CISA Exam Section Guide

CISA Governance & Management of IT Exam Prep Hub (2026)

Master Domain 1 of the CISA exam. Explore our expert guides on IT governance, risk assessment, and management for your 2026 certification.

Quick answer: Prepare for the CISA Governance and Management of IT domain with our comprehensive study hub. This section covers key concepts for the 2026 exam, including detailed breakdowns of IT governance frameworks and risk assessment methodologies. Our complete study guides provide the essential knowledge you need to master this critical area of the CISA exam.

Key facts

Exam Body:
ISACA
Domain 1 Weighting:
18% of exam (2024 Job Practice)
Passing Score:
450 out of 800
Exam Format:
150 multiple-choice questions

Overview

Mastering the Mindset, Not Just the Material

You will not pass the Governance and Management of IT domain by memorizing frameworks. This section of the CISA exam is the least technical and most conceptual, which is precisely why so many candidates struggle. It tests your judgment, not your recall. The questions are designed to see if you can think like a strategic advisor to the business, not just an IT technician. Your primary task is to shift your perspective from implementation to oversight.

Success in this domain requires you to evaluate situations from a top-down, business-first viewpoint. When you see a question about a specific IT control, your first thought shouldn't be about the technical configuration. Instead, you must ask: Does this control support a business objective? Is it aligned with the organization's risk appetite? Is there a formal policy that mandates this control, and is the process for managing it documented and followed? This domain is about the "why" behind IT actions—the structures, policies, and processes that ensure IT delivers value to the business and manages risk effectively. Getting this mindset right is more critical than knowing every single process in COBIT.

From Theory to Application: How to Approach Key Concepts

Your biggest mistake in this domain will be attempting to learn IT governance frameworks like COBIT or ITIL as if they were instruction manuals. The exam will not ask you to list the 34 processes of COBIT 5. It will present a scenario and expect you to apply the principles of good governance to identify the best or most appropriate action. You must focus on the purpose and function of these concepts, not their intricate details.

To correctly answer the situational questions, you must internalize the distinct roles of core governance components. The exam will test your ability to differentiate between concepts that sound similar but have critically different functions in practice. Before you dive into the detailed guides, master these fundamental distinctions:

  • Governance vs. Management: Governance is about setting direction and ensuring objectives are achieved (the board and senior leadership's role), while management is about planning, building, and running activities to meet that direction (the operational role). A question about setting risk appetite is a governance function; a question about implementing a new firewall is a management function.
  • Framework Purpose: You don't need to be a COBIT expert, but you need to know it's a framework for the governance and management of enterprise IT. You need to know ITIL is focused on IT Service Management (ITSM). The exam will test if you know which tool to apply to a given problem.
  • The Document Hierarchy: A policy is a high-level statement of intent from management. A standard provides mandatory rules to support a policy. A procedure is a step-by-step guide for a specific task. A guideline offers recommended, non-mandatory best practices. You will be given scenarios where you must identify a breakdown in this hierarchy.

Thinking Like a CISA: Evaluating Process, Not Just Outcomes

Throughout this domain, you are an auditor and an advisor. Your job is to assess whether the organization has the right structures in place to manage its IT in alignment with business goals. This requires a specific way of thinking. For example, if a question describes a critical server that was not patched for a known vulnerability, the technically correct answer might be "apply the patch immediately." However, the CISA answer is to first determine if a patch management policy exists, if it was followed, and why the process failed. The CISA is concerned with the breakdown of the governance and management process, as that is the root cause of the risk.

This perspective is crucial when studying risk management, strategic alignment, and performance monitoring. You are not being tested on your ability to calculate risk, but on your ability to evaluate if the organization has a formal, effective risk management process. You are not creating the IT strategy, but assessing whether the process for creating it ensures alignment with the enterprise strategy. This focus on process, policy, and structure is the key to mastering the CISA Governance and Management of IT domain.

Every guide in this cluster (4)

Every published article that belongs to this cluster, organized by type. New content is added continuously.

CISA 1:1 Prometric Simulator

2,300+ practice questions with instant Socratic feedback