StudyToCert

All certifications / CISA / Lessons

ISACA Certified Information Systems Auditor (CISA) 2024 job practice · Domain 2: Governance and management of IT

IT governance, organizational structure and IT strategy: board, steering committee, business alignment

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

IT governance is how an organization makes sure its use of technology supports its goals, delivers value, manages risk and uses resources responsibly. It is part of enterprise governance, not a separate IT project. Governance is different from management. Governance evaluates options, sets direction, makes high-level decisions and monitors performance; management plans, builds, runs and monitors activities within that direction. The CISA exam returns to this split often: when a question asks who is ultimately accountable, it is usually a governance body.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISA study plan