Enterprise Architecture
In the context of ISACA's Certified in the Governance of Enterprise IT (CGEIT) credential and the broader discipline of Governance of Enterprise IT (GEIT), Enterprise Architecture (EA) is a structured approach for describing and aligning an organization's business processes, information, applicatio… In the context of ISACA's Certified in the Governance of Enterprise IT (CGEIT) credential and the broader discipline of Governance of Enterprise IT (GEIT), Enterprise Architecture (EA) is a structured approach for describing and aligning an organization's business processes, information, applications, and technology infrastructure with its strategic goals. EA acts as a blueprint that shows both the current state (baseline architecture) and the desired future state (target architecture) of the enterprise, along with a roadmap for moving between them. From a governance perspective, EA is a key enabler of strategic alignment, one of the core objectives of GEIT. It ensures that IT investments support business priorities rather than evolving in isolated, inconsistent ways. Boards and executive management rely on EA to evaluate whether proposed initiatives fit the enterprise's direction, avoid duplication, and use resources efficiently. In COBIT, EA is addressed mainly through the management objective APO03 Managed Enterprise Architecture, which covers developing an architecture vision, defining reference architectures across business, information, data, application, and technology domains, selecting opportunities and solutions, defining implementation plans, and providing architecture services. Common frameworks used alongside COBIT include TOGAF, with its Architecture Development Method, and the Zachman Framework, which classifies architectural artifacts. For CGEIT candidates, EA connects to several domains. In Governance of Enterprise IT, it supports a governance framework by setting principles and standards. In IT Resources, it guides optimal use of applications, infrastructure, information, and people. In Benefits Realization, it helps prioritize portfolios and investments that deliver value. In Risk Optimization, it reduces complexity, technical debt, and security exposure by enforcing standardization. Effective EA governance typically involves an architecture board, clear principles, compliance reviews, and metrics. Ultimately, EA translates business strategy into actionable IT decisions, enabling agility, interoperability, cost efficiency, and informed decision-making, ensuring that enterprise IT consistently creates value while managing risk and resources responsibly.
Enterprise Architecture in CGEIT: Governance of Enterprise IT - A Complete Guide
Introduction
Enterprise Architecture (EA) is a core topic within Domain 1 of the ISACA CGEIT certification: Governance of Enterprise IT. CGEIT tests your ability to think like a governance professional, someone who makes sure IT creates value, manages risk and uses resources well, in line with what stakeholders expect. Enterprise Architecture is one of the most important tools for reaching those goals. This guide explains why EA matters, what it is, how it works in a governance setting, and how to answer CGEIT exam questions about it.
Why Enterprise Architecture Is Important
Without a clear architectural view, organizations tend to build IT in a fragmented, reactive way. Business units buy their own systems, data is duplicated, integration becomes expensive, and technology investments drift away from strategy. EA addresses these problems by giving the organization one coherent blueprint. Its importance comes from several points:
1. Strategic alignment: EA turns business strategy into a structured target state for business processes, information, applications and technology. This makes sure IT investments directly support enterprise objectives.
2. Value delivery: EA reduces redundancy and promotes reuse and standardization. It helps the enterprise get the most benefit from IT-enabled investments and avoid waste.
3. Risk optimization: A well-defined architecture reduces complexity, highlights dependencies and single points of failure, and builds security and compliance requirements into the design from the start.
4. Resource optimization: EA guides the efficient use of people, information, applications and infrastructure. It identifies where to consolidate, retire or invest.
5. Agility and change enablement: A clear current-state and target-state view helps the enterprise respond faster to market changes, mergers, acquisitions and new technologies.
6. Better decision-making: EA gives the board, executives and IT steering committees a shared, holistic view. Investment and portfolio decisions can then be based on facts, not intuition.
7. Communication: EA creates a common language between business and IT, which reduces misunderstanding and builds trust.
What Enterprise Architecture Is
Enterprise Architecture is a holistic, structured description of an enterprise's components and their relationships. It covers business processes, information and data, applications and technology. It also sets the principles and guidelines that govern how those components are designed and how they evolve over time.
EA is usually organized into four architecture domains:
1. Business Architecture: Defines business strategy, governance, organization structure, capabilities and key business processes.
2. Data / Information Architecture: Describes the structure of logical and physical data assets and the resources that manage them.
3. Application Architecture: Provides a blueprint for individual applications, how they interact, and how they relate to core business processes.
4. Technology (Infrastructure) Architecture: Describes the hardware, software, networks and platforms needed to support business, data and application services.
Key elements of EA include:
- Baseline (As-Is / Current State) Architecture: How the enterprise operates today.
- Target (To-Be / Future State) Architecture: How the enterprise should look to support strategy.
- Gap Analysis: The differences between the current and target states.
- Roadmap / Transition Architectures: A sequenced plan of projects and programs that moves the enterprise from current to target state.
- Architecture Principles: High-level rules that guide decisions, for example: reuse before buy before build, data is an asset, security by design.
- Standards and Reference Models: Approved technologies, patterns and models.
- Architecture Repository: A central store for architecture artifacts, models and decisions.
Common EA Frameworks
CGEIT does not require deep technical knowledge of any single framework. You should still recognize the common ones:
- TOGAF (The Open Group Architecture Framework): Uses the Architecture Development Method (ADM), an iterative cycle covering preliminary work, architecture vision, business, information systems and technology architectures, opportunities and solutions, migration planning, implementation governance and architecture change management. Requirements management sits at the center of the cycle.
- Zachman Framework: A classification matrix or ontology. It crosses perspectives (planner, owner, designer, builder, subcontractor, user) with interrogatives (what, how, where, who, when, why).
- FEAF (Federal Enterprise Architecture Framework): Used by US government agencies.
- COBIT: Not an EA framework itself, but it includes the practice APO03 Managed Enterprise Architecture (named Manage Enterprise Architecture in COBIT 5). This links EA directly to governance and management objectives. The governance practice EDM01 Ensured Governance Framework Setting and Maintenance provides the overall direction within which EA operates.
How Enterprise Architecture Works in a Governance Context
From a CGEIT perspective, the key idea is that EA is a governance enabler. It is not just a technical design activity. Here is how it works in practice:
Step 1: Establish the EA governance structure.
The board and executive management set the direction. An Architecture Board or Architecture Review Board (ARB) is usually created, often reporting to the IT Steering Committee or IT Strategy Committee. It oversees architecture decisions, approves standards, grants exceptions (dispensations) and ensures compliance.
Step 2: Define the architecture vision and principles.
The vision comes from enterprise strategy and stakeholder needs. Architecture principles are agreed and communicated so that every later decision is consistent.
Step 3: Document the baseline architecture.
The current business processes, information flows, applications and technology are captured. This creates a fact base for evaluating options.
Step 4: Define the target architecture.
The desired future state is designed to support strategic objectives, including requirements for risk, security, compliance and performance.
Step 5: Perform gap analysis and build the roadmap.
Gaps are identified and turned into initiatives. These initiatives feed the IT investment portfolio and are prioritized based on value, risk and resource constraints.
Step 6: Integrate with portfolio, program and project management.
New investments are reviewed for architectural compliance before approval. EA becomes an input to business cases and portfolio decisions.
Step 7: Monitor compliance and manage change.
Architecture compliance reviews check that projects follow standards. Exceptions are formally managed. The architecture is updated as strategy, technology and the environment change.
Step 8: Measure EA effectiveness.
Useful metrics include:
- Percentage of projects that comply with architecture
- Reduction in redundant applications
- Cost savings from standardization
- Time to deliver new capabilities
- Stakeholder satisfaction
Key Roles
- Board / Executive Management: Accountable for direction and for making sure EA supports strategy.
- CIO: Responsible for implementing EA and aligning it with IT strategy.
- Chief Architect / EA Team: Develops and maintains the architecture.
- Architecture Review Board: Approves standards, reviews compliance and handles exceptions.
- Business Process Owners: Make sure business architecture reflects real needs.
Relationship Between EA and Other CGEIT Concepts
- IT Strategy: EA is the bridge between strategy and execution.
- Benefits Realization (Domain 3): EA keeps investments coherent and value-focused.
- Risk Optimization (Domain 4): EA reduces architectural risk and embeds controls.
- Resource Optimization: EA guides how infrastructure, applications and information are used.
- Governance Framework: EA is one of the enablers that put governance into practice. In COBIT 2019 terms, this falls under the components of a governance system, such as processes, information, and services, infrastructure and applications.
Exam Tips: Answering Questions on Enterprise Architecture
1. Think governance, not technology. CGEIT is a governance exam. When a question asks about EA, the best answer usually focuses on alignment with business strategy, value delivery or stakeholder needs. Avoid answers built around technical details or specific products.
2. The primary purpose of EA is alignment. If asked about the MAIN benefit or objective of EA, the answer typically relates to aligning IT with business strategy or providing a holistic view that enables informed decisions. Cost reduction and standardization are benefits, but they are usually secondary.
3. Business drives architecture. EA should start from business strategy and requirements, not from technology. If an option suggests designing the technology architecture first, it is usually wrong.
4. Current state before target state, then gap analysis. Know the logical sequence: understand strategy and vision, document the baseline, define the target, analyze gaps, then build the roadmap. Questions often test this order.
5. Look for the FIRST or BEST step. When asked what to do FIRST in an EA initiative, favor:
- Obtaining executive or board sponsorship
- Understanding business strategy and objectives
- Defining architecture principles
Avoid jumping straight to tool selection or implementation.
6. EA must have governance oversight. Answers that mention an Architecture Review Board, compliance reviews or formal exception management are often correct when the question deals with ensuring adherence to architecture.
7. Link EA to portfolio management. The best approach usually ensures that new IT investments are evaluated against the target architecture before approval. EA is an input to investment decisions.
8. Watch for scenario questions about fragmentation. If a scenario describes duplicate systems, integration problems, inconsistent data or business units acting independently, the root cause is often the lack of an enterprise architecture or weak EA governance. The best remedy is usually to establish or enforce EA.
9. EA is a living artifact. Choose answers that show EA being maintained, reviewed and updated as strategy and technology change. Answers that treat it as a one-time project are usually wrong.
10. Accountability versus responsibility. The board or executive management is accountable for making sure governance mechanisms such as EA exist. The CIO and EA team are responsible for developing and maintaining it. Read carefully for the word accountable versus responsible.
11. Exceptions should be managed, not ignored. If a project deviates from standards, the right action is usually to go through the formal exception or dispensation process, which includes risk assessment and approval. Rejecting the project outright or allowing silent non-compliance are usually wrong.
12. Recognize frameworks at a high level. Know that TOGAF uses the ADM, that Zachman is a classification matrix, and that COBIT includes Managed Enterprise Architecture (APO03). Do not overthink framework-specific details.
13. Eliminate extreme or narrow options. Options that say always, only, or focus on a single department are often distractors. EA is enterprise-wide and holistic.
14. Value over compliance for its own sake. When choosing between an answer that emphasizes conformance and one that emphasizes business value enabled by architecture, the value-focused answer is generally preferred. The exception is a question that is specifically about compliance.
Sample Question Walkthrough
Question: An organization has multiple business units, each acquiring its own applications, which leads to high integration costs and data inconsistencies. What should the IT governance committee do FIRST?
A. Mandate a single vendor for all applications
B. Establish an enterprise architecture aligned with business strategy
C. Centralize all IT budgets under the CIO
D. Implement a data warehouse to consolidate data
Analysis:
- Option A is a narrow technical fix.
- Option C changes the funding structure but does not address design coherence.
- Option D treats a symptom.
- Option B addresses the root cause with a governance-level, strategy-aligned solution. B is the best answer.
Summary
Enterprise Architecture is the blueprint that connects business strategy to IT execution. In CGEIT, view EA as a governance mechanism that:
- Ensures alignment
- Supports value delivery
- Optimizes risk and resources
- Informs investment decisions
Remember these points:
- Start from business strategy.
- Follow the sequence of baseline, target, gaps and roadmap.
- Ensure oversight through an architecture board.
- Integrate EA with portfolio management.
- Keep EA current.
When in doubt on the exam, choose the answer that is holistic, business-driven, governance-oriented and focused on long-term enterprise value.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!