Certified Information Systems Auditor Study Guide
- Questions
- 150
- Time limit
- 4h
- Passing score
- 450 on a scale of 200-800
- Exam fee
- $575
- Governing body
- ISACA
The Certified Information Systems Auditor (CISA) credential, issued by ISACA, is the benchmark certification for professionals who audit, control, monitor, and assess an organization's information systems and business processes. It signals to employers that a candidate can evaluate IT risk, review controls, and ensure that technology environments align with governance and compliance requirements.
CISA is aimed at IS/IT auditors, audit managers, consultants, and security professionals who need to demonstrate mastery of audit methodology rather than pure technical implementation. It is also a common target for compliance officers and risk analysts who work alongside audit teams.
Why It Matters for Your Career
- It is one of the most widely recognized credentials in IT audit, governance, and risk, giving holders global mobility across industries and regulatory environments.
- Employers in banking, healthcare, and government frequently list CISA as a preferred or required qualification for senior audit and risk roles.
- The certification has a long track record of professional recognition.
Because the exam content is periodically revised to keep pace with how organizations manage risk and technology, earning CISA also signals that a professional's knowledge reflects current practice rather than outdated audit frameworks.
Understanding the mechanics of the CISA exam helps you plan your study timeline and testing logistics well in advance.
Format and Timing
- The exam consists of 150 questions covering the five job practice domains.
- Candidates are given a total testing time of 240 minutes (4 hours) to complete the exam.
- A scaled score of 450 or higher out of a possible 800 is required to pass.
Delivery and Test Centers
ISACA delivers the CISA exam through PSI, which supports both in-person test center appointments and remote online proctoring, giving candidates flexibility in how and where they sit for the exam. PSI operates more than 1,300 testing locations worldwide, making the exam broadly accessible regardless of where a candidate is based.
Registration and Cost
- The exam registration fee is US$575.00 for ISACA members.
- The exam registration fee is US$760.00 for non-members, reflecting the value of ISACA membership for candidates planning to test more than once.
- Once registered, candidates have an exam eligibility period of 6 months from the date of registration to sit for the exam, so scheduling your test date should factor into your study plan from day one.
The CISA exam content outline became effective 1 August 2024 and organizes exam content into five job practice domains, each carrying a specific weight toward your final score.
Domain 1: Information Systems Auditing Process (18%)
Covers audit planning, standards, risk-based audit strategy, and how to conduct and report on IS audits in line with professional guidelines.
Domain 2: Governance and Management of IT (18%)
Focuses on IT governance frameworks, organizational structure, policies, strategic alignment, and how management oversees IT resources and risk.
Domain 3: Information Systems Acquisition, Development and Implementation (12%)
Addresses project governance, system development lifecycle practices, testing, and controls applied when systems are acquired or built.
Domain 4: Information Systems Operations and Business Resilience (26%)
Covers IT operations management, service management, data governance, and business continuity/disaster recovery planning.
Domain 5: Protection of Information Assets (26%)
Focuses on security controls, identity and access management, network and endpoint security, and incident response.
Domains 4 and 5 together account for 52% of the exam content, meaning operations, resilience, and security controls should receive the largest share of your study time. The revised outline places particular emphasis on risk, security, and controls related to disruptive technologies and emerging IT audit practices, so candidates should expect scenario-based questions that connect traditional audit principles to modern technology environments.
Most candidates need eight to twelve weeks of consistent study to cover all five domains, though your timeline should flex based on prior audit or IT experience.
Weeks 1-2: Foundation
Start with Domains 1 and 2 to build a shared vocabulary around audit process and IT governance. These domains establish the language and frameworks referenced throughout the rest of the exam.
Weeks 3-4: Systems Lifecycle
Move into Domain 3, focusing on how controls are embedded during system acquisition, development, and implementation. This is typically the lightest-weighted domain, so pair it with review of earlier material.
Weeks 5-7: Heavy-Weight Domains
Dedicate the largest block of time to Domains 4 and 5, since together they make up over half the exam. Break these into sub-topics: operations and resilience one week, security and access controls the next, using scenario-based questions to test applied understanding rather than memorization.
Weeks 8-10: Integration and Practice
- Take full-length timed practice exams to build stamina for the four-hour session.
- Review missed questions by domain to identify weak areas.
- Revisit glossary terms and flashcards for concepts that keep tripping you up.
Final Week
Focus on light review, weak-area drilling, and rest. Avoid cramming new material in the final 48 hours; instead, reinforce what you already know and confirm your test appointment details.
Preparation quality matters, but so does how you manage the exam itself.
Before Exam Day
- Confirm your appointment details and identification requirements with PSI well ahead of time, especially if you chose remote online proctoring.
- Do a final review of domain weightings so you can mentally allocate time proportionally, spending more attention on questions from the heavier domains.
- Get a full night's sleep; a four-hour exam rewards sustained focus over last-minute cramming.
During the Exam
- Read each question carefully for qualifiers like "best," "most likely," or "first," since CISA questions often test judgment among several plausible answers.
- Flag uncertain questions and move on rather than getting stuck, then return with fresh eyes if time allows.
- Think like an auditor, not an implementer: CISA rewards the most appropriate audit or governance response, not necessarily the most technically sophisticated one.
Common Mistakes to Avoid
- Over-studying Domain 3 while under-preparing for Domains 4 and 5, which carry more than half the total weight.
- Memorizing terms without understanding how concepts apply in real audit scenarios.
- Waiting until the last weeks of your eligibility period to schedule a test date, which can force you into an inconvenient time slot or location.
You don't need to prepare for CISA from scratch. Free study resources on this site are built to reinforce the same domain structure the exam uses, so your practice time maps directly onto what you'll be tested on.
Practice Questions
Scenario-style practice questions modeled on CISA's domain weightings let you simulate exam conditions, identify weak domains early, and build the timed-testing stamina needed for a four-hour exam.
Flashcards
Flashcards are useful for locking in recurring frameworks, control types, and audit terminology that show up across multiple domains, particularly the governance and security-heavy sections.
Glossary
A glossary of IT audit and governance terminology helps you quickly look up unfamiliar vocabulary you encounter while reading practice questions or study guides, reducing the friction of switching between multiple reference sources.
Using these tools alongside a structured study plan lets you spend less time hunting for study material and more time actually practicing recall and applied judgment, which is what the CISA exam is designed to test.
CISA flashcards
30 cards on the highest-yield terms and rules. Grading uses spaced repetition and saves in this browser.
Browse all 30 cards
How many domains make up the CISA job practice, and what is the total exam duration?
The CISA exam covers 5 job practice domains and has a total testing time of 240 minutes (4 hours) across 150 questions.
Which two CISA domains carry the highest combined weighting, and what is that weighting?
Domain 4 (Information Systems Operations and Business Resilience) and Domain 5 (Protection of Information Assets) together account for 52% of exam content, each weighted at 26%.
What scaled score is needed to pass the CISA exam?
A scaled score of 450 or higher (on ISACA's 200-800 scale) is required to pass.
What is the primary objective of an IS audit charter?
An audit charter formally documents the audit function's purpose, authority, and responsibility, and it should be approved by senior management and the audit committee/board.
Define audit risk.
Audit risk is the risk that the auditor may issue an incorrect opinion because material errors or misstatements went undetected; it combines inherent risk, control risk, and detection risk.
What is the difference between inherent risk and control risk?
Inherent risk is the susceptibility of a process to material error assuming no controls exist; control risk is the risk that a control will fail to prevent or detect such an error in a timely manner.
What is detection risk in an audit context?
Detection risk is the risk that an auditor's procedures will fail to detect a material error or misstatement that exists.
What is the purpose of a risk-based audit approach?
A risk-based approach directs audit resources and testing toward the areas of highest risk to the organization, rather than treating all areas equally, maximizing audit value and coverage efficiency.
What is segregation of duties (SoD) and why does it matter to an IS auditor?
SoD divides critical tasks (e.g., authorization, custody, recordkeeping) among different individuals so no single person can commit and conceal fraud or errors; auditors test for SoD violations as a key control weakness.
Distinguish preventive, detective, and corrective controls.
Preventive controls stop an undesirable event before it occurs (e.g., access controls); detective controls identify an event after it happens (e.g., log monitoring); corrective controls remediate the impact after detection (e.g., restoring from backup).
What is a compensating control?
A compensating control is an alternative control that reduces risk to an acceptable level when a primary control cannot be implemented, e.g., manager review substituting for automated SoD enforcement.
What is the role of COBIT in IT governance?
COBIT is ISACA's framework for the governance and management of enterprise IT, aligning IT goals with business objectives and providing a structure for control, risk, and performance evaluation.
What is IT governance, broadly defined?
IT governance is the leadership, organizational structures, and processes that ensure an organization's IT sustains and extends its strategies and objectives, tying IT investment to business value and risk management.
What is a Business Impact Analysis (BIA)?
A BIA identifies critical business processes and the impact of their disruption over time, establishing recovery priorities, Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO).
Define Recovery Time Objective (RTO) and Recovery Point Objective (RPO).
RTO is the maximum acceptable time to restore a process/system after a disruption; RPO is the maximum acceptable amount of data loss measured in time (how far back data must be recoverable).
What is the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
A BCP addresses continuing critical business operations during and after a disruption across the whole organization; a DRP is a narrower, technical subset focused on restoring IT systems and infrastructure.
What is a change management process meant to control?
Change management ensures that changes to systems, applications, and infrastructure are requested, assessed, approved, tested, and documented before deployment to minimize unintended impact and maintain integrity.
What is the System Development Life Cycle (SDLC), and why is auditor involvement important early?
The SDLC is the structured process of planning, analyzing, designing, developing, testing, implementing, and maintaining systems; early auditor involvement ensures controls and requirements are built in rather than retrofitted.
What is the purpose of user acceptance testing (UAT)?
UAT validates that a system meets business requirements and functions correctly from the end user's perspective before it is moved into production.
What does the principle of least privilege mean?
Least privilege means users and processes are granted only the minimum access rights necessary to perform their required functions, reducing the attack surface and potential for misuse.
What is defense in depth?
Defense in depth is a security strategy that layers multiple, overlapping controls (physical, technical, administrative) so that if one control fails, others still provide protection.
What is the difference between authentication and authorization?
Authentication verifies the identity of a user or system (who you are); authorization determines what actions or resources that verified identity is permitted to access (what you can do).
What is a firewall's primary function in a network security architecture?
A firewall enforces access control policy by filtering network traffic between zones of differing trust levels based on defined rules.
What is encryption at rest versus encryption in transit?
Encryption at rest protects stored data on disks or media; encryption in transit protects data as it moves across a network, typically via protocols like TLS.
What is a digital signature used to provide?
A digital signature provides authentication, integrity, and non-repudiation by using asymmetric cryptography to prove a message originated from a specific sender and was not altered.
What is the purpose of a vulnerability assessment versus a penetration test?
A vulnerability assessment identifies and catalogs known weaknesses in systems, while a penetration test actively attempts to exploit those weaknesses to demonstrate real-world impact.
What is data classification and why is it a foundational control?
Data classification categorizes information (e.g., public, internal, confidential, restricted) based on sensitivity and value, driving proportionate handling, access, and protection requirements.
What is an audit evidence sufficiency and appropriateness standard used for?
Sufficiency refers to the quantity of evidence needed to support a conclusion; appropriateness refers to its relevance and reliability; auditors must gather evidence meeting both criteria to support findings.
What is CoBIT's relationship to CISA exam content?
COBIT provides the governance and control framework referenced throughout CISA domains, especially Domain 2 (Governance and Management of IT), for aligning IT processes with enterprise goals.
What is the purpose of continuous auditing/continuous monitoring techniques?
These techniques use automated tools to test controls and transactions on an ongoing or near-real-time basis, enabling earlier detection of anomalies compared to periodic manual audits.
CISA glossary
25 terms the CISA tests, defined in plain English.
- Audit Charter
- A formal document approved by senior management that defines the purpose, authority, and responsibility of the internal audit function.
- Audit Evidence
- Information gathered by an auditor during fieldwork that must be sufficient (adequate quantity) and appropriate (relevant and reliable) to support audit conclusions.
- Business Continuity Plan (BCP)
- A documented, organization-wide plan for maintaining or quickly resuming critical business functions during and after a disruptive event.
- Business Impact Analysis (BIA)
- A process that identifies critical business functions and quantifies the operational and financial impact of their disruption to prioritize recovery efforts.
- Change Management
- The formal process of requesting, evaluating, approving, testing, and documenting changes to IT systems to minimize disruption and preserve control integrity.
- CISA
- Certified Information Systems Auditor, an ISACA credential recognizing expertise in auditing, controlling, monitoring, and assessing information systems and business.
- COBIT
- Control Objectives for Information and Related Technologies; ISACA's framework for enterprise governance and management of IT, aligning IT processes with business objectives.
- Compensating Control
- An alternative safeguard implemented to reduce risk to an acceptable level when a primary control is not feasible or is otherwise absent.
- Continuous Auditing
- An approach using automated tools to evaluate controls and transactions on an ongoing or near-real-time basis rather than through periodic manual review.
- Control Risk
- The risk that a control will fail to prevent or detect a material error or misstatement in a timely manner.
- Data Classification
- The practice of categorizing data by sensitivity or value (e.g., public, internal, confidential, restricted) to determine appropriate handling and protection requirements.
- Defense in Depth
- A layered security strategy that combines multiple independent controls so that the failure of one does not compromise the entire system.
- Detection Risk
- The risk that an auditor's testing procedures fail to identify a material error or misstatement that actually exists.
- Digital Signature
- A cryptographic mechanism using asymmetric key pairs that provides authentication, data integrity, and non-repudiation for a message or document.
- Disaster Recovery Plan (DRP)
- A technical plan focused on restoring IT systems, applications, and infrastructure following a disaster, typically a subset of the broader BCP.
- Inherent Risk
- The level of risk that exists in a process or activity before any controls are applied.
- ISACA
- A global professional association (formerly the Information Systems Audit and Control Association) that develops IT governance, audit, security, and risk certifications and frameworks including COBIT.
- IT Governance
- The leadership, structures, and processes that ensure an organization's IT investments and activities support and extend its strategic objectives.
- Least Privilege
- A security principle granting users and processes only the minimum access rights necessary to perform their assigned functions.
- Penetration Testing
- An authorized, simulated attack against a system or network to actively exploit vulnerabilities and evaluate real-world exploitability and impact.
- Recovery Point Objective (RPO)
- The maximum acceptable amount of data loss, measured as a point in time to which data must be recoverable following a disruption.
- Recovery Time Objective (RTO)
- The maximum tolerable duration within which a business process or system must be restored after a disruption.
- Segregation of Duties (SoD)
- A control principle that divides key responsibilities among multiple people to prevent any single individual from having end-to-end control over a critical process.
- System Development Life Cycle (SDLC)
- The structured sequence of phases — planning, analysis, design, development, testing, implementation, and maintenance — used to build and deploy information systems.
- Vulnerability Assessment
- A systematic review process that identifies, classifies, and reports known security weaknesses in systems or networks without actively exploiting them.
Sources
- 1.CISA Exam Content Outline — ISACA (accessed Jul 18, 2026)
- 2.Certification Exam Candidate Guides — ISACA (accessed Jul 18, 2026)
- 3.CISA Certification Overview — ISACA (accessed Jul 18, 2026)
- 4.ISACA's CISA Exam Updated to Reflect Innovations and Evolving Technologies (Press Release, 2024) — ISACA (accessed Jul 18, 2026)
Official sources
Primary documents used to verify the exam details shown on this page.
- CISA Exam Content OutlineISACAisaca.org
- CISA Certification OverviewISACAisaca.org
- ISACA's CISA Exam Updated to Reflect Innovations and Evolving Technologies (Press Release, 2024)ISACAisaca.org
- Certification Exam Candidate GuidesISACAisaca.org
- CISA ExamISACAisaca.org
Last verified against the ISACA exam content outline: