Skip to content

CISA - Certified Information Systems Auditor

Exam Overview

The Certified Information Systems Auditor (CISA) is ISACA's flagship audit credential and the global gold standard for professionals who audit, control, monitor, and assess an organization's information technology and business systems. CISA has been issued since 1978 and is widely required for IT audit, IS assurance, and IT compliance roles across Big 4 firms, internal audit functions, financial services, healthcare, regulated industries, and government.

CISA is accredited under ANSI/ISO/IEC Standard 17024 and is approved for US Department of Defense roles under directive 8140 (formerly 8570) in the IAT Level III, IAM Level I, and CSSP Auditor categories. It is regularly listed as the preferred or required certification for IT auditor, IS audit manager, IT compliance manager, and SOX/NIST/ISO assurance roles.

Exam Details: - Exam Code: CISA - Format: Linear, fixed-form, computer-based - Duration: 4 hours (240 minutes) - Number of Questions: 150 multiple-choice - Question Types: Multiple choice (4 options, single best answer) - Passing Score: 450 out of 800 (scaled) - Cost: $575 USD ISACA member / $760 USD non-member - Languages: English, Chinese (Simplified), French, German, Hebrew, Italian, Japanese, Korean, Spanish, Turkish - Delivery: PSI test centers worldwide OR online-proctored (remote, with strict environment requirements) - Validity: 3-year CPE cycle (120 CPEs, 20 min/year) - Prerequisites: 5 years of professional IS audit, control, or security work experience. Substitutions available (see Eligibility section).

Five CISA Domains (Current Job Practice)

Domain 1: Information System Auditing Process (21%)

  • IS audit standards, guidelines, and codes of ethics (ITAF)
  • Business processes, types of controls
  • Risk-based audit planning
  • Types of audits and assessments
  • Audit project management
  • Sampling methodology
  • Audit evidence collection techniques
  • Data analytics
  • Reporting and communication techniques
  • Quality assurance and improvement of the audit process

Domain 2: Governance and Management of IT (17%)

  • IT governance and IT strategy
  • IT-related frameworks (COBIT 2019, ITIL, ISO/IEC 38500)
  • IT standards, policies, and procedures
  • Organizational structure
  • Enterprise architecture
  • Enterprise risk management
  • Maturity models
  • Laws, regulations, and industry standards affecting the organization
  • IT resource management
  • IT service provider acquisition and management
  • IT performance monitoring and reporting
  • Quality assurance and quality management of IT

Domain 3: Information Systems Acquisition, Development, and Implementation (12%)

  • Project governance and management
  • Business case and feasibility analysis
  • System development methodologies (Waterfall, Agile, DevOps, Iterative, Spiral)
  • Control identification and design
  • Testing methodologies (unit, integration, system, UAT, regression, performance, security)
  • Configuration and release management
  • System migration, infrastructure deployment, and data conversion
  • Post-implementation review

Domain 4: Information Systems Operations and Business Resilience (23%)

  • Common technology components
  • IT asset management
  • Job scheduling and production process automation
  • System interfaces
  • End-user computing and shadow IT
  • Data governance
  • Systems performance management
  • Problem and incident management
  • Change, configuration, release, and patch management
  • IT service level management
  • Database management
  • Business impact analysis (BIA)
  • System resiliency
  • Data backup, storage, and restoration
  • Business continuity plan (BCP)
  • Disaster recovery plan (DRP)

Domain 5: Protection of Information Assets (27%)

  • Information asset security frameworks, standards, and guidelines
  • Privacy principles
  • Physical access and environmental controls
  • Identity and access management
  • Network and end-point security
  • Data classification
  • Data encryption and encryption-related techniques
  • Public key infrastructure (PKI)
  • Web-based communication techniques
  • Virtualized environments
  • Mobile, wireless, and Internet-of-Things (IoT) devices
  • Security awareness training and programs
  • Information system attack methods and techniques
  • Security testing tools and techniques
  • Security monitoring tools and techniques
  • Incident response management
  • Evidence collection and forensics

Study Materials

Notes

Study Resources

  • Fact Sheet - Quick reference (frameworks, formulas, audit terminology)
  • Practice Plan - 14-week study schedule
  • Scenarios - Realistic CISA-style audit scenarios and finding-writing
  • Strategy - "BEST answer wins" tactics for ISACA-style questions

Audience and Career Profile

CISA is targeted at IT audit and assurance professionals, typically with 5+ years of experience auditing or controlling information systems. Common roles:

  • IT Auditor / Senior IT Auditor / IT Audit Manager
  • IS Audit Director / VP Internal Audit (IT)
  • External IT Auditor (Big 4: Deloitte, PwC, EY, KPMG)
  • IT Compliance Manager (SOX, HIPAA, PCI DSS, FedRAMP)
  • IT Risk Manager
  • Cybersecurity Auditor
  • Privacy Auditor
  • Information Security Officer (audit-aligned)
  • IT Governance Specialist
  • SOX 404 IT General Controls (ITGC) Tester

Eligibility and Experience Substitutions

The standard requirement is 5 years of professional information systems auditing, control, or security work experience. The following substitutions can waive a maximum of 3 years:

Substitution Years Waived
1 year of information systems experience OR 1 year of non-IS auditing experience 1 year
60-120 college semester credit hours (associate's / bachelor's degree) 1-2 years
Master's degree from an ISACA-accredited university 1 year
2 years as a full-time university instructor in a related field 1 year

You may sit for the exam before meeting the experience requirement. After passing, you have 5 years from the exam date to submit the certification application and verify experience. Without verified experience, the passing score does not result in CISA certification.

Official Resources

  • CISA Certification Page: https://www.isaca.org/credentialing/cisa
  • CISA Exam Content Outline: https://www.isaca.org/credentialing/cisa/cisa-exam-content-outline
  • ITAF (Information Technology Audit Framework): https://www.isaca.org/resources/itaf
  • CISA Review Manual (CRM), 28th Edition (current): ISACA bookstore (the primary text)
  • CISA Questions, Answers and Explanations (QAE) Database: ISACA online study tool
  • Self-paced training: ISACA Online Review Course
  • Instructor-led training: ISACA chapter offerings or training partners (Hemang Doshi, Phil Martin, Cybrary)

Books

  1. CISA Review Manual, 28th Edition by ISACA - the gold standard, follows exam content outline exactly
  2. CISA Review Questions, Answers and Explanations Manual, 13th Edition by ISACA - 1,000+ practice questions
  3. CISA Certified Information Systems Auditor Study Guide, 5th Edition by Hemang Doshi (Wiley) - widely praised for clarity
  4. Wiley CISAsecure by David Cannon - alternative text with strong governance coverage
  5. All-in-One CISA Certified Information Systems Auditor Exam Guide by Peter Gregory (McGraw-Hill)

Video Courses

  1. Hemang Doshi CISA Video Course (Udemy) - widely considered the best video resource for CISA
  2. Phil Martin CISA (Udemy) - structured by domain, strong on audit terminology
  3. Cybrary CISA - free option
  4. ISACA Online Review Course - official, expensive but thorough
  5. Inside Cloud and Security CISA playlist (free on YouTube)

Practice Tests

  1. ISACA QAE Database - 1,000+ official questions; the closest representation of exam style
  2. Hemang Doshi practice tests (Udemy) - large supplementary bank
  3. Pocket Prep CISA - mobile-friendly question bank
  4. LearnZapp CISA Official ISACA app

Communities

  • r/cisa on Reddit (active, full of recently-passed wisdom)
  • ISACA Engage Community
  • TechExams CISA forum
  • Discord servers focused on CISA study groups
  • CISM (ISACA) - Sister certification focused on security management rather than audit. ~30% topic overlap with CISA.
  • CISSP (ISC2) - Broad security management. Significant overlap in domains 2-5.
  • CCSP (ISC2) - Cloud security; complements CISA for cloud-heavy audit engagements.
  • AWS Certified Security - Specialty - Cloud-specific technical depth that complements CISA's framework focus.
  • CRISC (ISACA) - Risk management; natural progression after CISA.
  • CGEIT (ISACA) - IT governance; for senior CISA holders moving into governance roles.
  • CIA (IIA) - Internal audit generalist; pairs with CISA for hybrid audit careers.

After You Pass

  • Submit certification application within 5 years of the exam date
  • Provide verification of work experience (signed by supervisor or independent verifier)
  • Pay first Annual Maintenance Fee ($45 member / $85 non-member)
  • Begin earning 120 CPE credits over 3-year cycle (minimum 20 CPE per year)
  • Adhere to ISACA Code of Professional Ethics

Mindset Tip

The CISA exam tests the mindset of an independent IS auditor, not a security implementer. When choosing between answers, ask:

  1. Which option provides the most reliable and independent assurance?
  2. Which option is the auditor's response (not the auditee's response)?
  3. Which option aligns with audit standards (ITAF, IIA Standards)?
  4. Which option preserves auditor independence and objectivity?
  5. Which option is the BEST, not merely correct, answer?

ISACA writes questions where 2-3 options are technically correct and only one is BEST in the context of an independent audit. This perspective is the single biggest determinant of exam success.