Governance sets the direction; management keeps the engine running. IT management turns strategy into operational capability — and gives IS auditors a rich set of processes to evaluate: resource management, segregation of duties, vendor oversight, performance monitoring, and quality management.
Governance sets the direction; management makes it real. Part B completes Domain 2 by examining how IT is managed day to day. Four management disciplines dominate the exam: managing IT resources (people, assets, and segregation of duties), managing vendors (contracts, SOC reports, and the all-important right-to-audit clause), monitoring performance (KPIs, KRIs, and whether anyone acts on them), and managing quality (ISO 9001, CMMI, and the independence of the QA function). Throughout, the auditor's eye is on accountability and reliable evidence — not just whether the technology works.
Learning Objectives
By the end of this lesson you will be able to…
Evaluate IT resource management practices for alignment with organizational needs and governance requirements. Bloom: Evaluate
Assess IT vendor management programs for contract adequacy, oversight, and risk management. Bloom: Evaluate
Review IT performance monitoring and reporting mechanisms for completeness and accuracy. Bloom: Evaluate
Evaluate quality assurance and quality management practices within IT operations. Bloom: Evaluate
Apply IS audit procedures to identify and report deficiencies across all IT management domains. Bloom: Apply
Explain how IT management failures translate into organizational risk. Bloom: Understand
Key Terms
Vocabulary flashcards
👈 Read the term, recall the definition, then click or press Enter to check yourself.
Lesson Content
Study the material
1
IT Resource Management
IT can only deliver if its resources are managed deliberately. COBIT 2019 frames five resource types — people, process, information, technology, and partners — and the auditor evaluates how each is acquired, deployed, and retired.
Workforce & assets
Five resource types: people, process, information, technology, partners.
Workforce: skills-gap analysis, succession planning, security vetting, role-based and annual security-awareness training, and off-boarding with prompt access revocation.
The fastest way an organization fails an access audit is weak off-boarding — terminated staff whose accounts stay live for weeks are a textbook finding.
2
Segregation of Duties
Segregation of duties (SoD) ensures no single person controls an entire critical transaction, limiting both error and fraud. It is one of the most-tested control concepts on the exam.
No one should initiate, authorize, AND complete a transaction.
Separate development from production access; IT operations from security; system administration from audit/log review.
Where SoD is not feasible (e.g., small organizations), compensating controls such as independent management review of logs must fill the gap.
💡 Exam TipFor SoD scenarios, ask whether a single person can initiate, authorize, AND complete a transaction. Any two of those three in one person may be a concern depending on the risk.
Try it — assign the duties without creating a conflict
A change process needs all four duties performed, and this team has four people — each with a role that naturally fits one duty. Give everyone the right work without letting any one person hold two incompatible duties. The matrix flags the toxic combinations, and points out when a technically-clean assignment still puts the wrong role on a job.
Interactive · adjust & explore
Each person’s role is shown under their name. Give every duty to the person whose role fits it — then make sure no one holds two incompatible duties.
Who does what?
Initiaterequest / develop
Authorizeapprove
Completeexecute / deploy
Reviewaudit / reconcile
Assigned Conflicting duty
——
Can’t separate them? In a small team full separation may be impossible. Fill the gap with compensating controls: independent management review of logs, dual authorization, transaction monitoring, and mandatory vacations — and document why.
🔎 In practice
The exam’s tell: one person who can initiate, authorize, and complete the same transaction is a segregation-of-duties violation — and a developer with production access is the classic IT example. When you can’t separate the duties, the answer is compensating controls, not ignoring the risk.
3
IT Vendor Management
As organizations outsource more, vendor controls effectively become the organization's controls. The auditor evaluates the full vendor lifecycle and the contract terms that make oversight possible.
Critical contract terms: SLAs, data ownership and return/destruction on termination, minimum security standards, right-to-audit clause, incident/breach notification, subcontractor (fourth-party) disclosure, IP ownership, liability.
SOC reports & cloud
SOC 1 (financial-reporting controls), SOC 2 (Security, Availability, Processing Integrity, Confidentiality, Privacy), SOC 3 (public). Type I = design at a point in time; Type II = operating effectiveness over a period.
Review complementary user entity controls (CUECs) — controls the customer must operate — and any listed subservice organizations.
Cloud: shared-responsibility model, data residency/jurisdiction, CASB visibility, CSA STAR certification.
💡 Exam TipIn cloud/outsourcing arrangements, look for the right-to-audit clause. Without it, the auditor cannot independently verify vendor controls and must rely entirely on the vendor's own representations — a significant limitation.
4
IT Performance Monitoring & Reporting
You can't govern what you don't measure — and you can't govern what you measure but ignore. Monitoring exists to surface degradation early and to inform governance decisions.
Audit angle: verify all four Balanced Scorecard perspectives — financial, customer, internal-process, and learning/growth — are actually measured and reported, not just the financial one; a finance-only scorecard is a finding.
KRIs (forward-looking): open critical vulnerabilities, days since last backup verification, failed privileged-access attempts.
Dashboards: executive RAG status, operational detail, and board/audit-committee risk reporting.
🔎 In practice
A help desk reporting 95% first-call resolution by closing and reopening unresolved tickets isn't a tooling problem — it's a reporting-integrity finding. The metric is being gamed.
💡 Exam TipWhen metrics are reported but not acted upon, the finding isn't that the metrics are wrong — it's that the management response process is ineffective. Reporting without action is not governance.
5
Quality Assurance & Quality Management
The quality of IT services depends on consistent, measured processes — and on a QA function independent enough to tell the truth about them.
Principles: customer focus, process approach, continual improvement, evidence-based decision-making.
Frameworks: ISO 9001 (QMS), CMMI (five maturity levels), Six Sigma (DMAIC), Total Quality Management.
ITIL 4 service quality: service-level management, continual service improvement (CSI), and problem management (root-cause elimination vs. firefighting). (also Lesson 5 — ITSM/ITIL processes in operations)
Level
Name
Description
1
Initial
Unpredictable, reactive processes.
2
Managed
Projects are planned and controlled — but processes are project-specific, not organization-wide.
3
Defined
Processes are documented and standardized across the organization.
4
Quantitatively Managed
Processes are measured and controlled statistically.
5
Optimizing
Continuous process improvement.
💡 Exam TipQuality questions often hinge on QA independence. If QA reports to the same manager as developers, or developers approve their own code for release, independence is compromised — a finding regardless of the technical quality of the output.
Scored Knowledge Check
Test your Domain 2B judgment
Select the best answer for each question, then submit for your score and the rationale for every item. Focus on accountability, oversight, and the reliability of evidence.