Section 1: 35–45%I1
IT Governance and the IT Function
Exam insight
ISC starts with IT governance because every control that follows rests on a well-organized, well-supervised IT function. The AICPA tests whether you can spot the segregation-of-duties failures and governance gaps that let one person both write code and run it in production.
What AICPA wants you to know
- 1Explain how IT governance aligns IT strategy with overall business strategy and objectives.
- 2Describe the role of the IT steering committee and key IT governance frameworks such as COBIT.
- 3Identify the responsibilities of core IT roles and how they should be separated.
- 4Apply segregation-of-duties principles to keep systems development, operations, and security distinct.
- 5Evaluate governance risks introduced by cloud computing and outsourcing arrangements.
Patterns in this topic
The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.
Exam tip
Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.