Day 2 — Afternoon · Domain 2B

Management of IT — Part B

Governance sets the direction; management keeps the engine running. IT management turns strategy into operational capability — and gives IS auditors a rich set of processes to evaluate: resource management, segregation of duties, vendor oversight, performance monitoring, and quality management.

Session: Afternoon, Day 2 Duration: ~3 hrs Exam Weight: 18% (Domain 2) Knowledge Check: 5 Questions

Overview

Where strategy becomes operational reality

Governance sets the direction; management makes it real. Part B completes Domain 2 by examining how IT is managed day to day. Four management disciplines dominate the exam: managing IT resources (people, assets, and segregation of duties), managing vendors (contracts, SOC reports, and the all-important right-to-audit clause), monitoring performance (KPIs, KRIs, and whether anyone acts on them), and managing quality (ISO 9001, CMMI, and the independence of the QA function). Throughout, the auditor's eye is on accountability and reliable evidence — not just whether the technology works.

Learning Objectives

By the end of this lesson you will be able to…

Key Terms

Vocabulary flashcards

👈 Read the term, recall the definition, then click or press Enter to check yourself.

Lesson Content

Study the material

1

IT Resource Management

IT can only deliver if its resources are managed deliberately. COBIT 2019 frames five resource types — people, process, information, technology, and partners — and the auditor evaluates how each is acquired, deployed, and retired.

Workforce & assets

  • Five resource types: people, process, information, technology, partners.
  • Workforce: skills-gap analysis, succession planning, security vetting, role-based and annual security-awareness training, and off-boarding with prompt access revocation.
  • Asset management: hardware inventory and lifecycle, software-license compliance, cloud-resource inventory, end-of-life tracking.
🔎 In practice

The fastest way an organization fails an access audit is weak off-boarding — terminated staff whose accounts stay live for weeks are a textbook finding.

2

Segregation of Duties

Segregation of duties (SoD) ensures no single person controls an entire critical transaction, limiting both error and fraud. It is one of the most-tested control concepts on the exam.

  • No one should initiate, authorize, AND complete a transaction.
  • Separate development from production access; IT operations from security; system administration from audit/log review.
  • Where SoD is not feasible (e.g., small organizations), compensating controls such as independent management review of logs must fill the gap.
💡 Exam TipFor SoD scenarios, ask whether a single person can initiate, authorize, AND complete a transaction. Any two of those three in one person may be a concern depending on the risk.

Try it — assign the duties without creating a conflict

A change process needs all four duties performed, and this team has four people — each with a role that naturally fits one duty. Give everyone the right work without letting any one person hold two incompatible duties. The matrix flags the toxic combinations, and points out when a technically-clean assignment still puts the wrong role on a job.

Interactive · adjust & explore

Each person’s role is shown under their name. Give every duty to the person whose role fits it — then make sure no one holds two incompatible duties.

Who does what? Initiaterequest / develop Authorizeapprove Completeexecute / deploy Reviewaudit / reconcile
Assigned Conflicting duty
🔎 In practice

The exam’s tell: one person who can initiate, authorize, and complete the same transaction is a segregation-of-duties violation — and a developer with production access is the classic IT example. When you can’t separate the duties, the answer is compensating controls, not ignoring the risk.

3

IT Vendor Management

As organizations outsource more, vendor controls effectively become the organization's controls. The auditor evaluates the full vendor lifecycle and the contract terms that make oversight possible.

Lifecycle & contracts

  • Lifecycle: due diligence & selection → contract → ongoing monitoring → offboarding.
  • Due diligence: financial stability, security/compliance posture (certifications, audit reports), references, business-continuity capability, data-handling practices.
  • Critical contract terms: SLAs, data ownership and return/destruction on termination, minimum security standards, right-to-audit clause, incident/breach notification, subcontractor (fourth-party) disclosure, IP ownership, liability.

SOC reports & cloud

  • SOC 1 (financial-reporting controls), SOC 2 (Security, Availability, Processing Integrity, Confidentiality, Privacy), SOC 3 (public). Type I = design at a point in time; Type II = operating effectiveness over a period.
  • Review complementary user entity controls (CUECs) — controls the customer must operate — and any listed subservice organizations.
  • Cloud: shared-responsibility model, data residency/jurisdiction, CASB visibility, CSA STAR certification.
💡 Exam TipIn cloud/outsourcing arrangements, look for the right-to-audit clause. Without it, the auditor cannot independently verify vendor controls and must rely entirely on the vendor's own representations — a significant limitation.
4

IT Performance Monitoring & Reporting

You can't govern what you don't measure — and you can't govern what you measure but ignore. Monitoring exists to surface degradation early and to inform governance decisions.

  • Frameworks: IT Balanced Scorecard (financial, customer, internal-process, learning/growth), COBIT 2019 performance management, ITIL reporting.
  • Audit angle: verify all four Balanced Scorecard perspectives — financial, customer, internal-process, and learning/growth — are actually measured and reported, not just the financial one; a finance-only scorecard is a finding.
  • KPIs: availability, MTTR, MTBF, SLA-compliance rate, change-success rate, help-desk first-call resolution.
  • KRIs (forward-looking): open critical vulnerabilities, days since last backup verification, failed privileged-access attempts.
  • Dashboards: executive RAG status, operational detail, and board/audit-committee risk reporting.
🔎 In practice

A help desk reporting 95% first-call resolution by closing and reopening unresolved tickets isn't a tooling problem — it's a reporting-integrity finding. The metric is being gamed.

💡 Exam TipWhen metrics are reported but not acted upon, the finding isn't that the metrics are wrong — it's that the management response process is ineffective. Reporting without action is not governance.
5

Quality Assurance & Quality Management

The quality of IT services depends on consistent, measured processes — and on a QA function independent enough to tell the truth about them.

  • Principles: customer focus, process approach, continual improvement, evidence-based decision-making.
  • Frameworks: ISO 9001 (QMS), CMMI (five maturity levels), Six Sigma (DMAIC), Total Quality Management.
  • Software QA: an independent testing function, code-review standards, defect tracking, test-coverage requirements.
  • ITIL 4 service quality: service-level management, continual service improvement (CSI), and problem management (root-cause elimination vs. firefighting). (also Lesson 5 — ITSM/ITIL processes in operations)
LevelNameDescription
1InitialUnpredictable, reactive processes.
2ManagedProjects are planned and controlled — but processes are project-specific, not organization-wide.
3DefinedProcesses are documented and standardized across the organization.
4Quantitatively ManagedProcesses are measured and controlled statistically.
5OptimizingContinuous process improvement.
💡 Exam TipQuality questions often hinge on QA independence. If QA reports to the same manager as developers, or developers approve their own code for release, independence is compromised — a finding regardless of the technical quality of the output.

Scored Knowledge Check

Test your Domain 2B judgment

Select the best answer for each question, then submit for your score and the rationale for every item. Focus on accountability, oversight, and the reliability of evidence.

Q1.A cloud vendor contract has no right-to-audit clause, but the vendor provides an annual SOC 2 Type II report. The auditor should conclude that:

Question 1 options
Correct: B. The missing clause is a contractual deficiency that limits the auditor's ability to independently verify controls. SOC 2 reports are useful but are produced by auditors the vendor selects. It's a finding and a limitation — not a disqualifying event. Why the others fall short: A a vendor-selected SOC report doesn’t make an independent audit right redundant; C terminating over a single clause is disproportionate; D ‘most vendors don’t allow it’ normalizes the gap rather than flagging the limitation.

Q2.An IT help desk reports a 95% first-call resolution rate every month. The auditor discovers unresolved calls are closed after 24 hours and reopened as new tickets. The MOST significant finding is:

Question 2 options
Correct: A. Closing and reopening tickets artificially inflates the KPI, making it unreliable. This is a governance and integrity finding about reporting reliability — not primarily an SLA or tooling issue. Why the others fall short: B extending the SLA treats a symptom and ignores the manipulation; C calling 95% ‘industry-standard’ accepts a gamed number; D swapping tools sidesteps the reporting-integrity problem.

Q3.A developer responsible for a critical financial application also has production access to deploy changes directly. This MOST represents:

Question 3 options
Correct: B. Developer access to production is a classic SoD violation — the developer can both create and deploy changes without independent review. It has access-management implications (D), but the root finding is the SoD violation. Why the others fall short: A availability risk is a consequence, not the core failure; C ‘acceptable in small shops’ excuses the gap rather than requiring compensating controls; D access is involved, but the root finding is the SoD violation.

Q4.A vendor's SOC 2 Type II report lists a complementary user entity control (CUEC) requiring the customer to maintain a privileged-access review for admin accounts on the vendor's platform. The auditor should:

Question 4 options
Correct: B. CUECs are controls the user organization must implement to complete the control environment described in the SOC report. The auditor must verify the organization is actually operating the required CUEC — it is not the vendor's responsibility. Why the others fall short: A a CUEC is by definition the customer’s responsibility, not the vendor’s; C asking to strip the CUEC misreads its purpose; D accepting the report without testing the CUEC leaves a required control unverified.

Q5.An IT department is at CMMI Level 2 for change management: individual projects manage changes effectively, but there is no organization-wide standardized process. This BEST aligns with:

Question 5 options
Correct: B. CMMI Level 2 (Managed) is characterized by project-level control. Processes exist and work within projects but are not standardized across the organization — that institutionalization is Level 3 (Defined). Why the others fall short: A Level 1 is reactive/unpredictable, but projects here manage changes effectively; C Level 3 requires org-wide standardization, which is explicitly absent; D Level 4 requires statistical control, well beyond this state.