What to Study for the ISACA CISA Exam

The Certified Information Systems Auditor (CISA®) certification validates expertise in auditing, controlling, monitoring, and assessing information systems and related technology.

ISACA’s current CISA Exam Content Outline, effective August 2024, covers five job-practice domains. Questions test both technical knowledge and the ability to apply audit judgment to realistic business situations.

The current domain weights differ significantly from earlier versions of the exam. Information Systems Operations and Business Resilience and Protection of Information Assets are now the two largest domains, each accounting for 26% of the exam.

CISA Exam and Certification Requirements

Anyone interested in information systems audit may take the CISA exam. You do not have to meet the work-experience requirement before testing.

To earn the CISA certification, you must:

  • Pass the CISA exam.
  • Have at least five years of qualifying professional information systems auditing, control, or security experience.
  • Apply for certification within five years of passing the exam.
  • Adhere to ISACA’s Code of Professional Ethics.
  • Comply with ISACA’s Information Systems Auditing Standards.
  • Meet continuing professional education requirements after certification.

Qualifying experience must be obtained within the 10 years preceding the application for certification. ISACA may permit certain substitutions or waivers under its current certification rules. Review the official CISA certification requirements for details.

CISA Exam Format

  • Number of questions: 150
  • Testing time: Four hours
  • Score range: 200 to 800
  • Passing score: 450

A score of 450 represents ISACA’s minimum standard of knowledge. It does not mean that a candidate answered exactly 45% of the questions correctly.

What Is on the CISA Exam?

Domain Exam Weight
Information Systems Auditing Process 18%
Governance and Management of IT 18%
Information Systems Acquisition, Development, and Implementation 12%
Information Systems Operations and Business Resilience 26%
Protection of Information Assets 26%

Domain 1: Information Systems Auditing Process

Exam weight: 18%

This domain covers planning, conducting, documenting, and following up on information systems audits.

Audit Planning

Review:

  • IS audit standards, guidelines, and codes of ethics
  • Types of audits, assessments, and reviews
  • Risk-based audit planning
  • Audit objectives and scope
  • Materiality and audit risk
  • Preventive, detective, and corrective controls
  • Manual, automated, and compensating controls

A risk-based audit should prioritize areas with the greatest potential impact and likelihood rather than give every process equal attention.

Audit Execution

Study:

  • Audit project management
  • Testing and sampling methods
  • Evidence collection
  • Data analytics
  • Reporting and communication
  • Audit quality assurance and improvement

Audit evidence should be sufficient, reliable, relevant, and useful. When evidence conflicts or appears incomplete, the auditor should obtain additional support before reaching a conclusion.

Reporting and Follow-Up

Audit findings should clearly describe the condition, applicable criteria, cause, effect or risk, and recommendation. Management owns the decision to accept or treat risk. The auditor evaluates the response, communicates residual risk, and follows up to determine whether agreed actions were completed.

Domain 2: Governance and Management of IT

Exam weight: 18%

This domain measures whether IT structures, resources, policies, and performance support the organization’s strategies and objectives.

IT Governance

Review:

  • Laws, regulations, and industry standards
  • Organizational structure
  • IT governance and IT strategy
  • Policies, standards, procedures, and practices
  • Enterprise architecture
  • Enterprise risk management
  • Privacy programs
  • Data governance and classification

Understand how the board, senior management, IT leadership, data owners, control owners, risk owners, and auditors differ in authority and accountability.

IT Management

Study IT resource management, vendor management, performance reporting, quality assurance, and quality management.

Be able to evaluate:

  • Whether IT investments support business objectives
  • Whether roles and responsibilities are defined appropriately
  • Whether incompatible duties are separated
  • Whether vendors meet contractual and control requirements
  • Whether KPIs and KRIs provide useful information
  • Whether IT risk ownership is clearly assigned

Domain 3: Information Systems Acquisition, Development, and Implementation

Exam weight: 12%

This domain covers the controls used throughout the systems lifecycle, from proposal through acquisition, development, testing, implementation, and review.

Acquisition and Development

Review:

  • Project governance and project management
  • Business cases and feasibility studies
  • Benefits realization
  • System development methodologies
  • Requirements management
  • Control identification and design
  • Vendor selection and contracts
  • Supply-chain risk

Controls should be considered during requirements and design, not added only after development is complete.

Implementation

Study:

  • System readiness and implementation testing
  • Configuration and release management
  • Infrastructure deployment
  • Data conversion and migration
  • Acceptance criteria
  • Fallback and rollback planning
  • Post-implementation review

Before implementation, auditors should evaluate whether testing is complete, defects are appropriately addressed, data conversion is reconciled, access is authorized, users are prepared, and contingency plans are in place.

Domain 4: Information Systems Operations and Business Resilience

Exam weight: 26%

This is one of the two largest CISA domains. It covers daily IT operations and the organization’s ability to continue or recover critical services.

Information Systems Operations

Review:

  • IT infrastructure and components
  • IT asset life cycle management
  • Job scheduling and production automation
  • System interfaces
  • Shadow IT and end-user computing
  • Availability and capacity management
  • Problem and incident management
  • Change, configuration, release, and patch management
  • Operational log management
  • Service-level management
  • Database management

Focus on whether processes are authorized, documented, tested, monitored, and aligned with organizational objectives.

Business Resilience

Study:

  • Business impact analysis
  • Recovery time objectives
  • Recovery point objectives
  • System and operational resilience
  • Backup, storage, and restoration
  • Business continuity planning
  • Disaster recovery planning
  • Plan testing and maintenance

The business impact analysis identifies critical processes, dependencies, impacts, and recovery priorities. Technology recovery strategies should follow business requirements rather than determine them.

Domain 5: Protection of Information Assets

Exam weight: 26%

This domain covers information security controls and the management of security events.

Information Asset Security and Control

Review:

  • Security frameworks, standards, and guidelines
  • Physical and environmental controls
  • Identity and access management
  • Network and endpoint security
  • Data loss prevention
  • Encryption
  • Public key infrastructure
  • Cloud and virtualized environments
  • Mobile, wireless, and Internet of Things devices

Understand confidentiality, integrity, and availability and how different administrative, technical, and physical controls support those objectives.

Security Event Management

Study:

  • Security awareness programs
  • Attack methods and techniques
  • Vulnerability and security testing
  • Security monitoring
  • Incident response
  • Evidence collection
  • Digital forensics

When evaluating an incident, the auditor should consider whether the organization preserved evidence, followed approved procedures, assigned responsibilities, communicated appropriately, restored operations, and applied lessons learned.

How to Study for the CISA Exam

Think Like an Auditor

The CISA exam generally asks you to evaluate controls and recommend improvements, not personally administer systems. Ask:

  • What is the greatest risk?
  • Is the evidence sufficient and reliable?
  • Who owns the process, asset, control, or risk?
  • Which control best addresses the root cause?
  • Does the auditor have enough information to reach a conclusion?
  • What should the auditor do before reporting the finding?
  • Which action preserves auditor independence?

Prioritize the Largest Domains

Information Systems Operations and Business Resilience and Protection of Information Assets account for 52% of the exam. Give these domains substantial study time while still reviewing the complete outline.

Compare Similar Audit Concepts

Practice distinguishing:

  • Governance versus management
  • Risk owner versus control owner
  • Preventive versus detective controls
  • Compliance testing versus substantive testing
  • Incidents versus problems
  • Business continuity versus disaster recovery
  • RTO versus RPO
  • Auditor recommendations versus management decisions

Start Preparing for the CISA Exam

Pocket Prep’s CISA practice questions help you review all five domains and apply information systems audit concepts to realistic scenarios. Each question includes a detailed explanation so you can understand why each answer is correct or incorrect.