What to Study for the ISACA CISA Exam
The Certified Information Systems Auditor (CISA®) certification validates expertise in auditing, controlling, monitoring, and assessing information systems and related technology.
ISACA’s current CISA Exam Content Outline, effective August 2024, covers five job-practice domains. Questions test both technical knowledge and the ability to apply audit judgment to realistic business situations.
The current domain weights differ significantly from earlier versions of the exam. Information Systems Operations and Business Resilience and Protection of Information Assets are now the two largest domains, each accounting for 26% of the exam.
CISA Exam and Certification Requirements
Anyone interested in information systems audit may take the CISA exam. You do not have to meet the work-experience requirement before testing.
To earn the CISA certification, you must:
- Pass the CISA exam.
- Have at least five years of qualifying professional information systems auditing, control, or security experience.
- Apply for certification within five years of passing the exam.
- Adhere to ISACA’s Code of Professional Ethics.
- Comply with ISACA’s Information Systems Auditing Standards.
- Meet continuing professional education requirements after certification.
Qualifying experience must be obtained within the 10 years preceding the application for certification. ISACA may permit certain substitutions or waivers under its current certification rules. Review the official CISA certification requirements for details.
CISA Exam Format
- Number of questions: 150
- Testing time: Four hours
- Score range: 200 to 800
- Passing score: 450
A score of 450 represents ISACA’s minimum standard of knowledge. It does not mean that a candidate answered exactly 45% of the questions correctly.
What Is on the CISA Exam?
| Domain | Exam Weight |
|---|---|
| Information Systems Auditing Process | 18% |
| Governance and Management of IT | 18% |
| Information Systems Acquisition, Development, and Implementation | 12% |
| Information Systems Operations and Business Resilience | 26% |
| Protection of Information Assets | 26% |
Domain 1: Information Systems Auditing Process
Exam weight: 18%
This domain covers planning, conducting, documenting, and following up on information systems audits.
Audit Planning
Review:
- IS audit standards, guidelines, and codes of ethics
- Types of audits, assessments, and reviews
- Risk-based audit planning
- Audit objectives and scope
- Materiality and audit risk
- Preventive, detective, and corrective controls
- Manual, automated, and compensating controls
A risk-based audit should prioritize areas with the greatest potential impact and likelihood rather than give every process equal attention.
Audit Execution
Study:
- Audit project management
- Testing and sampling methods
- Evidence collection
- Data analytics
- Reporting and communication
- Audit quality assurance and improvement
Audit evidence should be sufficient, reliable, relevant, and useful. When evidence conflicts or appears incomplete, the auditor should obtain additional support before reaching a conclusion.
Reporting and Follow-Up
Audit findings should clearly describe the condition, applicable criteria, cause, effect or risk, and recommendation. Management owns the decision to accept or treat risk. The auditor evaluates the response, communicates residual risk, and follows up to determine whether agreed actions were completed.
Domain 2: Governance and Management of IT
Exam weight: 18%
This domain measures whether IT structures, resources, policies, and performance support the organization’s strategies and objectives.
IT Governance
Review:
- Laws, regulations, and industry standards
- Organizational structure
- IT governance and IT strategy
- Policies, standards, procedures, and practices
- Enterprise architecture
- Enterprise risk management
- Privacy programs
- Data governance and classification
Understand how the board, senior management, IT leadership, data owners, control owners, risk owners, and auditors differ in authority and accountability.
IT Management
Study IT resource management, vendor management, performance reporting, quality assurance, and quality management.
Be able to evaluate:
- Whether IT investments support business objectives
- Whether roles and responsibilities are defined appropriately
- Whether incompatible duties are separated
- Whether vendors meet contractual and control requirements
- Whether KPIs and KRIs provide useful information
- Whether IT risk ownership is clearly assigned
Domain 3: Information Systems Acquisition, Development, and Implementation
Exam weight: 12%
This domain covers the controls used throughout the systems lifecycle, from proposal through acquisition, development, testing, implementation, and review.
Acquisition and Development
Review:
- Project governance and project management
- Business cases and feasibility studies
- Benefits realization
- System development methodologies
- Requirements management
- Control identification and design
- Vendor selection and contracts
- Supply-chain risk
Controls should be considered during requirements and design, not added only after development is complete.
Implementation
Study:
- System readiness and implementation testing
- Configuration and release management
- Infrastructure deployment
- Data conversion and migration
- Acceptance criteria
- Fallback and rollback planning
- Post-implementation review
Before implementation, auditors should evaluate whether testing is complete, defects are appropriately addressed, data conversion is reconciled, access is authorized, users are prepared, and contingency plans are in place.
Domain 4: Information Systems Operations and Business Resilience
Exam weight: 26%
This is one of the two largest CISA domains. It covers daily IT operations and the organization’s ability to continue or recover critical services.
Information Systems Operations
Review:
- IT infrastructure and components
- IT asset life cycle management
- Job scheduling and production automation
- System interfaces
- Shadow IT and end-user computing
- Availability and capacity management
- Problem and incident management
- Change, configuration, release, and patch management
- Operational log management
- Service-level management
- Database management
Focus on whether processes are authorized, documented, tested, monitored, and aligned with organizational objectives.
Business Resilience
Study:
- Business impact analysis
- Recovery time objectives
- Recovery point objectives
- System and operational resilience
- Backup, storage, and restoration
- Business continuity planning
- Disaster recovery planning
- Plan testing and maintenance
The business impact analysis identifies critical processes, dependencies, impacts, and recovery priorities. Technology recovery strategies should follow business requirements rather than determine them.
Domain 5: Protection of Information Assets
Exam weight: 26%
This domain covers information security controls and the management of security events.
Information Asset Security and Control
Review:
- Security frameworks, standards, and guidelines
- Physical and environmental controls
- Identity and access management
- Network and endpoint security
- Data loss prevention
- Encryption
- Public key infrastructure
- Cloud and virtualized environments
- Mobile, wireless, and Internet of Things devices
Understand confidentiality, integrity, and availability and how different administrative, technical, and physical controls support those objectives.
Security Event Management
Study:
- Security awareness programs
- Attack methods and techniques
- Vulnerability and security testing
- Security monitoring
- Incident response
- Evidence collection
- Digital forensics
When evaluating an incident, the auditor should consider whether the organization preserved evidence, followed approved procedures, assigned responsibilities, communicated appropriately, restored operations, and applied lessons learned.
How to Study for the CISA Exam
Think Like an Auditor
The CISA exam generally asks you to evaluate controls and recommend improvements, not personally administer systems. Ask:
- What is the greatest risk?
- Is the evidence sufficient and reliable?
- Who owns the process, asset, control, or risk?
- Which control best addresses the root cause?
- Does the auditor have enough information to reach a conclusion?
- What should the auditor do before reporting the finding?
- Which action preserves auditor independence?
Prioritize the Largest Domains
Information Systems Operations and Business Resilience and Protection of Information Assets account for 52% of the exam. Give these domains substantial study time while still reviewing the complete outline.
Compare Similar Audit Concepts
Practice distinguishing:
- Governance versus management
- Risk owner versus control owner
- Preventive versus detective controls
- Compliance testing versus substantive testing
- Incidents versus problems
- Business continuity versus disaster recovery
- RTO versus RPO
- Auditor recommendations versus management decisions
Start Preparing for the CISA Exam
Pocket Prep’s CISA practice questions help you review all five domains and apply information systems audit concepts to realistic scenarios. Each question includes a detailed explanation so you can understand why each answer is correct or incorrect.