CISA Exam · 12 min read Updated

CISA IT Governance Domain 1 Study Guide (2026)

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

CISA IT Governance Domain 1 Study Guide (2026)

Key Takeaways

  • Exam Weight: 17% of the CISA exam (approx. 26 questions)
  • Official Name: Domain 2: Governance and Management of IT
  • Key Framework: COBIT 2019 is the most critical framework to understand.
  • Core Concept: Distinguishing between Governance Objectives (Evaluate, Direct, Monitor - EDM) and Management Objectives (Plan, Build, Run, Monitor - PBRM).
  • Common Trap: Blaming operational management for a strategic governance failure.
  • Key Roles: Board of Directors, IT Steering Committee, Chief Information Officer (CIO).

You feel confident about IT governance. You've memorized what COBIT stands for and the definition of an IT steering committee. Then the exam hits you with a scenario about a failing IT project and asks for the primary reason. The #1 trap isn't forgetting a framework; it's misplacing the blame between the CIO who ran the project and the Board who approved it.

Quick answer

To pass CISA Domain 2, you must master the distinction between governance (the board's role to Evaluate, Direct, Monitor) and management (the CIO's role to Plan, Build, Run, Monitor). This domain tests your judgment in applying frameworks like COBIT to ensure IT strategy supports business objectives and delivers value, not just technical execution.

Key facts

  • Exam Weight: 17% of the CISA exam (approx. 26 questions)
  • Official Name: Domain 2: Governance and Management of IT
  • Key Framework: COBIT 2019 is the most critical framework to understand.
  • Core Concept: Distinguishing between Governance Objectives (Evaluate, Direct, Monitor - EDM) and Management Objectives (Plan, Build, Run, Monitor - PBRM).
  • Common Trap: Blaming operational management for a strategic governance failure.
  • Key Roles: Board of Directors, IT Steering Committee, Chief Information Officer (CIO).

Why Do So Many Candidates Stumble on IT Governance?

Most CISA candidates come from a technical or audit background. We're comfortable with controls, processes, and finding exceptions. Domain 2 forces you to zoom out and think like a member of the board. It's less about finding a misconfigured server and more about asking, "Did we even buy the right server to begin with, and does it support our five-year business plan?"

This leads to the central myth of studying for this domain.

Free 5-Min Diagnostic

Studying for CISA CISA2? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

The Myth: "If I memorize the COBIT principles and ITIL processes, I'll pass Domain 2." The Reality: Memorization is the starting point, not the finish line. The exam tests judgment. It presents scenarios where IT is failing and asks you to identify the root cause, which is almost always a breakdown in governance, not just a mistake in management.

Knowing the ITIL Service Value Chain is good. Knowing that the business—not IT—is responsible for defining the acceptable service levels (SLAs) that ITIL helps manage is what gets you the point. Try VoraPrep's free CISA practice questions to see this in action.

This Week's Drill: The Mindset Shift

Go through ten CISA practice questions from Domain 2. Don't answer them yet. For each question, simply label it: "Is this asking about a Governance failure (a problem with direction/oversight) or a Management failure (a problem with execution)?" This single exercise will re-wire your brain faster than anything else.

What's the Real Difference Between Governance and Management?

This is the most critical distinction in the entire domain. If you master this, you're halfway there.

  • Governance sets the stage. It's the "what" and the "why." It ensures the organization is heading in the right direction.
  • Management runs the show. It's the "how." It ensures the journey is efficient and effective.

Think of it like building a house.

  • Governance: The homeowner (Board of Directors) decides they need a three-bedroom house to support their growing family (business objective), sets a budget (risk appetite), and approves the architect's plans (strategic direction). They check in periodically to make sure the house looks like the plans (monitoring).
  • Management: The general contractor (CIO) hires plumbers and electricians (IT staff), orders lumber (resources), and oversees the day-to-day construction to ensure it's built to code and on schedule (execution).

If the foundation cracks, it's a management problem. If the family realizes they actually needed a four-bedroom house after it's already built, that's a massive governance failure. The CISA exam loves testing for that second type of problem.

Governance vs. Management: A CISA Exam Cheat Sheet

AspectGovernanceManagement
Who?Board of Directors, IT Steering Committee, Executive ManagementCIO, IT Directors, Line Managers
What?Defines strategic direction, sets objectives, ensures value is delivered.Plans, builds, runs, and monitors activities to achieve objectives.
COBIT VerbsEvaluate, Direct, Monitor (EDM)Plan, Build, Run, Monitor (PBRM)
Core Question"Are we doing the right things?""Are we doing things right?"
ExampleApproving the IT budget and ensuring it aligns with business priorities.Managing the IT help desk to meet Service Level Agreements (SLAs).
AccountabilityUltimate accountability for IT's contribution to business value.Accountability for the performance of IT services and projects.

How Should I Analyze IT Investments Like the CISA Exam Wants Me To?

The exam won't make you perform complex accounting. It will, however, test whether you can spot a flawed business case for an IT project. You need to understand the language of value.

While you won't need a calculator, you must understand the concepts of Return on Investment (ROI) and Net Present Value (NPV) to evaluate if a project's justification is sound.

  • Return on Investment (ROI): A simple, high-level metric. The formula is ROI = ((Gain from Investment - Cost of Investment) / Cost of Investment) * 100%. It's useful but can be misleading because it ignores when you get the money back.
  • Net Present Value (NPV): A more sophisticated metric that accounts for the time value of money (a dollar today is worth more than a dollar next year). It discounts all future cash flows back to today's value. A positive NPV means the project is expected to be profitable.

Worked Example: The Cloud Migration Trap

An organization, "Legacy Systems Inc.," is considering a cloud migration project. The project manager's business case shows these figures:

  • Initial Investment (Year 0): $200,000
  • Net Annual Savings (Years 1-5): $50,000 per year
  • Discount Rate (Cost of Capital): 12%
The Tempting (but incomplete) Analysis:

The project manager presents a simple ROI calculation:

  • Total Gain over 5 years: 5 * $50,000 = $250,000
  • ROI = (($250,000 - $200,000) / $200,000) * 100% = 25%

This 25% ROI looks okay. Many managers would approve this. But the CISA mindset requires you to dig deeper.

✨ Free Domain Calculator

Calculate Your CISA Study Hours by Domain

See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.

Calculate CISA Study Plan →
The Auditor's Analysis (Using NPV):

You need to find the Present Value (PV) of each year's savings and see if they add up to more than the initial $200,000 investment.

  • Year 0: -$200,000 (Investment)
  • Year 1 PV: $50,000 / (1 + 0.12)^1 = $44,643
  • Year 2 PV: $50,000 / (1 + 0.12)^2 = $39,860
  • Year 3 PV: $50,000 / (1 + 0.12)^3 = $35,589
  • Year 4 PV: $50,000 / (1 + 0.12)^4 = $31,776
  • Year 5 PV: $50,000 / (1 + 0.12)^5 = $28,371
NPV = -$200,000 + $44,643 + $39,860 + $35,589 + $31,776 + $28,371 = -$19,761 The Verdict: The project has a negative NPV. Despite the positive simple ROI, when you account for the cost of capital, the project is projected to lose the company nearly $20,000 in today's money. The CISA Exam Trap: A question presents this scenario and asks for the auditor's primary concern.
  • Tempting Wrong Answer: "The ROI of 25% is too low for a strategic project."
  • ✓ Correct Answer:

    "The project's business case may be flawed as the Net Present Value is negative, indicating it fails to meet the company's cost of capital."

The auditor's job is to ensure that the methods used for decision-making are sound. Focusing on simple ROI while ignoring NPV is an unsound practice. You can drill these judgment calls with VoraPrep's adaptive question bank, which targets your specific weak spots.

Which Frameworks Do I Actually Need to Know for the Exam?

Don't boil the ocean. You don't need to be a certified practitioner in every framework. You need to know their purpose and how an auditor would use them to evaluate an organization.

COBIT 2019

This is ISACA's own framework and the philosophical backbone of the CISA exam. It is the "umbrella" framework for IT Governance and Management, helping align IT with business goals. An auditor's primary focus is to determine if the organization has a formal IT governance structure based on a recognized framework like COBIT. A key testable concept is the COBIT Goals Cascade, which links stakeholder needs to enterprise goals, then to IT-related goals, and finally to specific governance and management objectives.

ITIL v4

ITIL focuses on IT Service Management (ITSM). It provides best practices for delivering and supporting IT services efficiently. The current version, ITIL v4, is built around the Service Value System (SVS) and the Service Value Chain (SVC). An auditor uses ITIL to ask: Are IT services (like the help desk) delivered predictably? Are there defined processes for incident, problem, and change management?

ISO/IEC 27001

This is the international standard for an Information Security Management System (ISMS). It provides a systematic approach to managing sensitive company information so that it remains secure. An auditor's focus is on whether the organization manages security risks systematically and whether controls are selected based on a formal risk assessment process, documented in a Statement of Applicability (SoA).

NIST Cybersecurity Framework (CSF)

The NIST CSF provides a structured approach to Cybersecurity Risk Management, particularly for critical infrastructure. It is organized around five core functions: Identify, Protect, Detect, Respond, Recover. An auditor would use this to assess if the organization has a comprehensive cybersecurity program and can effectively respond to and recover from a cyber attack.

What Key Roles and Responsibilities Are Tested?

The CISA exam will test your understanding of who is responsible for what. A breakdown in these roles is often the root cause of issues in exam scenarios.

Board of Directors

The Board holds ultimate accountability for the governance of IT. They set the organization's strategic direction and risk appetite—the amount and type of risk they are willing to accept to achieve their objectives. They delegate execution but cannot delegate final responsibility.

IT Steering Committee

This is a senior-level committee with both business and IT representation. Its primary function is to provide strategic direction for IT, ensuring alignment with business goals. They approve major IT projects, allocate resources, and resolve priority conflicts. This is a critical governance body, and its absence or ineffectiveness is a common red flag in CISA questions.

Chief Information Officer (CIO)

The CIO is the senior-most management role for IT. The CIO is responsible for the day-to-day running of the IT department, executing the strategy set by the steering committee, and managing IT resources to deliver services effectively and efficiently. Common Trap: A question describes a pattern of IT projects failing to deliver business value.
  • Tempting Wrong Answer: "The CIO should be replaced due to poor project management."
  • ✓ Correct Answer:

    "The effectiveness of the IT Steering Committee should be reviewed to ensure proper oversight and alignment of IT projects with business strategy."

A pattern of failure points to a breakdown in governance and oversight (a Steering Committee problem), not just one person's execution (a CIO problem). To better understand the CISA exam's structure, review our CISA Exam Study Guide (2026): Domains, Pass Rates, Strategy.

How Can I Create a Weekly Study Plan for This Domain?

Don't just read—actively engage. A four-week sprint can help you master Domain 2.

  • Week 1: Master the Core Concepts.
  • Focus: Governance vs. Management, and the roles of the Board, Steering Committee, and CIO.
  • Drill: Use the "Mindset Shift" drill mentioned earlier. For every practice question, identify if the root issue is governance or management. Use VoraPrep's detailed explanations to confirm your reasoning.
  • Week 2: Understand the Frameworks.
  • Focus: The purpose of COBIT, ITIL v4, ISO 27001, and NIST CSF.
  • Drill: For each framework, write a single sentence explaining what problem it solves for a business. Example: "ITIL v4 helps an organization co-create value through effective IT service management."
  • Week 3: Connect IT to Business Value.
  • Focus: Business cases, ROI vs. NPV, and risk concepts (Risk Appetite, Tolerance, and Capacity).
  • Drill: Review the NPV example. Find a tech article about a company's major IT investment. List three tangible benefits, three intangible benefits, and three risks an auditor would want to see addressed in the business case.
  • Week 4: Review and Test.
  • Focus: Integrate all concepts and tackle scenario-based questions.
  • Drill: Take a 50-question mixed quiz on Domain 2 using an adaptive learning engine. Vory, our AI tutor, can help you break down the logic for any questions you miss, solidifying your judgment-based thinking.

If you're balancing this with a job, our guide on How to Pass the CISA While Working Full Time (2026) has practical strategies.

⚡ Instant Knowledge Check · 1-Click Test Drive
CISA Domain 5: Protection of Information Assets

When conducting an IS audit of an enterprise cloud infrastructure environment, which of the following identity and access management (IAM) findings represents the GREATEST information security risk?

Frequently asked questions

What is the difference between risk appetite, tolerance, and capacity? Risk appetite is the high-level amount of risk an organization is willing to accept to achieve its objectives, set by the board. Risk tolerance is the specific, acceptable deviation from that appetite for a particular risk. Risk capacity is the maximum amount of risk the organization can possibly absorb without failing. Think of appetite as the target speed (65 mph), tolerance as the acceptable variance (+/- 5 mph), and capacity as the speed at which the car's engine explodes (120 mph). Who is ultimately accountable for IT governance? The Board of Directors holds ultimate accountability for all enterprise governance, including the governance of IT. They may delegate the implementation and oversight to committees like the IT Steering Committee, but the final responsibility rests with them. Do I need to be an accountant to pass the CISA exam? Absolutely not. You do not need to perform complex calculations. You must understand business case concepts like ROI and NPV from an auditor's perspective—assessing whether the justification is sound, complete, and uses appropriate methods, not calculating the figures yourself. How much of CISA Domain 2 is about COBIT? While COBIT is not the only topic, it provides the foundational mindset for IT governance that ISACA tests heavily. Understanding COBIT’s principles, especially the distinction between governance and management, is critical and likely applies to at least half the concepts in this domain. Is ITIL part of COBIT? No, they are separate frameworks, but they are complementary. COBIT provides the overall governance and management framework (what to do and why), while ITIL provides detailed best practices for a specific area within that framework: IT service management (how to do it).

--- Ready to Pass Your CISA Exam? Stop memorizing and start thinking like an examiner. VoraPrep's adaptive learning engine, 2,300+ practice questions with detailed explanations, and 24/7 Vory AI tutor are designed to build your audit judgment. We target your weak areas so you study smarter, not just longer. Visit voraprep.com to get started. Start Your Free 14-Day Trial at voraprep.com →

Official resources and references

RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CISA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CISA diagnostic + 12-week plan PDF

Start →
CISA 1:1 Prometric Simulator

2,300+ practice questions with instant Socratic feedback