Governance is the force that aligns IT with business strategy, manages risk, and ensures accountability. An IS auditor who doesn't understand governance will misread the very controls they are testing. Part A covers the legal landscape, governance structures and strategy, policies, enterprise architecture, enterprise risk management, privacy, and data governance.
Governance sets the direction the auditor measures against
Domain 2 is worth 18% of the exam and splits across two lessons. Part A is about governance — the leadership, structures, and processes that ensure IT serves the business and that risk is owned at the right level. The recurring exam theme: governance questions test accountability and oversight, not just whether IT is efficient. Your job as auditor is to evaluate whether the structures exist, whether decisions are reviewed at the appropriate level, and whether the organization can demonstrate — with evidence — that it does what it claims.
Learning Objectives
By the end of this lesson you will be able to…
Explain how laws, regulations, and industry standards shape the IS audit framework. Bloom: Understand
Assess the adequacy of organizational IT governance structures, policies, and strategic alignment. Bloom: Evaluate
Evaluate enterprise architecture decisions from a risk and control perspective. Bloom: Evaluate
Apply enterprise risk management concepts to IT governance assessments. Bloom: Apply
Identify privacy program requirements and their implications for IS auditors. Bloom: Remember
Assess data governance and classification programs for adequacy and effectiveness. Bloom: Evaluate
Key Terms
Vocabulary flashcards
👈 Read the term, recall the definition, then click or press Enter to check yourself.
Lesson Content
Study the material
1
Laws, Regulations & Industry Standards
Non-compliance is itself an auditable risk, and regulatory requirements drive control requirements. The auditor does not need to be a lawyer — but must know which regimes apply to the organization and evaluate whether controls actually meet them.
Financial & corporate governance
SOX — Section 302 (CEO/CFO certification of controls), Section 404 (management and auditor attestation on internal control over financial reporting), PCAOB AS 2201 (IT general controls).
GLBA Safeguards Rule (financial institutions must run an information-security program); Basel III (operational-risk implications for banks).
Sector regulations
Healthcare: HIPAA (Privacy, Security, and Breach Notification Rules); HITECH extends enforcement to business associates.
Payment card: PCI DSS — 12 requirements across 6 goals; applies to any entity that stores, processes, or transmits cardholder data.
PIPEDA (Canada): consent-based collection, the ten fair-information principles, and mandatory breach reporting to the Privacy Commissioner where there is a real risk of significant harm — frequently relevant to cross-border data flows involving Canadian personal data.
Government: FISMA (NIST framework for federal agencies); FedRAMP (cloud authorization for U.S. federal use).
Industry standards (adopted, not legally mandated)
When management says "we're PCI compliant," that is a claim to verify with evidence — an Attestation of Compliance, current scan reports, scope documentation — not something to accept at face value.
💡 Exam TipRegulation questions test the auditor's role, not regulatory recall. The auditor evaluates whether controls meet requirements and whether compliance monitoring is effective — and verifies management's compliance claims with evidence.
2
Organizational Structure, IT Governance & Strategy
Governance is fundamentally about accountability and oversight. COBIT 2019 draws a clear line between governance (the board's job) and management (running IT day to day), and the auditor's task is to confirm the right bodies exist and actually exercise oversight.
Val IT (value delivery) and Risk IT (IT-specific risk) are now integrated into COBIT 2019 — but ISACA still references them by name in some CISA material, so you may encounter both the integrated and the standalone terms.
Governance bodies & structure
Board (oversight, risk appetite, IT policy), audit committee, IT steering committee (cross-functional governance of IT investments), CIO/CISO (execution).
Centralized vs. decentralized governance trade-offs; matrix accountability challenges; the IT reporting line (CIO to CEO/CFO/COO) has independence implications.
IT strategic planning: align IT strategy to business strategy; portfolio management (run-the-business vs. change-the-business); investment prioritization with business cases.
The auditor asks: does an IT steering committee exist and meet regularly? Is there a board-approved IT strategy? Are IT performance metrics reported to the board/audit committee? Are IT risks rolled into enterprise risk reporting?
🔎 In practice
An IT project that came in on time and on budget but was never reviewed by the steering committee or board is still a governance deficiency. A successful outcome does not excuse the absence of oversight.
💡 Exam TipGovernance questions test accountability and oversight, not just efficiency. IT making major investment decisions without board review or audit-committee visibility is a governance deficiency — even if the project succeeds.
3
IT Policies, Standards, Procedures & Practices
The documentation hierarchy is how management intent becomes enforceable specifics. Auditors evaluate not just whether documents exist, but whether they are approved, communicated, current, and acknowledged.
The hierarchy
Policy (high-level management intent) > standard (mandatory specification, e.g. minimum password length) > procedure (step-by-step instructions) > guideline (recommended, non-mandatory) > baseline (minimum secure configuration for a system type).
Documented and formally approved by the appropriate authority; communicated to all affected parties; reviewed and updated on a defined cycle; aligned with applicable law; and acknowledged/understood by employees.
Common policies to audit: AUP, Information Security, Access Control, Change Management, Data Classification & Handling, Incident Response, Business Continuity, Vendor Management.
Policy exceptions must be requested, approved, documented, and monitored.
🔎 In practice
A beautifully written policy that nobody has acknowledged — or that hasn't been reviewed in five years — is a finding. Existence is not effectiveness.
📚
Explore furtherPolicies, Standards, Procedures & Guidelines — an interactive walk-through of the governance documentation hierarchy.
Enterprise architecture is the blueprint that links business, data, application, and technology layers to strategy. Security and control belong in the architecture — and systems that operate outside EA governance (shadow IT) are control gaps by definition.
Frameworks: TOGAF (with its iterative Architecture Development Method), Zachman (a classification schema), SABSA (security-specific), FEAF (U.S. government).
Four EA domains: business architecture, data/information architecture, application architecture, technology architecture.
Auditor evaluation: documented current and target state; security and control requirements integrated into architectural decisions; a governance process that reviews deviations; legacy systems identified and risk-assessed; EA supports regulatory compliance.
Shadow IT — unauthorized systems outside EA governance — represents an uncontrolled gap.
🔎 In practice
A new system deployed without architecture review isn't simply "insecure." It's a governance finding: the EA governance process failed to detect or prevent an unauthorized deployment.
💡 Exam TipA system deployed without an architecture or security review is a governance finding — architectural controls and governance processes failed — not merely a technical "the system is insecure" finding.
📚
Explore furtherCybersecurity Design Principles — the security-architecture fundamentals that should be built into EA decisions.
ERM identifies, assesses, responds to, and monitors risk across the whole organization — IT risk included. Critically, the auditor sits in the third line: independent assurance, not risk owner and not control designer.
Frameworks & process
COSO ERM (2017) components: Governance & Culture; Strategy & Objective-Setting; Performance; Review & Revision; Information, Communication & Reporting. Also ISO 31000 and ISACA Risk IT.
IT risk taxonomy: strategic, operational, compliance, information-security risk. Captured in a risk register with named owners, against a board-approved risk appetite.
A qualitative risk is rated by likelihood × impact, and where it lands sets the priority. The plotted example — a likely event with major impact — sits in the extreme zone: it demands treatment, not acceptance.
The Three Lines Model
First line: operational management (owns and manages risk). Second line: risk and compliance functions (oversight and monitoring). Third line: internal audit (independent assurance).
The three lines model keeps risk ownership separate from assurance: the first line owns and runs controls, the second line sets policy and monitors, and the third line — internal audit, where the IS auditor sits — provides independent assurance. Answers that put the auditor in the first or second line are testing this boundary.
🔎 In practice
A board that formally accepts a specific risk that's within its stated appetite, without adding controls, has chosen risk acceptance — a legitimate, documented response, not a deficiency.
💡 Exam TipThe IS auditor is the third line (independent assurance). The auditor does not own or manage risk (first line) or design controls (second line). Answers that ask the auditor to "help management implement" a response are testing this boundary.
Try it — put numbers on the decision (ALE & ROSI)
The heat map above rates risk qualitatively. Management often needs a quantitative view too: how much a risk costs per year, and whether a control is worth buying. Move the sliders and watch the money — then find the price at which the safeguard stops paying for itself.
Interactive · adjust & explore
Your decision
Each slider is a choice you'd defend to the board.
Exposure — what's at stake
$2,000,000
Replacement / impact value of the asset.
35%
Share of value lost in one event. SLE = AV × EF.
0.40 / yr
Events per year. ALE = SLE × ARO.
The control — your countermeasure
70%
Share of the annual loss this control removes.
$95,000
Fully-loaded annual cost to run the safeguard.
The verdict
ALE before
—
Risk mitigated
—
ALE after
—
Net benefit
—
——Adjust the sliders to evaluate the decision.
Net benefit vs. what you spend
Your operating point (●) rides the bold line for the effectiveness you chose. Cross the dashed break-even line and the control starts losing money.
Your control Other effectiveness levels Operating point Break-even
🔎 In practice
AV, EF, ARO, and effectiveness are estimates, and the model is linear — it sharpens judgment, it doesn't replace it. When a control's cost exceeds the risk it removes (ROSI < 0), the sound responses are transfer (insure), accept within appetite, or find a cheaper control — the same treatment choices from the heat map above, now with a dollar figure behind them.
📚
Explore furtherRisk Management & Risk Analysis — interactive modules on the formal risk-reduction process and on assessing threats and vulnerabilities.
Privacy and security are not the same thing. Security protects data from unauthorized access; privacy ensures data is collected, used, retained, and shared appropriately. An organization can have excellent security and still violate privacy.
Frameworks: OECD Privacy Principles (8), GAPP (10, AICPA/CPA Canada), and the GDPR principles (lawfulness/fairness/transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity & confidentiality, accountability).
Program components: privacy policy and notices, consent management, data-subject rights (access, erasure, portability, objection), privacy impact assessments (PIAs), the Data Protection Officer role, breach detection and notification, and cross-border transfer mechanisms (SCCs, BCRs, adequacy decisions).
Auditor evaluation: PIAs before new processing begins; a documented inventory of personal-data flows; data-subject requests fulfilled within required timeframes; breach notification within regulatory windows; data-processing agreements with third-party processors.
🔎 In practice
A company can encrypt everything and still violate privacy — for example, by using customer data for a marketing purpose the customer never consented to. Security controls don't answer the privacy question.
📚
Explore furtherPrivacy Tenets — an interactive primer on personal-data protection principles.
Data is a strategic asset that needs ownership and accountability. The distinction the exam loves: the data owner (business) classifies data and sets access requirements; the data custodian (IT) implements the technical controls.
Roles: owner (business, accountable for the asset), steward (operational quality and compliance), custodian (IT storage, security, availability). Plus data-quality management, master data management, and data catalog/lineage.
Classification: typical tiers Public, Internal, Confidential, Restricted/Secret; regulatory-driven categories such as PHI, PCI data, PII, and classified government data.
Data lifecycle: creation → storage → use → sharing → archival → destruction.
Retention & disposal: schedules aligned to legal/regulatory/business needs; secure disposal via cryptographic erasure, physical destruction, or degaussing; media-sanitization standard NIST SP 800-88.
Auditor evaluation: data owners formally designated; a documented and enforced classification policy; labels consistently applied; retention schedules followed; a verified secure-disposal process. (also Lesson 5 — operational log retention)
🔎 In practice
When marketing staff can freely read customer financial data, the root cause is usually not the IAM system — it's that the data owner never defined access requirements. The access gap is a downstream symptom of the governance failure.
💡 Exam TipData governance questions test accountability: the owner (business) classifies and sets access; the custodian (IT) implements technical controls. The auditor evaluates whether this structure exists and works.
📚
Explore furtherData Roles — an interactive module on owner, custodian, and processor responsibilities.
Select the best answer for each question, then submit for your score and the rationale for every item. Think governance: accountability, oversight, and evidence.