11.3 Governance Versus Management Objectives
Key Takeaways
- Governance objectives live only in EDM, use Evaluate / Direct / Monitor, and start with Ensured.
- Management objectives live in APO, BAI, DSS, and MEA, use plan / build / run / monitor, and start with Managed.
- Management executes inside the direction EDM sets; the CIO does not absorb the board’s EDM role by running the work.
- EDM03 Ensured Risk Optimization, APO12 Managed Risk, and DSS05 Managed Security Services are risk and security at board, planning, and run layers.
- MEA is management monitoring. Do not call it a governance domain because the name is Monitor, Evaluate and Assess.
Quick Answer: Governance objectives live only in EDM, use Evaluate / Direct / Monitor, and start with Ensured. Management objectives live in APO, BAI, DSS, and MEA, use plan / build / run / monitor, and start with Managed. Management executes inside the direction EDM sets. EDM03 Ensured Risk Optimization, APO12 Managed Risk, and DSS05 Managed Security Services are the same concern at three layers. MEA is management monitoring, not board governance. Calling MEA a governance domain because it says Monitor, Evaluate and Assess is a Foundation miss.
Chapter 5 taught governance distinct from management as a principle. This section is the objective-catalog version of the same split. The exam will hand you a title, a verb, or a short scenario and expect you to land in the right domain without reciting practices. If you can apply the pattern in fifteen seconds, you will clear most recognition items in the 23% domain.
The recognition pattern
| Signal | Governance objectives | Management objectives |
|---|---|---|
| Domain | EDM only | APO, BAI, DSS, MEA |
| Title verb | Ensured … | Managed … |
| Activity verbs | Evaluate, Direct, Monitor | Plan, Build, Run, Monitor |
| Owner | Board / governing body | Executive management, including the CIO |
| Count | 5 | 35 |
| Question the objective answers | Are we doing the right I&T things, inside appetite, with the right resources and stakeholders? | Are we planning, building, running, and checking the work the board directed? |
If the official title starts with Ensured, you are in governance. If it starts with Managed, you are in management. Do not “fix” a title on the exam. Ensured Risk Optimization is not “Managed Risk,” and Managed Risk is not a governance objective.
Monitor appears on both verb lists. That is intentional. Governance monitors whether direction is followed and whether value, risk, and resources stay in balance. Management monitors whether the work is performing — service levels, control operation, project progress, compliance tasks. Same English word. Different altitude. Shared vocabulary is not shared ownership.
Management executes inside EDM direction
The split is a loop, not a wall. EDM evaluates stakeholder needs and options, directs priorities, appetite, resource envelopes, and engagement rules, then monitors whether that direction is producing balanced value. Management’s 35 objectives plan, build, run, and monitor inside that envelope.
Without EDM, management is self-directed: the CIO shop decides what “good” means and then grades its own homework. Without management, EDM is a board resolution with no operating system: appetite exists on paper and nobody treats risk, nobody runs security services, nobody delivers the service. Foundation items punish both “the CIO is the board because the CIO is senior” and “the board should run the service desk to stay in control.”
Harborline’s CIO can chair a stand-up, approve a sprint, and reassign analysts. Those acts sit in APO, BAI, DSS, and MEA. They become aligned management only if EDM has already set the framework (EDM01), the benefits expectation (EDM02), the appetite (EDM03), the resource envelope (EDM04), and the stakeholder reporting rules (EDM05). Busy management does not absorb empty governance.
The opposite failure is testable too. If Harborline’s chair starts assigning developers or rewriting the vendor statement of work, the governing body has dropped into management and can no longer monitor independently. Distinction runs both ways.
Three-layer example: EDM03, APO12, DSS05
This is a high-yield distinction. Risk and security appear at three altitudes in the core model. Candidates who treat the three titles as synonyms will miss items that look easy.
EDM03 Ensured Risk Optimization is the board layer. Risk appetite and tolerance are understood. I&T-related risk is identified and managed as a governance outcome. The board does not write the operational risk register. It ensures that an appetite exists, that I&T-related risk is in the governance conversation, and that residual risk is monitored against the envelope.
APO12 Managed Risk is the management-planning layer. Executive management manages the I&T risk process: identify, assess, treat, and report risk in line with the appetite EDM03 set. This is where risk methodology, risk registers, treatment plans, and management risk committees live. The title starts with Managed. The domain is APO. The owner is management.
DSS05 Managed Security Services is the run layer. Operations protect information assets: identities, endpoints, vulnerabilities, and security events. DSS05 Managed Security Services executes security services day to day. It is not the board’s appetite conversation and not the enterprise I&T risk process. A SOC triage is DSS, not EDM.
Walk Harborline once. The board sets a low appetite for claimant-data exposure — EDM03 Ensured Risk Optimization. The CISO organization designs a treatment plan and reports residual risk against that appetite — APO12 Managed Risk. The security-operations team patches, monitors, and responds — DSS05 Managed Security Services. If the stem says “the board approved appetite,” you are in EDM03. If it says “management maintains the I&T risk process,” you are in APO12. If it says “the SOC triages an alert,” you are in DSS05.
The same three-layer habit helps elsewhere, but learn the risk/security triple first. Value often runs EDM02 Ensured Benefits Delivery (board value) to portfolio and investment management (APO) to project delivery (BAI). Resources often run EDM04 Ensured Resource Optimization to people and service-agreement management (APO) to the operational run (DSS). Always start from owner, title verb, and altitude — never from the single English word “risk,” “security,” or “monitor.”
MEA is not governance
MEA Monitor, Evaluate and Assess is a management domain. Its four objectives start with Managed. Management monitors performance and conformance, the internal-control system, compliance with external requirements, and assurance.
The name looks like Evaluate / Monitor, so candidates drag MEA into the board column. That is the trap the blueprint is built to catch.
- Board monitoring = EDM (especially benefits, risk, resource, and stakeholder reporting under EDM02, EDM03, EDM04, and EDM05).
- Management monitoring = MEA.
Altitude, owner, and title verb decide. A performance dashboard the CIO uses to run the function is MEA. A benefits-and-risk pack the board uses to evaluate and redirect is EDM. An internal-control assessment led by management or an assurance function is MEA. Calling MEA “the governance domain because it says Evaluate” is a Foundation miss.
Counts reinforce the split. MEA has 4 objectives, not 5. EDM has 5. Do not swap the counts because both names contain Evaluate and Monitor. Do not invent a story that MEA replaced EDM in 2019. Both domains exist. They sit on different sides of the governance/management line.
A Harborline tell: after the failed vendor go-live, the CIO launches a weekly operational scorecard (MEA) and tells the chair, “Governance is restored — we are monitoring now.” Monitoring work is necessary and still management. Governance is restored only when the board is again evaluating options, directing appetite and benefits, and monitoring value, risk, resources, and stakeholders — EDM, titled Ensured, not MEA titled Managed.
Exam traps for the split
- Calling MEA a governance domain because the official name is Monitor, Evaluate and Assess.
- Treating EDM03 Ensured Risk Optimization, APO12 Managed Risk, and DSS05 Managed Security Services as three labels for one process.
- Using the word monitor as proof of EDM when the stem is operational (DSS) or management assurance (MEA).
- “Fixing” official titles: Ensured Risk Management, Managed Governance Framework, Ensured Security Services.
- Saying management sets appetite, or that the board should approve every patch.
- Counting 37, or calling EDM a management domain, or calling all 40 objectives “processes.”
Prefer the answer that keeps Ensured + EDM as governance, keeps Managed + APO/BAI/DSS/MEA as management, separates EDM03 / APO12 / DSS05 by layer, and leaves MEA in the management column. Role title is a hint. The verb and the official title are the proof.
How do EDM03 Ensured Risk Optimization, APO12 Managed Risk, and DSS05 Managed Security Services differ?
Why is MEA Monitor, Evaluate and Assess not a governance domain?