This chapter discusses IT governance and related topics that will represent approximately 15% of the CISA examination. The key learning objectives are to evaluate the effectiveness of an organization's IT governance structure, strategy, policies, risk management, and monitoring practices. Best practices for IT governance include establishing an IT strategy committee, using an IT balanced scorecard to evaluate performance, and ensuring effective information security governance. The chapter also covers IT strategic planning, policies, procedures, risk management, personnel management, sourcing strategies, and outsourcing considerations.