Certified IT Governance Manager
CITGM® evaluates advanced governance judgment rather than operational IT knowledge alone.
- Credential
- Certified IT Governance Manager
- Certification Designation
- CITGM®
- Certification Level
- Advanced / Management
- Certification Body
- International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
- Program Category
- Enterprise IT Governance, Technology Risk, Investment & Executive Oversight
- Delivery Format
- Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning
- Recommended Training Duration
- 50–60 Hours
- Certification Examination
- Proctored, advanced competency-based management examination
- Alternative Assessment Pathway
- Enterprise IT Governance Management Capstone
- Credential Renewal Cycle
- 3 Years
Govern Technology Value, Risk and Assurance.
What You Will Learn
Master the core areas of it governance.
Board & Executive Engagement
IT Risk Appetite & Management Framework
Regulatory Strategy & Compliance Programs
IT Investment, Portfolio & Value Governance
Third-Party & Supply Chain Governance
Assurance, Audit & Control Maturity
Governance Performance & Improvement
Become an IT Governance professional the market trusts.
Certification Designation: CITGM®
Certification Level: Advanced / Management
Certification Body: International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
Program Category: Enterprise IT Governance, Technology Risk, Investment & Executive Oversight
Delivery Format: Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning
Advanced Manager level — Three-year certification cycle with continuing professional education
Recommended Training Duration: 50–60 Hours
Certification Examination: Proctored, advanced competency-based management examination
Alternative Assessment Pathway: Enterprise IT Governance Management Capstone
Credential Renewal Cycle: 3 Years
Who Should Earn CITGM®?
CITGM® is designed for experienced professionals and leaders such as:
- IT Governance Manager
- Technology Governance Manager
- IT Risk Manager
- Technology Risk Manager
- GRC Manager
- IT Compliance Manager
- IT Controls Manager
- Governance and Assurance Manager
- Cybersecurity Governance Manager
- Technology Portfolio Manager
- IT Strategy Manager
- IT Service Governance Manager
- Vendor Governance Manager
- Third-Party Risk Manager
- Enterprise Architecture Governance Manager
- Data Governance Manager
- AI Governance Manager
- IT Audit Manager
- Technology Program Manager
- Director of IT Governance
- Director of Technology Risk
- Director of IT Strategy
- Director of GRC
- Senior Technology Consultant
- Senior IT Managers
- Professionals preparing for CIO, CTO, CISO, CRO, or technology-governance leadership responsibilities
CITGM® Body of Knowledge — Eight Modules
Module 1 — Enterprise Governance Strategy and Decision Rights
1.1 Governance Models and Enterprise Context
1.2 Governing Bodies, Committees, and Accountability
1.3 Decision Rights, Authority, and Escalation
1.4 Policies, Standards, Principles, and Governance Architecture
1.5 Governance Culture, Ethics, and Organizational Accountability
Module 2 — Strategy Alignment, Investment, Portfolio, and Value Governance
2.1 Enterprise and Technology Strategy Alignment
2.2 Technology Investment and Capital Allocation
2.3 Portfolio Prioritization and Resource Governance
2.4 Business Cases, Benefits, and Value Realization
2.5 Strategic Roadmaps, Transformation, and Post-Investment Review
Module 3 — Technology Risk, Controls, Compliance, and Assurance
3.1 Enterprise Technology Risk and Risk Appetite
3.2 Control Frameworks and Control Effectiveness
3.3 Compliance, Legal, Regulatory, and Contractual Governance
3.4 Audit, Assurance, and Independent Challenge
3.5 Exceptions, Remediation, Risk Acceptance, and Escalation
Module 4 — Cybersecurity, Data, Privacy, Continuity, and Resilience Governance
4.1 Cybersecurity Strategy and Governance
4.2 Information, Data, and Privacy Governance
4.3 Identity, Access, and Critical Information Controls
4.4 Business Continuity, Disaster Recovery, and Critical Services
4.5 Cyber Incidents, Crisis Oversight, Recovery, and Resilience
Module 5 — Architecture, Services, Vendors, and Technology Ecosystems
5.1 Enterprise Architecture Governance and Technology Standards
5.2 IT Service Governance and Business-Service Alignment
5.3 Sourcing, Outsourcing, and Cloud Governance
5.4 Vendor, Contract, SLA, and Third-Party Risk Governance
5.5 Concentration Risk, Dependency, Exit Planning, and Ecosystem Resilience
Module 6 — Governance Metrics, Performance, Maturity, and Assurance
6.1 Executive IT Governance KPIs and KRIs
6.2 Risk, Compliance, Control, and Assurance Dashboards
6.3 Benefits, Investment, Service, and Value Measurement
6.4 Governance Maturity and Capability Assessment
6.5 Board Reporting, Review, and Continual Improvement
Module 7 — AI Governance, Innovation, and Emerging Technology
7.1 Enterprise AI Governance and Accountability
7.2 AI Risk, Data, Ethics, Transparency, and Human Oversight
7.3 Automation, Algorithmic Decision-Making, and Control
7.4 Innovation Portfolio and Emerging-Technology Governance
7.5 Responsible Adoption, Assurance, Monitoring, and Future Readiness
Module 8 — Executive Leadership, Workforce, and Governance Transformation
8.1 Governance Workforce and Capability Strategy
8.2 Roles, Skills, Training, and Professional Development
8.3 Executive and Board-Level Technology Communication
8.4 Stakeholder Management and Governance Culture
8.5 Organizational Change and Governance Transformation
CITGM® Course Learning Outcomes
Upon successful completion, participants will be able to:
1. Design Enterprise IT Governance Structures
Establish governance bodies, decision rights, accountability, policies, operating models, and escalation.
2. Align Technology Strategy, Investment, and Enterprise Value
Govern technology strategy, business cases, portfolios, benefits, funding decisions, and value realization.
3. Direct Technology Risk, Compliance, Controls, and Assurance
Establish risk governance, control expectations, compliance oversight, audit-response processes, exceptions, and assurance mechanisms.
4. Govern Cybersecurity, Data, Privacy, and Resilience
Integrate cybersecurity, information governance, privacy, continuity, recovery, and resilience into enterprise oversight.
5. Govern Architecture, Services, Vendors, and Third Parties
Establish architecture governance, sourcing standards, provider oversight, service expectations, and third-party risk controls.
6. Measure Governance Performance and Maturity
Develop KPIs, KRIs, maturity assessments, executive dashboards, assurance measures, and improvement priorities.
7. Govern AI, Innovation, and Emerging Technology
Establish accountability, risk, ethics, transparency, human oversight, and investment governance for AI and emerging technology.
8. Advise Executives and Lead Governance Transformation
Translate technology risk, performance, and investment information into executive decisions and lead governance improvement.
CITGM® Certification Testing Outcomes — Skills & Competencies Tested
CITGM® evaluates advanced governance judgment rather than operational IT knowledge alone.
Governance Design
Evaluate governance structures, committees, responsibilities, decision rights, policies, escalation, and accountability.
Strategy and Value
Prioritize technology investments, assess strategic alignment, evaluate benefits, and determine value-realization actions.
Risk and Assurance
Evaluate risk appetite, technology risk, controls, compliance gaps, audit findings, exceptions, and assurance requirements.
Cybersecurity and Resilience Governance
Evaluate enterprise cybersecurity, incident governance, continuity, critical dependencies, recovery, and resilience.
Architecture and Ecosystem Governance
Evaluate technology standards, cloud, vendors, sourcing, architecture, concentration risk, and external dependencies.
Performance and Maturity
Interpret executive KPIs, KRIs, maturity information, control performance, benefits, and governance outcomes.
AI and Innovation Governance
Evaluate AI accountability, model oversight, automation, emerging risk, responsible use, and innovation decisions.
Executive Leadership
Translate technology conditions into enterprise risk, investment alternatives, governance recommendations, and board-level information.
CITGM® Competency Standard
Evaluate → Direct → Prioritize → Govern → Assure → Measure → Advise → Transform
CITGM®–IBACTP® IT Governance Management Competency Model
1. Enterprise Governance Strategy, Structures, and Decision Rights
Design governance operating models, committees, authority structures, policies, responsibilities, accountability, and escalation mechanisms.
2. Strategy Alignment, Portfolio Governance, and Value Realization
Govern strategic alignment, investments, portfolios, business cases, benefits, value, prioritization, funding, and resource allocation.
3. Enterprise Technology Risk, Controls, Compliance, and Assurance
Establish technology-risk approaches, risk appetite linkages, control frameworks, compliance oversight, assurance, audit responses, and exception governance.
4. Cybersecurity, Data, Privacy, Continuity, and Resilience Governance
Govern cybersecurity strategy, data, privacy, continuity, recovery, incident oversight, critical services, and resilience.
5. Architecture, Services, Vendors, and Technology Ecosystems
Govern enterprise architecture, technology standards, services, cloud, sourcing, vendors, outsourcing, third parties, and ecosystem dependencies.
6. Governance Performance, Metrics, Maturity, and Assurance
Establish executive KPIs and KRIs, maturity assessments, dashboards, assurance models, governance reviews, and improvement mechanisms.
7. AI Governance, Innovation, and Emerging Technology Risk
Establish governance for AI, automation, data-driven decisions, emerging platforms, innovation, responsible use, human oversight, and emerging risk.
8. Executive Communication, Board Oversight, Workforce, and Transformation
Communicate technology risk and value to senior leadership, develop governance capabilities, lead organizational change, and strengthen governance culture.
CITGM® Leadership Progression
Evaluate → Direct → Govern → Prioritize → Assure → Measure → Communicate → Transform
What Is CITGM®?
The Certified IT Governance Manager (CITGM®) validates advanced competency in designing, directing, evaluating, monitoring, assuring, and continuously improving enterprise governance of information and technology.
CITGM® develops managers capable of moving beyond procedural governance toward enterprise-level judgment and leadership.
The certification prepares managers to evaluate not only whether governance processes exist, but whether those processes actually produce:
CITGM® prepares managers to determine:
- Clear accountability
- Better decisions
- Controlled risk
- Improved performance
- Reliable assurance
- Appropriate investment
- Resilience
- Enterprise value
Recommended Prerequisites and Eligibility
Recommended Prerequisites and Eligibility
CITGM® is positioned at the advanced management level.
Recommended progression:
Standards and International Framework Alignment
The CITGP® and CITGM® Bodies of Knowledge should be strongly anchored in recognized governance, risk, cybersecurity, service management, continuity, privacy, and AI governance principles. A particularly important foundation is ISO/IEC 38500:2024, the current third edition of the international standard on governance of IT for the organization. ISO describes it as providing guiding principles for governing bodies and those supporting them regarding the effective, efficient, and acceptable use of IT. (ISO)
Relevant standards and frameworks include:
COBIT 2019 remains explicitly positioned by ISACA as a framework for the governance and management of enterprise information and technology and includes 40 governance and management objectives. (ISACA)
NIST CSF 2.0 is also particularly relevant because GOVERN is now one of its six core Functions and addresses cybersecurity strategy, expectations, policies, roles, responsibilities, supply-chain risk, and oversight in the context of enterprise risk management. (NIST)
ISO/IEC 27014 provides governance guidance specifically for information security, including the concepts of evaluation, direction, monitoring, and communication of information security activities. ISO indicates that the 2020 edition is currently published while a replacement edition is progressing through final development. (ISO)
- ISO/IEC 38500:2024 — Governance of IT for the Organization
- ISO/IEC 27001
- ISO/IEC 27002
- ISO/IEC 27005
- ISO/IEC 27014
- ISO/IEC 27701
- ISO/IEC 20000-1
- ISO 22301
- ISO 31000
- ISO/IEC 42001
- ISO/IEC 23894
- NIST Cybersecurity Framework 2.0
- NIST NICE Workforce Framework
- NIST AI Risk Management Framework
- COBIT 2019
- Relevant CISA cybersecurity guidance
- Recognized enterprise-risk, internal-control, audit, service-management, privacy, data-governance, and technology-assurance practices
CITGP® Framework Application Progression
Understand → Apply → Assess → Monitor → Report → Improve
CITGM® Framework Application Progression
Understand → Interpret → Evaluate → Direct → Monitor → Assure → Improve
Framework alignment does not constitute formal accreditation, certification, endorsement, sponsorship, recognition, or affiliation by the referenced organizations.
Global and Vendor-Neutral Design
CITGP® and CITGM® are designed around transferable governance competencies rather than dependence on one:
GRC Platform • Cloud Provider • ITSM Tool • Security Product • ERP System • Audit Platform • AI Vendor • Governance Framework
The certifications are intended to remain applicable across:
- Private companies
- Public-sector organizations
- Financial institutions
- Healthcare
- Technology
- Education
- Manufacturing
- Energy
- Telecommunications
- Consulting
- Nonprofit organizations
- Multinational enterprises
Global Governance Principle
One Governance Framework. Multiple Technologies. Enterprise-Wide Accountability.
Accreditation and Credentialing Quality Alignment
The CITGP® and CITGM® certification frameworks can incorporate professional credentialing principles associated with:
ISO/IEC 17024 • ANAB • NCCA • I.C.E. • International Personnel-Certification and Conformity-Assessment Practices
The credentialing framework encompasses:
- Job Task Analysis
- Defined professional and management competencies
- Eligibility standards
- Validated Body of Knowledge
- Examination blueprint
- SME review
- Psychometric principles
- Examination security
- Candidate identity verification
- Impartial certification decisions
- Appeals and complaints
- Professional ethics
- Continuing education
- Recertification
- Credential verification
- Periodic review
- Continuous improvement
Credentialing Quality Lifecycle
Define → Validate → Assess → Certify → Maintain → Verify → Review → Improve
Alignment with credentialing principles does not constitute formal accreditation, recognition, approval, endorsement, or affiliation. Any formal external status should be represented only after officially awarded by the applicable independent organization.
- Integrated CITGP®
- CITGM® Certification Pathway
- Professional Level
- Advanced / Management Level
CITGP® — Certified IT Governance Professional
Primary emphasis:
Understand • Assess • Apply • Monitor • Measure • Report • Improve
Professional objective:
Support Effective and Accountable Technology Governance
↓
CITGM® — Certified IT Governance Manager
Primary emphasis:
Evaluate • Direct • Govern • Prioritize • Assure • Measure • Lead • Transform
Leadership objective:
Govern Information and Technology for Enterprise Value
The progression moves professionals from applying governance frameworks, assessing controls, monitoring risk, and supporting assurance to designing governance structures, directing technology decisions, prioritizing investments, establishing accountability, advising executives, and transforming governance capabilities.
CITGP® vs. CITGM® Pathway Comparison
| Area | CITGP® — Professional | CITGM® — Advanced Manager |
|---|---|---|
| Primary Focus | Apply IT governance | Lead enterprise technology governance |
| Governance | Understand and apply | Design and direct |
| Strategy | Evaluate alignment | Establish governance direction |
| Decision Rights | Interpret | Define and govern |
| Risk | Assess and report | Establish risk governance |
| Controls | Evaluate | Govern control framework |
| Compliance | Support | Direct oversight |
| Assurance | Support testing/review | Establish assurance model |
| Cybersecurity | Apply governance | Direct cybersecurity governance |
| Data & Privacy | Apply controls | Govern enterprise requirements |
| Investment | Evaluate business cases | Prioritize portfolio and funding |
| Architecture | Support governance | Establish architecture oversight |
| Projects | Support governance | Direct portfolio governance |
| Vendors | Assess providers | Govern sourcing and dependency |
| Services | Monitor | Establish service governance |
| Metrics | Interpret KPIs/KRIs | Establish executive measures |
| AI Governance | Apply principles | Establish enterprise governance |
| Executive Reporting | Prepare information | Advise executives and boards |
| Transformation | Support improvement | Lead governance transformation |
| Objective | Support Accountable IT | Govern Technology for Enterprise Value |
IBACTP® IT Governance Career Pathway
- CITGP® — Professional Level
- CITGM® — Advanced / Management Level
Understand → Assess → Apply → Monitor → Measure → Report → Improve
Strengthen Accountability. Evaluate Risk. Support Better Technology Decisions.
↓
Evaluate → Direct → Govern → Prioritize → Assure → Measure → Lead → Transform
Govern Technology. Direct Investment. Protect Enterprise Value.
Certification Overview
Govern Technology. Direct Investment. Assure Accountability. Protect Enterprise Value.
The Certified IT Governance Manager (CITGM®) is an advanced, vendor-neutral management certification designed to validate leadership competency in the enterprise governance of information and technology.
CITGM® is intended for professionals who are responsible not merely for managing IT operations, but for helping ensure that technology decisions are aligned with enterprise strategy, appropriately governed, risk-informed, measurable, accountable, secure, resilient, and capable of delivering sustained organizational value.
The certification recognizes that modern technology governance extends far beyond traditional IT oversight. Enterprise leaders must now govern environments that may include:
CITGM® therefore develops managers who can connect:
- Cloud computing
- Cybersecurity
- Artificial intelligence
- Data and analytics
- Digital platforms
- Enterprise applications
- Automation
- Third-party ecosystems
- Privacy
- Technology architecture
- Business continuity
- Digital transformation
- Technology investment portfolios
Strategy + Technology + Risk + Investment + Accountability + Performance + Assurance
The certification prepares managers to establish and oversee the structures through which organizations:
CITGM® moves beyond supporting governance processes.
It prepares managers to:
- Align technology with business and enterprise strategy
- Establish governance structures and decision authority
- Define technology-related accountability
- Govern technology investments and portfolios
- Evaluate enterprise technology risk
- Oversee cybersecurity governance
- Govern data, privacy, and information responsibilities
- Establish architecture principles and technology standards
- Oversee IT services and critical technology capabilities
- Govern cloud, outsourcing, and third-party relationships
- Assure compliance and control effectiveness
- Monitor technology performance
- Evaluate benefits realization
- Govern artificial intelligence and emerging technologies
- Support executive and board oversight
- Improve governance maturity continuously
Design → Direct → Evaluate → Monitor → Assure → Improve
enterprise governance systems.
The certification integrates:
Enterprise Governance + Strategy + Decision Rights + Technology Investment + Risk + Cybersecurity + Architecture + Data + Vendors + Performance + Assurance + AI Governance + Executive Leadership
CITGM® Leadership Objective
Evaluate Enterprise Needs → Direct Technology Governance → Prioritize Investment → Govern Risk → Assure Performance → Strengthen Accountability → Advise Leadership → Protect Enterprise Value
What CITGM® Is Designed to Develop
CITGM® develops advanced management capability across several interconnected leadership responsibilities.
Strategic Governance
Managers must ensure that technology priorities reflect organizational strategy rather than operating as isolated technical initiatives.
Decision Governance
Managers must establish clarity around who can make technology decisions, who owns outcomes, and when issues require escalation.
Investment Governance
Managers must ensure that technology spending is prioritized based on value, risk, capability, cost, resilience, and strategic relevance.
Risk Governance
Managers must ensure that technology risks are identified, evaluated, treated, accepted at the appropriate level, and incorporated into broader enterprise risk.
Performance Governance
Managers must determine whether technology is actually delivering expected service, security, operational, financial, and strategic outcomes.
Assurance
Managers must establish confidence that controls, reports, metrics, audit evidence, and governance processes can be trusted.
Executive Governance
Managers must translate complex technology information into decision-relevant guidance for senior executives and boards.
The CITGM® Governance Perspective
CITGM® prepares managers to evaluate technology through multiple lenses at the same time.
Business Lens
Does the technology support enterprise priorities?
Risk Lens
What could go wrong, and what level of exposure is acceptable?
Financial Lens
Is the organization receiving sufficient value from its technology investment?
Control Lens
Are controls appropriately designed and operating effectively?
Performance Lens
Are technology services meeting expected outcomes?
Resilience Lens
Can critical technology capabilities withstand and recover from disruption?
Governance Lens
Are accountability and decision authority clear?
Assurance Lens
Can leadership trust the information being reported?
This multi-dimensional perspective is central to CITGM®.
Why CITGM®?
Technology Governance Is a Leadership Responsibility
Technology now influences nearly every major organizational objective.
Organizations depend on technology to:
As a result, technology decisions increasingly become executive and board-level decisions.
Leadership teams are routinely asked to consider:
These are not simply technical questions.
They are questions involving:
Strategy + Risk + Investment + Accountability + Enterprise Value
CITGM® is designed for this leadership environment.
- Generate revenue
- Serve customers
- Manage supply chains
- Protect sensitive information
- Deliver products and services
- Support employees
- Operate critical infrastructure
- Analyze data
- Automate processes
- Enable artificial intelligence
- Maintain regulatory compliance
- Support business continuity
- Drive innovation
- Should we migrate critical workloads to the cloud?
- How much cybersecurity investment is sufficient?
- Which legacy platforms should be modernized?
- Should we deploy generative AI?
- Can a third party be trusted with sensitive data?
- Should an identified technology risk be accepted?
- Is the organization sufficiently resilient?
- Are our technology investments producing value?
- Which projects should receive funding?
- What should leadership know about a major control failure?
Technology Governance Must Keep Pace With Technology Change
Technology is evolving faster than many traditional governance models.
Organizations are increasingly adopting:
Each introduces new questions involving:
CITGM® prepares managers to adapt governance principles to evolving technologies rather than relying only on static rules.
- Public and hybrid cloud
- AI and generative AI
- SaaS platforms
- Automation
- Low-code and no-code systems
- API ecosystems
- IoT
- Edge computing
- Digital platforms
- Third-party technology services
- Ownership
- Risk
- Security
- Privacy
- Data
- Cost
- Dependency
- Resilience
- Compliance
- Accountability
Governance Is About Direction, Not Micromanagement
The manager-level governance function should not attempt to make every technical decision.
Effective governance instead creates a structured environment within which management and technical teams can make appropriate decisions.
Strong governance establishes:
- Direction
- Authority
- Accountability
- Boundaries
- Measurement
- Assurance
Governance Must Balance Value and Risk
Poor governance may become overly restrictive.
Weak governance may expose the enterprise to unacceptable risk.
CITGM® teaches managers to find the appropriate balance between:
Value Creation + Risk Optimization + Resource Stewardship + Accountability
The goal is not to eliminate all technology risk.
The goal is to ensure that risk is:
- Understood
- Owned
- Controlled
- Accepted at the appropriate level
- Monitored
- Communicated
Governance Must Also Protect Enterprise Value
Technology governance is not simply about compliance.
A strong governance model should help ensure that technology:
CITGM® therefore treats governance as a mechanism for both:
- Supports strategic objectives
- Delivers measurable benefits
- Uses resources responsibly
- Protects information
- Strengthens resilience
- Reduces unnecessary complexity
- Enables innovation
- Avoids unmanaged risk
- Supports long-term organizational capability
- Value Creation
Value Protection
and:
Is Technology Governance Aligned With Enterprise Strategy?
Managers must evaluate whether technology governance supports broader organizational priorities.
Relevant questions include:
The objective is to connect:
- Do governance objectives reflect business strategy?
- Are major technology investments aligned with enterprise priorities?
- Are technology roadmaps coordinated with organizational transformation?
- Are governance priorities updated as strategy changes?
- Are business leaders adequately involved?
Are Governance Structures Appropriate?
Different organizations require different governance models.
Managers must determine:
CITGM® prepares managers to evaluate governance design based on organizational complexity, risk, scale, industry, and business model.
- Which governance bodies are required?
- Should there be an IT steering committee?
- Is cybersecurity governed separately?
- Who oversees data governance?
- Who governs AI?
- Are committee responsibilities duplicated?
- Are governance forums producing decisions or only meetings?
- Is accountability fragmented?
Are Decision Rights Clear?
A mature governance environment should identify who has authority to make decisions involving:
Ambiguous decision authority can create delay, duplication, and unmanaged risk.
- Technology standards
- Architecture
- Security controls
- Cloud adoption
- Risk acceptance
- Vendor selection
- Technology investment
- Data use
- AI deployment
- Project continuation
- Incident escalation
Are Accountability and Ownership Established?
CITGM® managers must determine whether responsibilities are assigned clearly.
Questions include:
Governance maturity requires moving from:
- Who owns the application?
- Who owns the data?
- Who owns the risk?
- Who owns the vendor?
- Who owns the service?
- Who owns the control?
- Who owns the remediation?
- “This named role owns this specific outcome.”
“IT is responsible.”
to:
Are Technology Investments Delivering Value?
CITGM® prepares managers to evaluate technology investments throughout their lifecycle.
The governance process includes:
Are Technology Risks Within Tolerance?
CITGM® prepares managers to connect technology risk with enterprise risk appetite.
Managers evaluate:
A mature risk-governance process ensures that high-risk technology decisions are not accepted casually or by individuals without appropriate authority.
- Inherent risk
- Controls
- Residual risk
- Risk tolerance
- Risk ownership
- Treatment
- Acceptance
- Escalation
- Monitoring
Are Cybersecurity Risks Appropriately Governed?
Cybersecurity governance requires more than operational security controls.
Managers must determine:
- Who owns cyber risk?
- How does cyber risk connect to enterprise risk?
- Are critical assets identified?
- Are security investments prioritized appropriately?
- Are significant incidents escalated?
- Are exceptions governed?
- Are cyber metrics meaningful?
- Is leadership receiving appropriate information?
- Are lessons learned driving improvement?
Are Architecture Decisions Consistent With Enterprise Direction?
Architecture governance helps prevent uncontrolled technology sprawl.
CITGM® prepares managers to govern:
The goal is not to prevent architectural flexibility.
It is to ensure that major architecture decisions support long-term enterprise objectives.
- Technology standards
- Target architecture
- Cloud strategy
- Integration standards
- Data architecture
- Security architecture
- Technical debt
- Legacy technology
- Exceptions
- Modernization
Are Data and Privacy Responsibilities Clear?
Modern organizations depend heavily on data.
CITGM® therefore integrates governance of:
Managers must ensure that responsibility for information is defined, not assumed.
- Data ownership
- Data stewardship
- Classification
- Access
- Quality
- Retention
- Privacy
- Data sharing
- Data lifecycle
- AI data use
Are Service Providers Appropriately Governed?
Organizations increasingly depend on external providers.
CITGM® addresses governance of:
Managers evaluate:
- Cloud providers
- SaaS providers
- Managed services
- Outsourcing
- Consultants
- Technology suppliers
- Data processors
- Security providers
- Due diligence
- Contracts
- SLAs
- Security
- Privacy
- Continuity
- Performance
- Concentration risk
- Exit strategy
- Dependency
Are Third-Party Dependencies Understood?
A provider may depend on other providers.
That creates fourth-party and ecosystem risk.
Managers may need to understand:
The governance perspective expands from:
- Critical subcontractors
- Geographic dependencies
- Cloud concentration
- Shared platforms
- Data processors
- Software suppliers
- Infrastructure dependencies
Vendor Risk
to:
Are Critical Technology Services Resilient?
Governance must ensure that business-critical technology can survive or recover from disruption.
CITGM® addresses:
Executives need confidence not merely that recovery plans exist, but that they are credible and tested.
- Business impact
- Critical services
- Recovery objectives
- Redundancy
- Disaster recovery
- Continuity
- Backup
- Incident escalation
- Recovery testing
- Dependency analysis
- Lessons learned
Are KPIs and KRIs Meaningful?
A governance dashboard can contain dozens of metrics and still provide little value.
CITGM® develops the ability to distinguish between:
Operational Metrics
What activity occurred?
Performance Indicators
Are expected outcomes being achieved?
Risk Indicators
Is exposure increasing or decreasing?
Control Indicators
Are important controls operating effectively?
Value Measures
Are investments producing intended benefits?
The objective is:
Measure What Supports Decisions—not What Is Convenient to Count
Are Audit Findings Being Remediated?
Audit findings should not remain open indefinitely.
Managers must ensure that:
CITGM® helps managers move from:
- Ownership is assigned
- Remediation plans exist
- Dates are realistic
- Evidence is collected
- Risk is monitored
- Extensions are governed
- Closure is independently validated where appropriate
- Sustainable Control Improvement
Audit Finding Management
to:
Does Leadership Receive Decision-Relevant Information?
Executives and boards do not need every technical detail.
They need to understand:
CITGM® develops the ability to translate:
Technology Condition → Enterprise Risk → Business Impact → Decision Options → Leadership Action
- What matters
- What changed
- What risk exists
- What decision is required
- What investment is needed
- What the alternatives are
- What happens if no action is taken
Is AI Being Governed Responsibly?
Artificial intelligence expands the governance agenda.
CITGM® prepares managers to consider:
The management question is not simply:
- AI inventory
- Ownership
- Approved use cases
- Data sources
- Model risk
- Privacy
- Security
- Bias
- Reliability
- Transparency
- Human oversight
- Third-party AI
- Monitoring
- Incident response
- Decommissioning
“Can we use AI?”
It is:
“Should we use it, under what controls, for what purpose, with what oversight, and with what accountability?”
Are Technology Benefits Being Realized?
Governance should not end when a project is completed.
Managers must determine whether:
This is benefits realization.
The progression becomes:
Investment → Delivery → Adoption → Outcome → Value
- Users adopted the solution
- Expected efficiencies occurred
- Costs decreased
- Risks were reduced
- Customer experience improved
- Revenue increased
- Service performance improved
- Strategic capability increased
Is the Governance Model Mature Enough?
Not every organization needs the same governance complexity.
A small organization may use simpler structures.
A multinational organization may require:
CITGM® prepares managers to assess governance maturity across areas such as:
The objective is not governance for governance's sake.
It is:
Governance Appropriate to the Organization's Scale, Risk, Complexity, and Strategy
- Formal committees
- Regional governance
- Segregated responsibilities
- Regulatory oversight
- Multiple assurance functions
- Extensive portfolio governance
- Strategy alignment
- Decision rights
- Accountability
- Risk
- Controls
- Performance
- Assurance
- Technology investment
- AI governance
- Continuous improvement
CITGM® Enterprise Governance Lifecycle
CITGM® connects the complete leadership lifecycle:
Enterprise Strategy → Governance Direction → Decision Rights → Investment → Risk → Controls → Performance → Assurance → Executive Oversight → Improvement
This lifecycle reinforces that governance is continuous.
It should adapt as:
-
01
Strategy changes
Technology evolves
-
02
Risk changes
New regulations emerge
-
03
Incidents occur
Investments succeed or fail
-
04
AI adoption expands
Organizational priorities change
What Makes CITGM® Different?
CITGM® develops managers across several critical leadership transitions.
From IT Oversight to Enterprise Governance
“IT manages technology.”
becomes:
“The enterprise establishes direction, accountability, risk parameters, and performance expectations for technology.”
From Spending to Investment Governance
“The budget was approved.”
becomes:
“The investment is strategically justified, governed throughout delivery, and measured for value.”
From Risk Registers to Risk Decisions
“The risk is documented.”
becomes:
“The risk has an owner, treatment, tolerance assessment, monitoring approach, and appropriately authorized decision.”
From Compliance to Assurance
“The control exists.”
becomes:
“There is sufficient evidence to conclude that the control operates effectively.”
From Dashboards to Executive Decisions
“Here are the technology metrics.”
becomes:
“Here is what leadership needs to understand, decide, and prioritize.”
From AI Adoption to AI Governance
“The business wants AI.”
becomes:
“The organization understands the value, data, risk, accountability, controls, monitoring, and human-oversight requirements.”
CITGM® Leadership Value Proposition
CITGM® integrates:
Enterprise Governance + Strategy + Investment + Decision Rights + Risk + Cybersecurity + Architecture + Data + Vendors + Performance + Assurance + AI + Executive Leadership
Its central management objective is:
Set Direction → Establish Accountability → Govern Investment → Optimize Risk → Assure Performance → Advise Leadership → Strengthen Governance → Protect Enterprise Value
- CITGP®
- CITGM® Progression
CITGP® — Professional Level
Understand • Assess • Apply • Monitor • Measure • Report • Improve
Primary objective:
Support Effective Technology Governance
↓
CITGM® — Advanced / Management Level
Evaluate • Direct • Govern • Prioritize • Assure • Measure • Advise • Transform
Primary objective:
Lead Enterprise Governance of Information and Technology
The progression moves the professional from:
Supporting Governance Processes
to:
Designing and Leading Enterprise Governance Systems
CITGM® Leadership Identity
A CITGM® leader should be capable of asking:
That is the advanced leadership capability CITGM® is designed to develop and validate.
- Does technology strategy support enterprise strategy?
- Are decision rights clear?
- Who owns the risk?
- Is accountability explicit?
- Are investments delivering value?
- Is residual risk within tolerance?
- Are controls effective?
- Are cybersecurity risks visible to leadership?
- Are architecture decisions sustainable?
- Is data being governed appropriately?
- Are vendors creating unacceptable dependency?
- Can critical services recover?
- Are our KPIs and KRIs meaningful?
- Can assurance results be trusted?
- Is AI governed responsibly?
- Are executives receiving decision-relevant information?
- Is the governance model improving?
- CITGP®
- CITGM®
Equivalent qualifying experience in IT governance, technology risk, cybersecurity governance, IT audit, compliance, enterprise architecture, information systems, technology management, portfolio management, internal controls, or executive technology leadership may satisfy applicable IBACTP® requirements.
Candidates should possess sufficient understanding of business and technology to evaluate the effectiveness of governance and appropriately challenge technology decisions.
Tools, Technologies, and Enterprise Governance Environments
CITGM® is vendor-neutral, but managers should understand categories such as:
Governance and GRC
Governance Platforms • GRC Systems • Policy Management • Risk Registers • Control Framework Repositories
Portfolio and Investment
Portfolio Management • Financial Planning • Business Cases • Benefits Tracking • Technology Roadmaps
Risk and Assurance
Audit Platforms • Compliance Systems • Control Testing • Evidence Management • Issue Management
Cybersecurity
Security Governance Dashboards • Vulnerability Data • Identity Metrics • Security Risk Reporting • Incident Governance
Service and Vendors
ITSM • CMDB • Vendor Management • Contract Management • SLA Monitoring • Third-Party Risk Platforms
Architecture and Data
Enterprise Architecture Repositories • Data Catalogs • Privacy Systems • Information-Governance Platforms
AI Governance
AI Inventories • Model Registers • AI Risk Assessments • Control Documentation • Monitoring and Assurance
Management focus:
Direction → Accountability → Evidence → Oversight → Assurance → Decision → Value
Flexible CITGM® Certification Assessment
Option 1 — CITGM® Certification Examination
100 Questions
90 Minutes
Advanced Multiple-Choice + Scenario-Based Management Questions
Closed Book
Secure Online Proctoring or Approved Testing Center
Recommended Passing Score: 70%
Assessment emphasizes:
Enterprise Governance • Strategy • Investment • Risk • Controls • Assurance • Resilience • Vendors • Metrics • AI • Executive Judgment
Option 2 — Enterprise IT Governance Management Capstone
Eligible candidates participating in an approved instructor-led pathway may demonstrate advanced competency through a structured Enterprise IT Governance Management Capstone.
The Capstone may integrate:
Enterprise Context → Governance Design → Risk Assessment → Investment Prioritization → Assurance → Executive Recommendation → Governance Transformation
CITGM® Certification Value Proposition
CITGM® integrates:
Enterprise Governance + Strategy + Investment + Risk + Assurance + Cybersecurity + Architecture + Vendors + Performance + AI + Executive Leadership
Its central management objective is:
Direct Technology Governance → Prioritize Investment → Govern Risk → Assure Accountability → Measure Value → Advise Leadership → Transform Enterprise Governance
Certified IT Governance Manager (CITGM®)
Govern Technology. Direct Investment. Assure Accountability. Protect Enterprise Value.
CITGM® aligns with senior roles at the intersection of:
Technology Management + Enterprise Governance + Cybersecurity + Risk + Compliance + Strategy + Investment + Assurance
There is no single BLS occupation titled “IT Governance Manager.” The closest official management benchmark is the Computer and Information Systems Managers benchmark, supplemented by governance-specific private-market salary data.
Technology Management Outlook
BLS reports approximately:
667,100 Computer and Information Systems Manager Jobs in 2024
Employment is projected to reach approximately:
768,700 by 2034
representing:
101,600 Additional Positions
and:
15% Employment Growth
between 2024 and 2034. (Bureau of Labor Statistics)
That growth rate is roughly five times the projected 3.1% growth for all U.S. occupations. (Bureau of Labor Statistics)
BLS projects approximately:
55,600 Openings Per Year
for computer and information systems managers over the 2024–2034 period. (Bureau of Labor Statistics)
Why Technology Governance Leadership Demand Is Growing
BLS expects continued demand for computer and information systems managers as organizations increase their reliance on complex technology environments.
BLS specifically identifies expansion in:
as factors contributing to management demand. (Bureau of Labor Statistics)
For CITGM® professionals, these same developments create governance questions involving:
Accountability • Investment • Risk • Architecture • Security • Data • Performance • Third Parties • AI • Executive Oversight
- Cloud computing
- Cybersecurity
- Digital platforms
- Artificial intelligence
CITGM® Salary Outlook
IT Governance Manager — U.S. Market Benchmark
As of July 1, 2026, Salary.com reported average U.S. compensation for an IT Governance Manager of approximately:
$137,517 Per Year
equivalent to approximately:
$66 Per Hour. (Salary)
The reported salary distribution was:
Percentile
Annual Salary
10th Percentile
$115,830
25th Percentile
$126,165
Average
$137,517
75th Percentile
$149,301
90th Percentile
$160,030
(Salary)
IT Governance Manager Salary by Experience
Salary.com's July 2026 market estimates show compensation increasing significantly with experience:
(Salary)
These are third-party market estimates and should not be interpreted as guaranteed compensation.
| Career Stage | Estimated Salary |
|---|---|
| Entry-Level / <1 year | $92,457 |
| Early Career / 1–2 years | $128,039 |
| Mid-Level / 2–4 years | $136,651 |
| Senior / 5–8 years | $166,773 |
| Expert / 8+ years | $206,220 |
IT Governance Manager Salary by State
Salary.com's July 2026 estimates illustrate substantial differences across geographic markets.
(Salary)
In Washington, D.C., Salary.com separately estimated an IT Governance Manager average around $152,257 in June 2026, with the middle 50% earning approximately $139,693–$165,304. (Salary)
| Location | Estimated Average Salary |
|---|---|
| District of Columbia | $152,259 |
| California | $151,681 |
| Massachusetts | $149,660 |
| Washington | $149,110 |
| New Jersey | $149,055 |
| New York | $146,194 |
| Maryland | $141,794 |
| Illinois | $140,171 |
| Virginia | $138,480 |
| Texas | $134,134 |
| North Carolina | $130,682 |
| South Carolina | $128,853 |
IT Governance Manager Compensation by Industry
Salary.com's 2026 estimates also show that industry can materially influence compensation.
Examples reported for IT Governance Managers included:
(Salary)
This reflects the greater strategic importance that technology governance may have in highly digital, heavily regulated, infrastructure-intensive, or risk-sensitive sectors.
| Industry | Estimated Average Salary |
|---|---|
| Software & Networking | $169,748 |
| Biotechnology | $162,958 |
| Energy & Utilities | $156,168 |
| Financial Services | $149,378 |
| Chemicals | $149,378 |
Official Technology Management Salary Benchmark
The BLS median annual wage for Computer and Information Systems Managers was:
$171,200 in May 2024
with the lowest 10% earning less than $104,450 and the highest 10% earning more than $239,200. (Bureau of Labor Statistics)
The highest-paying major industries reported by BLS included:
(Bureau of Labor Statistics)
Latest BLS 2025 Management Wage Data
The BLS May 2025 Occupational Employment and Wage Statistics reported approximately:
670,570 Computer and Information Systems Managers
earning a national mean wage of:
$192,160 Per Year
or approximately:
$92.39 Per Hour. (Bureau of Labor Statistics)
This provides an important official benchmark for senior technology-management roles into which experienced CITGM® professionals may progress.
| Industry | 2024 Median Annual Wage |
|---|---|
| Information | $196,060 |
| Finance & Insurance | $176,570 |
| Manufacturing | $174,790 |
| Management of Companies & Enterprises | $172,830 |
| Computer Systems Design & Related Services | $171,250 |
Why CITGM® Can Support Senior Career Progression
CITGM® competencies become increasingly relevant as professionals move from evaluating individual controls toward enterprise-level responsibilities involving:
Strategy
Which technology capabilities should the enterprise develop?
Investment
Which initiatives deserve funding?
Risk
Which exposures require executive attention?
Governance
Who should make decisions and who is accountable?
Assurance
Can leadership trust the reported information?
Resilience
Can critical technology survive disruption?
AI
How should new technology be governed?
Executive Communication
What do senior leaders and boards need to know?
This combination of technical understanding and management judgment can support progression into senior governance, risk, technology, cybersecurity, and assurance leadership roles.
Potential Careers for CITGM® Professionals
CITGM® competencies may support career progression toward roles such as:
- IT Governance Manager
- Technology Governance Manager
- Governance, Risk and Compliance Manager
- Technology Risk Manager
- IT Risk Manager
- IT Controls Manager
- Technology Controls Manager
- IT Compliance Manager
- Cybersecurity Governance Manager
- Information Security Governance Manager
- Technology Assurance Manager
- IT Audit Manager
- Vendor Governance Manager
- Third-Party Risk Manager
- Cloud Governance Manager
- Data Governance Manager
- AI Governance Manager
- Technology Portfolio Manager
- IT Strategy Manager
- Enterprise Architecture Governance Manager
- Director of IT Governance
- Director of Technology Risk
- Director of GRC
- Director of IT Strategy
- Director of Technology Assurance
- Head of Technology Governance
- Senior Technology Consultant
- Senior Technology Risk Advisor
Executive-Level Progression
Experienced governance managers may eventually progress toward broader executive responsibilities such as:
These positions typically require substantial experience beyond certification alone, but the governance competencies emphasized by CITGM®—strategy, investment, enterprise risk, accountability, assurance, and executive communication—are highly relevant to such career pathways.
- Chief Information Officer
- Chief Technology Officer
- Chief Information Security Officer
- Chief Risk Officer
- Chief Digital Officer
- VP of Technology Risk
- VP of IT Governance
- VP of Technology Strategy
- Head of Enterprise Technology Governance
Industries With Strong IT Governance Relevance
IT-governance expertise may be particularly important in sectors such as:
Financial Services
Banks, insurance companies, asset managers, payment platforms, and fintech organizations operate in highly regulated and technology-dependent environments.
Healthcare
Healthcare organizations must govern systems, cybersecurity, sensitive information, cloud services, clinical technologies, and third parties.
Government
Government agencies require accountability, security, procurement discipline, controls, assurance, and responsible stewardship of technology resources.
Technology
Technology organizations require governance of cloud environments, platforms, cybersecurity, AI, data, architecture, and digital services.
Energy and Utilities
Critical infrastructure environments place strong emphasis on cybersecurity, continuity, resilience, vendor dependency, and operational technology.
Manufacturing
Digital manufacturing, IoT, supply chains, automation, cloud, and operational technologies create expanding governance requirements.
Professional and Consulting Services
Organizations increasingly rely on consultants for IT governance, cybersecurity, GRC, audit, risk, digital transformation, and technology strategy.
CITGM® Employment Outlook Summary
15%
Projected growth in Computer and Information Systems Manager employment, 2024–2034. (Bureau of Labor Statistics)
101,600
Projected additional technology-management positions by 2034. (Bureau of Labor Statistics)
55,600
Projected average annual openings for Computer and Information Systems Managers. (Bureau of Labor Statistics)
$171,200
2024 BLS median annual wage for Computer and Information Systems Managers. (Bureau of Labor Statistics)
$192,160
May 2025 BLS mean annual wage for Computer and Information Systems Managers. (Bureau of Labor Statistics)
$239,200+
Upper-decile threshold reported by BLS for Computer and Information Systems Managers in May 2024. (Bureau of Labor Statistics)
$137,517
July 2026 market-average salary estimate for U.S. IT Governance Managers. (Salary)
$160,030
Salary.com's estimated 90th-percentile IT Governance Manager salary. (Salary)
$206,220
Salary.com's estimated average for IT Governance Managers with more than eight years of experience. (Salary)
CITGP® → CITGM® Career & Compensation Progression
| Career Dimension | CITGP® — Professional | CITGM® — Advanced Manager |
|---|---|---|
| Primary Focus | Apply and support governance | Lead enterprise governance |
| Typical Role | Analyst / Specialist / Consultant | Manager / Director / Governance Leader |
| Governance | Assess and monitor | Design and direct |
| Technology Risk | Analyze | Govern enterprise exposure |
| Controls | Evaluate | Establish assurance |
| Compliance | Support | Direct oversight |
| Cybersecurity | Governance analysis | Enterprise cyber governance |
| Investment | Analyze business cases | Prioritize funding |
| Vendors | Assess | Govern relationships |
| Metrics | Interpret | Establish executive KPIs/KRIs |
| AI Governance | Support controls | Establish enterprise oversight |
| Communication | Governance reporting | Executive and board communication |
| Market Salary Example | GRC Analyst avg. $100,913 | IT Governance Manager avg. $137,517 |
| Broader BLS Benchmark | $114,610 systems analysts / $132,510 security analysts | $192,160 mean for CIS managers |
| Career Objective | Support Accountable Technology Decisions | Govern Technology for Enterprise Value |
Website Employment Outlook Callout
- “Is it aligned with strategy?”
- “Is the risk acceptable?”
- “Are the controls effective?”
- “Is the investment delivering value?”
- “Can leadership trust the information?”
IT Governance Careers Sit at the Intersection of Technology, Risk, Cybersecurity, Compliance, and Executive Decision-Making
Organizations increasingly need professionals capable of answering not only:
“Does the technology work?”
but:
“Who is accountable?”
The labor-market indicators supporting these capabilities remain strong: information-security employment is projected to grow 29%, systems-analysis and management-analysis occupations 9%, and computer and information systems management 15% through 2034. (Bureau of Labor Statistics)
CITGP®
Build the Competency to Assess Governance, Risk, Controls, Performance, and Assurance.
↓
CITGM®
Develop the Leadership Capability to Govern Technology, Investment, Risk, and Enterprise Value.
CITGP® → CITGM®
From IT Governance Practice to Enterprise Technology Governance Leadership.
Employment and salary information is provided for career-planning and informational purposes. BLS figures represent broad U.S. occupational categories and are not specific to CITGP® or CITGM®. Salary.com figures are third-party market estimates for specific job titles. Certification does not guarantee employment, promotion, eligibility for a particular role, or compensation level. Actual compensation varies based on experience, education, responsibilities, geography, industry, employer, skills, and other factors.
- CITGP®
- CITGM®
- From IT Governance Competency to Enterprise Technology Governance Leadership.
Exam & Certification Details
Everything you need to plan your sitting.
CITGM-200
Exam code for the Advanced Manager-level IT Governance credential.
100 questions (maximum)
Multiple choice, completed in 120 minutes.
700 out of 1000
Passing score. Delivered in English.
Recommended experience
A minimum of five years of experience, including two years in a supervisory, lead or management role.
Where you sit it
IBACTP® approved testing centers and online proctored delivery
Staying certified
Three-year certification cycle with continuing professional education
Four ways to enroll. One credential.
Every route leads to the same CITGM® examination and the same designation.
Your Certification Pathway
Start as a Professional. Advance as a Leader.
Ready to certify as a CITGM®?
Self-Paced Learning
Exam fee only, with complimentary course materials provided — $400 USD.
Virtual Instructor-Led Training
4 days, 2 hours daily online. All course materials + Exam — $1,200 USD.
Bootcamps & Intensives
10 days, 2 hours daily. All course materials + Exam — $1,800 USD.
Corporate Training
Certify a whole team on a schedule that suits your organization. Fees negotiable.
Take the next step in IT Governance
Apply, choose your preparation route and book your examination with an approved provider.
Frequently Asked Questions — CITGP® & CITGM®
What is CITGP®?
CITGP® is a vendor-neutral professional IT-governance certification focused on governance principles, strategy alignment, technology risk, controls, compliance, cybersecurity governance, investments, vendors, performance, assurance, and AI governance.
What is CITGM®?
CITGM® is an advanced IT-governance management certification focused on enterprise governance structures, strategy, decision rights, technology investment, risk, controls, cybersecurity, architecture, vendors, performance, assurance, AI, and executive leadership.
How is CITGP® different from CITGM®?
CITGP® focuses on applying governance principles, analyzing risk, evaluating controls, monitoring performance, and supporting assurance.
CITGM® focuses on designing governance structures, directing technology decisions, prioritizing investments, establishing accountability, measuring enterprise outcomes, and advising leadership.
Do I need CITGP® before CITGM®?
CITGP® is the recommended professional progression. Equivalent qualifying experience in IT governance, technology risk, cybersecurity governance, audit, controls, compliance, information systems, architecture, or technology management may satisfy applicable IBACTP® eligibility requirements.
Is CITGP® an IT audit certification?
No. Audit and assurance form part of the curriculum, but CITGP® is broader. It also covers strategy, investment, risk, controls, cybersecurity, services, vendors, performance, data, AI, and governance structures.
Do the certifications cover COBIT?
Yes. COBIT concepts can form an important part of the governance framework alignment, while the certifications remain vendor- and framework-neutral rather than operating as COBIT product certifications. COBIT 2019 is explicitly designed for governance and management of enterprise information and technology. (ISACA)
Do the certifications cover ISO/IEC 38500?
Yes. ISO/IEC 38500:2024 is particularly relevant because it provides principles for governance of IT for organizations. (ISO)
Do they cover cybersecurity governance?
Yes. Both credentials integrate cybersecurity risk with enterprise governance. NIST CSF 2.0's GOVERN Function reinforces the importance of strategy, policy, roles, oversight, and enterprise-risk integration. (NIST)
Do they cover risk and compliance?
Yes. Technology risk, controls, regulatory and contractual requirements, compliance, exceptions, assurance, and remediation are core elements.
Do they cover vendor and third-party governance?
Yes. Sourcing, providers, cloud services, contracts, SLAs, concentration risk, dependency, third-party risk, and exit considerations are included.
Does CITGM® cover technology investment?
Yes. Business cases, prioritization, portfolio governance, funding, benefits realization, performance, and enterprise value are central management competencies.
Do they cover AI governance?
Yes. CITGP® addresses responsible AI use, accountability, risk, transparency, human oversight, and controls. CITGM® advances these areas into enterprise AI governance, investment, assurance, policy, monitoring, and executive oversight.
Does CITGM® prepare professionals for board communication?
Yes. Translating technology risk, investment, performance, assurance, resilience, and emerging technology issues into decision-relevant information for executives and boards is a major competency.
How are candidates assessed?
Candidates may complete the applicable CITGP® or CITGM® certification examination or, where eligible, complete the corresponding applied or management Capstone through an approved instructor-led pathway.
How long are the certifications valid?
The recommended credential cycle is three years, subject to applicable IBACTP® continuing professional education, professional ethics, certification-maintenance, and recertification requirements.