You feel confident about IT governance. You've memorized what COBIT stands for and the definition of an IT steering committee. Then the exam hits you with a scenario about a failing IT project and asks for the primary reason. The #1 trap isn't forgetting a framework; it's misplacing the blame between the CIO who ran the project and the Board who approved it.
To pass CISA Domain 2, you must master the distinction between governance (the board's role to Evaluate, Direct, Monitor) and management (the CIO's role to Plan, Build, Run, Monitor). This domain tests your judgment in applying frameworks like COBIT to ensure IT strategy supports business objectives and delivers value, not just technical execution.
Key facts
- Exam Weight: 17% of the CISA exam (approx. 26 questions)
- Official Name: Domain 2: Governance and Management of IT
- Key Framework: COBIT 2019 is the most critical framework to understand.
- Core Concept: Distinguishing between Governance Objectives (Evaluate, Direct, Monitor - EDM) and Management Objectives (Plan, Build, Run, Monitor - PBRM).
- Common Trap: Blaming operational management for a strategic governance failure.
- Key Roles: Board of Directors, IT Steering Committee, Chief Information Officer (CIO).
Why Do So Many Candidates Stumble on IT Governance?
Most CISA candidates come from a technical or audit background. We're comfortable with controls, processes, and finding exceptions. Domain 2 forces you to zoom out and think like a member of the board. It's less about finding a misconfigured server and more about asking, "Did we even buy the right server to begin with, and does it support our five-year business plan?"
This leads to the central myth of studying for this domain.
Studying for CISA CISA2? Benchmark your score in 5 minutes.
Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.
Knowing the ITIL Service Value Chain is good. Knowing that the business—not IT—is responsible for defining the acceptable service levels (SLAs) that ITIL helps manage is what gets you the point. Try VoraPrep's free CISA practice questions to see this in action.
This Week's Drill: The Mindset Shift
Go through ten CISA practice questions from Domain 2. Don't answer them yet. For each question, simply label it: "Is this asking about a Governance failure (a problem with direction/oversight) or a Management failure (a problem with execution)?" This single exercise will re-wire your brain faster than anything else.
What's the Real Difference Between Governance and Management?
This is the most critical distinction in the entire domain. If you master this, you're halfway there.
- Governance sets the stage. It's the "what" and the "why." It ensures the organization is heading in the right direction.
- Management runs the show. It's the "how." It ensures the journey is efficient and effective.
Think of it like building a house.
- Governance: The homeowner (Board of Directors) decides they need a three-bedroom house to support their growing family (business objective), sets a budget (risk appetite), and approves the architect's plans (strategic direction). They check in periodically to make sure the house looks like the plans (monitoring).
- Management: The general contractor (CIO) hires plumbers and electricians (IT staff), orders lumber (resources), and oversees the day-to-day construction to ensure it's built to code and on schedule (execution).
If the foundation cracks, it's a management problem. If the family realizes they actually needed a four-bedroom house after it's already built, that's a massive governance failure. The CISA exam loves testing for that second type of problem.
Governance vs. Management: A CISA Exam Cheat Sheet
| Aspect | Governance | Management |
|---|---|---|
| Who? | Board of Directors, IT Steering Committee, Executive Management | CIO, IT Directors, Line Managers |
| What? | Defines strategic direction, sets objectives, ensures value is delivered. | Plans, builds, runs, and monitors activities to achieve objectives. |
| COBIT Verbs | Evaluate, Direct, Monitor (EDM) | Plan, Build, Run, Monitor (PBRM) |
| Core Question | "Are we doing the right things?" | "Are we doing things right?" |
| Example | Approving the IT budget and ensuring it aligns with business priorities. | Managing the IT help desk to meet Service Level Agreements (SLAs). |
| Accountability | Ultimate accountability for IT's contribution to business value. | Accountability for the performance of IT services and projects. |
How Should I Analyze IT Investments Like the CISA Exam Wants Me To?
The exam won't make you perform complex accounting. It will, however, test whether you can spot a flawed business case for an IT project. You need to understand the language of value.
While you won't need a calculator, you must understand the concepts of Return on Investment (ROI) and Net Present Value (NPV) to evaluate if a project's justification is sound.
- Return on Investment (ROI): A simple, high-level metric. The formula is
ROI = ((Gain from Investment - Cost of Investment) / Cost of Investment) * 100%. It's useful but can be misleading because it ignores when you get the money back. - Net Present Value (NPV): A more sophisticated metric that accounts for the time value of money (a dollar today is worth more than a dollar next year). It discounts all future cash flows back to today's value. A positive NPV means the project is expected to be profitable.
Worked Example: The Cloud Migration Trap
An organization, "Legacy Systems Inc.," is considering a cloud migration project. The project manager's business case shows these figures:
- Initial Investment (Year 0): $200,000
- Net Annual Savings (Years 1-5): $50,000 per year
- Discount Rate (Cost of Capital): 12%
The project manager presents a simple ROI calculation:
- Total Gain over 5 years: 5 * $50,000 = $250,000
- ROI = (($250,000 - $200,000) / $200,000) * 100% = 25%
This 25% ROI looks okay. Many managers would approve this. But the CISA mindset requires you to dig deeper.
Calculate Your CISA Study Hours by Domain
See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.
You need to find the Present Value (PV) of each year's savings and see if they add up to more than the initial $200,000 investment.
- Year 0: -$200,000 (Investment)
- Year 1 PV: $50,000 / (1 + 0.12)^1 = $44,643
- Year 2 PV: $50,000 / (1 + 0.12)^2 = $39,860
- Year 3 PV: $50,000 / (1 + 0.12)^3 = $35,589
- Year 4 PV: $50,000 / (1 + 0.12)^4 = $31,776
- Year 5 PV: $50,000 / (1 + 0.12)^5 = $28,371
- Tempting Wrong Answer: "The ROI of 25% is too low for a strategic project."
-
✓ Correct Answer:
"The project's business case may be flawed as the Net Present Value is negative, indicating it fails to meet the company's cost of capital."
The auditor's job is to ensure that the methods used for decision-making are sound. Focusing on simple ROI while ignoring NPV is an unsound practice. You can drill these judgment calls with VoraPrep's adaptive question bank, which targets your specific weak spots.
Which Frameworks Do I Actually Need to Know for the Exam?
Don't boil the ocean. You don't need to be a certified practitioner in every framework. You need to know their purpose and how an auditor would use them to evaluate an organization.
COBIT 2019
This is ISACA's own framework and the philosophical backbone of the CISA exam. It is the "umbrella" framework for IT Governance and Management, helping align IT with business goals. An auditor's primary focus is to determine if the organization has a formal IT governance structure based on a recognized framework like COBIT. A key testable concept is the COBIT Goals Cascade, which links stakeholder needs to enterprise goals, then to IT-related goals, and finally to specific governance and management objectives.ITIL v4
ITIL focuses on IT Service Management (ITSM). It provides best practices for delivering and supporting IT services efficiently. The current version, ITIL v4, is built around the Service Value System (SVS) and the Service Value Chain (SVC). An auditor uses ITIL to ask: Are IT services (like the help desk) delivered predictably? Are there defined processes for incident, problem, and change management?ISO/IEC 27001
This is the international standard for an Information Security Management System (ISMS). It provides a systematic approach to managing sensitive company information so that it remains secure. An auditor's focus is on whether the organization manages security risks systematically and whether controls are selected based on a formal risk assessment process, documented in a Statement of Applicability (SoA).NIST Cybersecurity Framework (CSF)
The NIST CSF provides a structured approach to Cybersecurity Risk Management, particularly for critical infrastructure. It is organized around five core functions: Identify, Protect, Detect, Respond, Recover. An auditor would use this to assess if the organization has a comprehensive cybersecurity program and can effectively respond to and recover from a cyber attack.What Key Roles and Responsibilities Are Tested?
The CISA exam will test your understanding of who is responsible for what. A breakdown in these roles is often the root cause of issues in exam scenarios.
Board of Directors
The Board holds ultimate accountability for the governance of IT. They set the organization's strategic direction and risk appetite—the amount and type of risk they are willing to accept to achieve their objectives. They delegate execution but cannot delegate final responsibility.IT Steering Committee
This is a senior-level committee with both business and IT representation. Its primary function is to provide strategic direction for IT, ensuring alignment with business goals. They approve major IT projects, allocate resources, and resolve priority conflicts. This is a critical governance body, and its absence or ineffectiveness is a common red flag in CISA questions.Chief Information Officer (CIO)
The CIO is the senior-most management role for IT. The CIO is responsible for the day-to-day running of the IT department, executing the strategy set by the steering committee, and managing IT resources to deliver services effectively and efficiently. Common Trap: A question describes a pattern of IT projects failing to deliver business value.- Tempting Wrong Answer: "The CIO should be replaced due to poor project management."
-
✓ Correct Answer:
"The effectiveness of the IT Steering Committee should be reviewed to ensure proper oversight and alignment of IT projects with business strategy."
A pattern of failure points to a breakdown in governance and oversight (a Steering Committee problem), not just one person's execution (a CIO problem). To better understand the CISA exam's structure, review our CISA Exam Study Guide (2026): Domains, Pass Rates, Strategy.
How Can I Create a Weekly Study Plan for This Domain?
Don't just read—actively engage. A four-week sprint can help you master Domain 2.
- Week 1: Master the Core Concepts.
- Focus: Governance vs. Management, and the roles of the Board, Steering Committee, and CIO.
- Drill: Use the "Mindset Shift" drill mentioned earlier. For every practice question, identify if the root issue is governance or management. Use VoraPrep's detailed explanations to confirm your reasoning.
- Week 2: Understand the Frameworks.
- Focus: The purpose of COBIT, ITIL v4, ISO 27001, and NIST CSF.
- Drill: For each framework, write a single sentence explaining what problem it solves for a business. Example: "ITIL v4 helps an organization co-create value through effective IT service management."
- Week 3: Connect IT to Business Value.
- Focus: Business cases, ROI vs. NPV, and risk concepts (Risk Appetite, Tolerance, and Capacity).
- Drill: Review the NPV example. Find a tech article about a company's major IT investment. List three tangible benefits, three intangible benefits, and three risks an auditor would want to see addressed in the business case.
- Week 4: Review and Test.
- Focus: Integrate all concepts and tackle scenario-based questions.
- Drill: Take a 50-question mixed quiz on Domain 2 using an adaptive learning engine. Vory, our AI tutor, can help you break down the logic for any questions you miss, solidifying your judgment-based thinking.
If you're balancing this with a job, our guide on How to Pass the CISA While Working Full Time (2026) has practical strategies.