Certificate
Course Outline
Domain 1: Framework for the Governance of Enterprise IT (25%)
Ensure the definition, establishment, and management of a framework for the governance of enterprise IT that aligns with the mission, vision, and values of the enterprise.
Domain 1—Knowledge Statements:
- Understanding of the components of a framework for the governance of enterprise IT
- Understanding of IT governance industry practices, standards, and frameworks (for example, COBIT, Information Technology Infrastructure Library [ITIL], International Organization for Standardization [ISO] 20000, ISO 38500)
- Understanding of business drivers related to IT governance (for example, legal, regulatory, and contractual requirements)
- Understanding of IT governance enablers (for example, principles, policies, and frameworks; processes; organisational structures; culture, ethics, and behaviour; information; services, infrastructure, and applications; people, skills, and competencies)
- Understanding of techniques used to identify IT strategy (for example, SWOT, BCG Matrix)
- Understanding of components, principles, and concepts related to enterprise architecture (EA)
- Understanding of organisational structures and their roles and responsibilities (for example, enterprise investment committee, program management office, IT strategy committee, IT architecture review board, IT risk management committee)
- Understanding of methods to manage organisational, process, and cultural change
- Understanding of models and methods to establish accountability for information requirements, data and system ownership, and IT processes
- Understanding of IT governance monitoring processes and mechanisms (for example, balanced scorecard (BSC))
- Understanding of IT governance reporting processes and mechanisms
- Understanding of communication and promotion techniques
- Understanding of assurance methodologies and techniques
- Understanding of continuous improvement techniques and processes
Domain 2: Strategic Management (20%)
Ensure that IT enables and supports the achievement of enterprise objectives through the integration and alignment of IT strategic plans with enterprise strategic plans.
Domain 2—Knowledge Statements:
- Understanding of an enterprise's strategic plan and how it relates to IT
- Understanding of strategic planning processes and techniques
- Understanding of the impact of changes in business strategy on IT strategy
- Understanding of barriers to the achievement of strategic alignment
- Understanding of policies and procedures necessary to support IT and business strategic alignment
- Understanding of methods to document and communicate IT strategic planning processes (for example, IT dashboard/balanced scorecard, key indicators)
- Understanding of components, principles, and frameworks of enterprise architecture (EA)
- Understanding of current and future technologies
- Understanding of prioritisation processes related to IT initiatives
- Understanding of scope, objectives, and benefits of IT investment programmes
- Understanding of IT roles and responsibilities and methods to cascade business and IT objectives to IT personnel
Domain 3: Benefits Realisation (16%)
Ensure that IT-enabled investments are managed to deliver optimised business benefits and that benefit realisation outcomes and performance measures are established, evaluated, and progress is reported to key stakeholders.
Domain 3—Knowledge Statements:
- Understanding of IT investment management processes, including the economic life cycle of investments
- Understanding of basic principles of portfolio management
- Understanding of benefit calculation techniques (for example, earned value, total cost of ownership, return on investment)
- Understanding of process and service measurement techniques (for example, maturity models, benchmarking, key performance indicators [KPIs])
- Understanding of processes and practices for planning, development, transition, delivery, and support of IT solutions and services
- Understanding of continuous improvement concepts and principles
- Understanding of outcome and performance measurement techniques (for example, service metrics, key performance indicators [KPIs])
- Understanding of procedures to manage and report the status of IT investments
- Understanding of cost optimisation strategies (for example, outsourcing, adoption of new technologies)
- Understanding of models and methods to establish accountability over IT investments
- Understanding of value delivery frameworks (for example, Val IT)
- Understanding of business case development and evaluation techniques
Domain 4: Risk Optimisation (24%)
Ensure that an IT risk management framework exists to identify, analyse, mitigate, manage, monitor, and communicate IT-related business risk, and that the framework for IT risk management is aligned with the enterprise risk management (ERM) framework.
Domain 4—Knowledge Statements:
- Understanding of the application of risk management at the strategic, portfolio, program, project, and operations levels
- Understanding of risk management frameworks and standards (for example, RISK IT, the Committee of Sponsoring Organizations of the Treadway Commission Enterprise Risk Management—Integrated Framework (2004) [COSO ERM], International Organization for Standardization (ISO) 31000)
- Understanding of the relationship of the risk management approach to legal and regulatory compliance
- Understanding of methods to align IT and enterprise risk management (ERM)
- Understanding of the relationship of the risk management approach to business resiliency (for example, business continuity planning [BCP] and disaster recovery planning [DRP])
- Understanding of risks, threats, vulnerabilities, and opportunities inherent in the use of IT
- Understanding of types of business risk, exposures, and threats (for example, external environment, internal fraud, information security) that can be addressed using IT resources
- Understanding of risk appetite and risk tolerance
- Understanding of quantitative and qualitative risk assessment methods
- Understanding of risk mitigation strategies related to IT in the enterprise
- Understanding of methods to monitor the effectiveness of mitigation strategies and/or controls
- Understanding of stakeholder analysis and communication techniques
- Understanding of methods to establish key risk indicators (KRIs)
- Understanding of methods to manage and report the status of identified risks
Domain 5: Resource Optimisation (15%)
Ensure the optimisation of IT resources, including information, services, infrastructure, and applications, as well as people, to support the achievement of enterprise objectives.
Domain 5—Knowledge Statements:
- Understanding of IT resource planning methods
- Understanding of human resource procurement, assessment, training, and development methodologies
- Understanding of processes for acquiring application, information, and infrastructure resources
- Understanding of outsourcing and offshoring approaches that may be employed to meet investment program and operation level agreements (OLAs) and service level agreements (SLAs)
- Understanding of methods used to record and monitor IT resource utilisation and availability
- Understanding of methods used to evaluate and report on IT resource performance
- Understanding of interoperability, standardisation, and economies of scale
Requirements
ISACA requires at least five years of IT governance experience across the five CGEIT domains to qualify for certification. You may sit the CGEIT exam before meeting ISACA's experience requirements; however, the CGEIT qualification will only be awarded once all requirements have been fulfilled. We do not set specific entry requirements for this course.
Testimonials (2)
Risk optimization is more clear than the other subjects
Munirah Alsahli - GOSI
Course - CGEIT – Certified in the Governance of Enterprise IT
The trainer was extremely clear and concise. Very easy to understand and absorb the information.