CISA Practice Plan - 14 Week Schedule¶
CISA is a breadth-and-depth audit exam covering 5 domains. Most successful candidates spend 3 to 5 months preparing. This plan assumes 10 to 12 hours per week of focused study and is designed for someone with some audit, risk, or IT operations experience.
If you are an experienced internal or external IT auditor, you can compress this to 8 to 10 weeks. If you are new to audit (transitioning from security engineering, sysadmin, or development), plan 16 to 20 weeks.
A Note on Experience Requirement¶
CISA requires 5 years of professional information systems audit, control, or security work experience. You may sit for and pass the exam without meeting the requirement, but the certification will not be issued until you verify experience.
Common substitutions (max 3 years total): - 1 year of IS or non-IS audit experience -> waives 1 year - 60 college credit hours (associate's) -> waives 1 year - 120 college credit hours (bachelor's) -> waives 2 years - Master's degree in IS/IT from ISACA-accredited university -> waives 1 additional year - 2 years full-time university instructor in a related field -> waives 1 year
You have 5 years from the exam date to apply for certification with verified experience. Plan your career and education accordingly. If you are 1 to 2 years short of experience, sit for the exam now and accumulate experience while the score remains valid.
Materials Required¶
Before starting: - CISA Review Manual, 28th Edition (ISACA) - primary text; mirrors exam content outline - CISA Review Questions, Answers and Explanations Manual, 13th Edition (ISACA) - 1,000+ practice questions - Hemang Doshi CISA Video Course (Udemy) OR Phil Martin CISA (Udemy) - video course - ISACA QAE Database (online) - the closest match to actual exam style - Hemang Doshi: CISA Certified Information Systems Auditor Study Guide (Wiley, 5th Edition) - excellent supplementary text
Optional additions: - Pocket Prep CISA mobile app for spaced repetition - Prabh Nair CISA YouTube playlist (free) - audit-focused content - Anki deck for ISACA terminology and frameworks
Week-by-Week Plan¶
Week 1: Orientation, ITAF, and Audit Standards¶
Goals: Understand exam format, ISACA Code of Ethics, ITAF audit standards hierarchy, and types of audits.
Topics: - ISACA Code of Professional Ethics (memorize) - ITAF: Standards (mandatory), Guidelines (recommended), Tools and Techniques (optional) - Audit charter and audit committee reporting - Independence (in fact and in appearance) - Types of audits: financial, operational, integrated, compliance, IS, forensic, SOC ½/3
Activities: - Read CRM Domain 1 introduction and standards section - Watch Hemang Doshi Domain 1 first half - Take 50 practice questions on audit standards and ethics - Begin Anki deck with ITAF terminology
Deliverable: Written one-page summary of audit standards, audit charter, and independence in your own words.
Week 2: Domain 1 - Audit Process, Sampling, Evidence¶
Topics: - Audit lifecycle: planning, risk assessment, fieldwork, reporting, follow-up - Risk-based audit planning (audit universe, risk ranking) - Compliance vs substantive testing - Sampling: statistical vs non-statistical; attribute vs variable; stop-or-go, discovery - Audit evidence hierarchy (most reliable: re-performance, observation; least: oral) - Quality criteria: sufficient, reliable, relevant, useful - CAATs: generalized audit software, test data, parallel simulation, embedded modules - Audit documentation and workpapers
Activities: - Read CRM Domain 1 chapters 2-4 - Walk through a sample size calculation by hand (attribute sampling) - 75 practice questions on Domain 1 - Mini-exam: 50 Domain 1 questions
Deliverable: Audit lifecycle diagram with deliverables for each phase.
Week 3: Domain 1 Wrap-up + Begin Domain 2 (Governance Frameworks)¶
Topics (Domain 1 wrap): - Reporting: finding structure (5 C's), audit opinions - Follow-up audits and tracking remediation - Continuous auditing vs continuous monitoring - Quality assurance and improvement of the audit function
Topics (Domain 2 start): - IT governance vs IT management (COBIT 2019 separation) - COBIT 2019: 5 governance objectives (EDM), 35 management objectives (APO/BAI/DSS/MEA) - Six COBIT governance system principles - Seven enablers / components
Activities: - Memorize EDM01-05 names - Map a real-world IT process to a COBIT objective - 50 practice questions - Take Domain 1 full mini-exam
Week 4: Domain 2 - Strategy, Architecture, Standards¶
Topics: - IT strategic planning and alignment with business strategy - Balanced scorecard for IT - Enterprise architecture frameworks: TOGAF (ADM), Zachman, FEAF - IT steering committee, IT strategy committee - Policies, standards, procedures, guidelines hierarchy - Service-level agreements (SLAs), OLAs, UCs - Vendor management, third-party risk - ISO/IEC 38500 corporate governance of IT - IT portfolio management
Activities: - Read CRM Domain 2 chapters 1-3 - 75 practice questions on Domain 2
Week 5: Domain 2 Wrap-up + Domain 3 (SDLC and Project Management)¶
Topics (Domain 2 wrap): - Enterprise risk management (COSO ERM) - Maturity models: CMMI 5 levels (Initial, Managed, Defined, Quantitatively Managed, Optimizing) - Performance measurement: KPIs, KRIs, KGIs - Quality management (TQM, Six Sigma, ISO 9001)
Topics (Domain 3 start): - Project governance and project management lifecycle - PMBOK process groups: Initiating, Planning, Executing, Monitoring/Controlling, Closing - PRINCE2 stages - Business case, feasibility study, NPV, IRR, payback period - SDLC models: Waterfall, Iterative, Spiral, Agile (Scrum/Kanban/SAFe), DevOps, RAD, JAD
Activities: - 75 practice questions - Build CMMI mnemonic ("I Make Definitions Quite Often")
Week 6: Domain 3 - SDLC Phases, Testing, Implementation¶
Topics: - Feasibility -> Requirements -> Design -> Develop -> Test -> Implement -> Post-implementation review - Requirements: functional vs non-functional; FURPS+ - Design: logical vs physical; DFDs, ERDs, UML - Testing types: unit, integration, system, UAT, regression, performance, recovery, security, parallel, pilot - Black/white/gray box testing - Cutover strategies: direct, parallel, phased, pilot - Configuration management and version control - Code review (peer review, pair programming, walk-throughs, inspections) - Post-implementation review: was the business case realized? - Auditor's role in each SDLC phase
Activities: - Read CRM Domain 3 fully - Map auditor activities to SDLC phases - 100 practice questions on Domain 3
Week 7: Mid-Course Diagnostic + Domain 4 Part 1 (Operations)¶
Goals: Take a 100-question diagnostic. Address weak areas. Begin operations domain.
Topics: - IT operations: scheduling, monitoring, capacity, performance management - Help desk / service desk - Problem management vs incident management vs change management vs release management (ITIL alignment) - Configuration management database (CMDB) - Patch management lifecycle - IT asset management
Activities: - Take 100-question diagnostic across Domains 1-3 - Build remediation list for low-scoring topics - Read CRM Domain 4 chapters 1-2
Week 8: Domain 4 Part 2 (Resilience and BCP/DR)¶
Topics: - Business Impact Analysis (BIA): identify processes, calculate impact, prioritize - RTO, RPO, MTD/MTPD, WRT, MTTR, MTBF, SDO, MTO - Recovery sites: cold, warm, hot, mirrored, reciprocal, cloud (DRaaS) - Backup schemes: full, incremental, differential, mirror; GFS rotation - Replication: synchronous vs asynchronous - BCP vs DRP (BCP is broader: people, process, tech; DRP is IT-focused) - DR test types (least to most disruptive): read-through, walk-through, tabletop, simulation, parallel, full interruption - Crisis management and emergency response
Activities: - Build a comparison chart of recovery sites and test types - Walk through a BIA for a fictional company - 100 practice questions on Domain 4
Week 9: Domain 4 Wrap-up + Domain 5 Part 1 (IAM and Network Security)¶
Topics (Domain 4 wrap): - Database management (relational, NoSQL, normalization, ACID) - Data governance and data quality - End-user computing (EUC) and shadow IT controls - System interfaces
Topics (Domain 5 start): - Information security frameworks (ISO 27001/27002, NIST 800-53, NIST CSF) - Security policy, standards, procedures - IAM: identification, authentication, authorization, accounting (IAAA) - Authentication factors and types (knowledge, possession, biometric, behavior, location) - MFA, SSO, federation (SAML, OAuth, OIDC, Kerberos) - Access control models: DAC, MAC, RBAC, ABAC, RuBAC
Activities: - 75 practice questions
Week 10: Domain 5 Part 2 (Cryptography, Network Security, Physical)¶
Topics: - Symmetric vs asymmetric vs hashing - AES, RSA, ECC, DH, ECDSA, SHA-⅔, HMAC, bcrypt/Argon2 - PKI: CA, RA, CRL, OCSP, X.509, certificate types - Digital signatures, code signing - Network security: firewalls (stateful, NGFW, WAF), IDS/IPS, proxies - VPNs: IPsec (AH, ESP, modes), TLS VPN - Wireless security: WPA2/WPA3, EAP variants - Physical security: CPTED, perimeter, locks, mantraps, fire suppression - Environmental controls: HVAC, water detection, fire detection - Mobile, IoT, virtualization security
Activities: - Build crypto cheat sheet (algorithms, key sizes, use cases) - 100 practice questions on Domain 5
Week 11: Domain 5 Part 3 (Attacks, Testing, Forensics, Privacy)¶
Topics: - Common attack methods: phishing, MitM, DDoS, SQL injection, XSS, ransomware, supply chain - Security testing: vulnerability assessment, penetration testing (PTES, OSSTMM, NIST 800-115) - Security monitoring: SIEM, SOAR, UEBA - Incident response (NIST 800-61): preparation, detection, analysis, containment, eradication, recovery, lessons learned - Forensics: identification, preservation, collection, examination, analysis, presentation, decision; chain of custody - Privacy regulations: GDPR, CCPA, HIPAA, GLBA, SOX, PCI DSS, PIPEDA, LGPD - Data classification and handling - DLP, DRM
Activities: - Walk through an IR scenario end-to-end - 100 practice questions
Week 12: First Full-Length Practice Exam + Weak Domain Focus¶
Goals: Take a full 150-question simulated exam. Identify weak domains.
Activities: - Take ISACA QAE full-length practice exam under exam conditions (4 hours, no reference materials) - Review every wrong answer in depth (write the explanation in your own words) - Re-read weak chapters in CRM - Build new flashcards for missed concepts - Target 70%+ on first practice exam
Week 13: Second Full-Length Practice Exam + Cross-Domain Integration¶
Topics: - How domains intersect: a SOX audit touches Domains 1, 2, 4, 5 - Practice "BEST answer" question approach - Memorize Code of Ethics, ITAF tiers, COBIT EDM/APO/BAI/DSS/MEA, NIST 800-53 families, ISO 27001 themes - Review CRM end-of-chapter quizzes
Activities: - Take a second full-length exam from a different vendor (Hemang Doshi Udemy practice tests) - Target 75%+ on second full-length - Daily 30 minutes flashcard review - Spend 1-2 hours on each weak domain
Week 14: Final Review and Exam¶
Days 1-3: - Re-read CRM domain summaries - Review all flashcards twice - Watch a final review video (Hemang Doshi or Phil Martin "exam tips" video) - 75 practice questions per day, focused on weakest 2 domains
Day 4-5: - Light review only - no new material - Mind maps and summary sheets - Mental rehearsal of exam-day logistics - Confirm PSI test center appointment, ID, route OR test online-proctored environment
Day 6: - REST. No studying after early afternoon. - Light exercise, normal sleep, hydration
Exam Day: - Eat protein-rich breakfast - Arrive 30 minutes early at PSI center (or log in 30 min early for online-proctored) - Two forms of ID required (one government photo) - 4 hours, no scheduled breaks (you can take a break but the clock keeps running) - 150 questions, can navigate freely (mark and review) - Trust your preparation
Daily Habits Throughout¶
- 45 to 60 minutes of practice questions every day except rest day
- Anki flashcards - 15 minutes/day; new cards from current domain, review old cards
- Audit terminology journal - one page per day on a tested concept (sampling, control type, framework) in your own words
- Study group - weekly call with 1 to 3 other CISA candidates if possible
- ISACA Engage Community - browse weekly for current discussion threads
Practice Exam Score Targets¶
- Week 4: 50%+ on completed domains
- Week 7: 60% on full diagnostic
- Week 12: 70% on first full-length
- Week 13: 75%+ on second full-length
- Exam day: ready when consistently 75%+ on ISACA QAE and 80%+ on Hemang Doshi tests
Mindset Daily Reminders¶
- CISA rewards independent auditor judgment, not implementer thinking
- BEST answer, not only correct answer
- The auditor recommends, management decides
- Independence in fact AND in appearance
- Risk-based, not exhaustive
- Document everything (workpapers are the auditor's product)
After You Pass¶
- Submit certification application within 5 years (https://www.isaca.org/credentialing/cisa)
- Provide verification of work experience (signed by supervisor or independent verifier)
- Pay first AMF: $45 member / $85 non-member
- Plan 40+ CPEs in year 1 (free ISACA chapter meetings, webinars, books, articles, ISACA Journal)
- Adhere to ISACA Code of Professional Ethics
- Update LinkedIn, resume, and any clearance/role paperwork
- Consider companion certifications: CISM (sister cert, security management), CRISC (risk), CGEIT (governance), CCSP (cloud security)