized across the organization
Risk management process
- Identify
- Analyze
- Evaluate
- Treat
- Monitor
- Report
- Identify
- threats, vulnerabilities, assets, horizon scanning
- Analyze
- likelihood times business impact
- Evaluate
- compare against appetite and tolerance
- Treat
- avoid, mitigate, transfer, accept
- Monitor
- KRIs, register, reassess on change
- Risk register
- description, rating, owner, treatment, status
Residual risk is accepted by the business owner or senior management, never by IT or audit
Risk treatment
- Avoid
- stop the activity entirely
- Mitigate
- add or strengthen controls
- Transfer
- insurance, contracts, outsourcing
- Accept
- formal sign-off, documented
- Inherent risk
- before controls are applied
- Residual risk
- what is left after controls
- Insurance limit
- pays after, prevents nothing
Appetite, tolerance, indicators
- Risk appetite
- broad level board will accept
- Risk tolerance
- acceptable variation around appetite
- Risk capacity
- most the enterprise can absorb
- KRI
- early warning of rising exposure
- KPI
- how well a process performs
- KGI
- was the goal reached
- Risk culture
- bypassed controls mean weak culture
Appetite the board never communicates leaves operational managers deciding risk blind
Policy hierarchy
- Policy
- Standard
- Procedure
- Guideline
- Policy
- high level intent, board approved
- Standard
- mandatory specifics that support policy
- Procedure
- step by step instructions
- Guideline
- recommended, not mandatory
- Exception
- risk assessed, compensating control, expiry
Policy without standards and procedures is interpreted differently by every team
Organization and segregation
- Segregation of duties splits incompatible functions
- DBA doing security admin breaks SoD
- Compensating: supervision, logging, independent review
- Mandatory vacation exposes concealed fraud
- Job rotation limits sole control
- Background checks before sensitive roles
- Anonymous reporting channel for violations
- Termination removes access the same day
Third-party and outsourcing
- Accountability stays with the organization
- Right to audit clause in every contract
- Data ownership and return on exit
- SOC 2 Type II covers a period
- Qualified opinion: assess impact, seek compensating controls
- Fourth parties inherit your regulatory duties
- Concentration risk: one provider, many services
- Exit plan prevents vendor lock-in
- SLAs measurable, with penalties
Compliance and privacy
- Map overlapping regulations to common controls
- GDPR breach notice within 72 hours
- DPIA before high-risk profiling
- Cross-border transfer needs adequacy or safeguards
- Sanctions screening against OFAC, EU, UN
- Notification deadlines run regardless of investigation
- Continuous compliance monitoring beats periodic checks
- Siloed GRC duplicates effort, hides gaps
Measuring performance
- Balanced scorecard
- financial, customer, process, learning
- Weak customer view
- efficient but misaligned IT
- Maturity model
- where the process stands today
- Benchmarking
- compare with peers
- Governance metric
- projects delivering expected value
- CSA
- owners assess their own controls
- Investment review
- gate for unplanned initiatives
Key formulas
- SLE
- asset value x exposure factor
- ALE
- SLE x ARO
- ARO
- expected occurrences per year
- Control worth it
- annual cost below ALE reduction
- Residual
- inherent minus control effect
- Risk
- likelihood x impact
Quantitative gives dollars, qualitative gives high, medium, low; the exam asks which one you used
Rapid recall
- EDM
- evaluate, direct, monitor
- APO, BAI, DSS, MEA
- COBIT management domains
- GRC
- governance, risk, compliance integrated
- ERM
- enterprise-wide risk aggregation
- SoD
- no one person completes a fraud
- SCC
- standard contractual clauses for transfers
- ESG
- environmental, social, governance reporting
- M&A due diligence
- IT assessment before the deal
Reference strip: frameworks, roles, risk terms, contracts, regulations
Frameworks
- COBIT 2019 governance and management
- ISO 27001 ISMS, ISO 27005 risk
- ISO 31000 enterprise risk principles
- COSO internal control and ERM
- ITIL service management, NIST CSF
Who approves what
- Board: appetite, policy, governance framework
- Steering committee: priorities, project portfolio
- Business owner: residual risk acceptance
- Management: standards, procedures, exceptions
- Audit: independent assurance, never ownership
Risk vocabulary
- Inherent, residual, control, detection
- Appetite, tolerance, capacity
- KRI leads, KPI measures, KGI confirms
- Concentration, aggregation, emerging risk
- Risk owner named in the register
Contract essentials
- Right to audit, SOC report access
- Data ownership, location, return, destruction
- SLA metrics, penalties, escalation
- Subcontractor disclosure and approval
- Exit and transition assistance
Regulations to place
- GDPR: 72 hour notice, DPIA, transfers
- PCI DSS: cardholder data
- HIPAA: health information
- SOX: financial reporting controls
- Sanctions: OFAC, EU, UN lists
Quick exam traps
- Trap: Outsourcing IT transfers accountability to the vendor
- Trap: The CISO accepts residual risk for the business
- Trap: Risk appetite and risk tolerance mean the same thing
- Trap: A project delivered on time and under budget has succeeded
- Trap: Cyber insurance is a mitigation control
- Trap: Guidelines are mandatory once published
- Trap: A qualified SOC 2 opinion means the vendor must be dropped immediately
- Trap: Breach notification can wait until the investigation is complete
cybercertprep.com · original revision sheet written from the public body of knowledge