certslothcertsloth
CISA/Topic 07

ISACA / Professional

Governance, Data Ownership and Enterprise Architecture

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Trace objectives to decisions, owners and evidence.

Must remember

Evaluate whether IT strategy supports business strategy, with accountable decision bodies, resource allocation and performance oversight. Governance sets direction and monitors outcomes; management plans and operates within that direction. A committee name alone does not establish effective oversight.

Review enterprise architecture for coherent business, data, application and technology relationships. Uncontrolled exceptions can create duplicated capability and fragile dependencies. Policies, standards and procedures should be approved, communicated, current and enforced. Compare written intent with observed practice.

Data owners classify information and approve appropriate use; custodians implement handling; users follow requirements. Privacy governance includes purpose, minimization, retention, access and disposal. An inventory should connect systems, datasets, owners and criticality so risk decisions are not made from unknown assets.

Assess vendor selection, contracts, assurance and exit arrangements, including subcontractors and concentration risk. Evaluate resource capacity, skills, cost and quality management. KPIs measure performance, while KRIs help expose rising risk. Board reporting should disclose meaningful exceptions and trends rather than only favorable activity counts.

Choose under exam pressure

Requirement Choice and reason
IT investment with no business sponsor Question alignment, ownership and benefit measurement.
Sensitive dataset has no owner Identify governance responsibility before assuming handling decisions are valid.
Many architecture exceptions Assess cumulative risk, expiry and authorized approval.

Traps

  • An approved policy is not proof of enforcement.
  • Outsourcing a service does not outsource all accountability.

Active recall

1. Governance versus management?

Direction/oversight versus planning and operating to achieve it.

2. Who decides data classification?

The accountable information owner under the organization’s scheme.

3. Why inventory dependencies?

They reveal business impact, concentration and recovery relationships.

4. Why review exception expiry?

Temporary risk acceptance can otherwise become permanent without review.

5. What makes board reporting useful?

Clear material risk, trends, accountability and decisions needed.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.