STUDY GUIDE · CISA

Certified Information Systems Auditor Study Guide

Aligned to the ISACA outline6 sections
By Vincent Ruan, EA, CFP®Published July 18, 2026
Questions
150
Time limit
4h
Passing score
450 on a scale of 200-800
Exam fee
$575
Governing body
ISACA

The Certified Information Systems Auditor (CISA) credential, issued by ISACA, is the benchmark certification for professionals who audit, control, monitor, and assess an organization's information systems and business processes. It signals to employers that a candidate can evaluate IT risk, review controls, and ensure that technology environments align with governance and compliance requirements.

CISA is aimed at IS/IT auditors, audit managers, consultants, and security professionals who need to demonstrate mastery of audit methodology rather than pure technical implementation. It is also a common target for compliance officers and risk analysts who work alongside audit teams.

Why It Matters for Your Career

  • It is one of the most widely recognized credentials in IT audit, governance, and risk, giving holders global mobility across industries and regulatory environments.
  • Employers in banking, healthcare, and government frequently list CISA as a preferred or required qualification for senior audit and risk roles.
  • The certification has a long track record of professional recognition.

Because the exam content is periodically revised to keep pace with how organizations manage risk and technology, earning CISA also signals that a professional's knowledge reflects current practice rather than outdated audit frameworks.

Understanding the mechanics of the CISA exam helps you plan your study timeline and testing logistics well in advance.

Format and Timing

  • The exam consists of 150 questions covering the five job practice domains.
  • Candidates are given a total testing time of 240 minutes (4 hours) to complete the exam.
  • A scaled score of 450 or higher out of a possible 800 is required to pass.

Delivery and Test Centers

ISACA delivers the CISA exam through PSI, which supports both in-person test center appointments and remote online proctoring, giving candidates flexibility in how and where they sit for the exam. PSI operates more than 1,300 testing locations worldwide, making the exam broadly accessible regardless of where a candidate is based.

Registration and Cost

  • The exam registration fee is US$575.00 for ISACA members.
  • The exam registration fee is US$760.00 for non-members, reflecting the value of ISACA membership for candidates planning to test more than once.
  • Once registered, candidates have an exam eligibility period of 6 months from the date of registration to sit for the exam, so scheduling your test date should factor into your study plan from day one.

The CISA exam content outline became effective 1 August 2024 and organizes exam content into five job practice domains, each carrying a specific weight toward your final score.

Domain 1: Information Systems Auditing Process (18%)

Covers audit planning, standards, risk-based audit strategy, and how to conduct and report on IS audits in line with professional guidelines.

Domain 2: Governance and Management of IT (18%)

Focuses on IT governance frameworks, organizational structure, policies, strategic alignment, and how management oversees IT resources and risk.

Domain 3: Information Systems Acquisition, Development and Implementation (12%)

Addresses project governance, system development lifecycle practices, testing, and controls applied when systems are acquired or built.

Domain 4: Information Systems Operations and Business Resilience (26%)

Covers IT operations management, service management, data governance, and business continuity/disaster recovery planning.

Domain 5: Protection of Information Assets (26%)

Focuses on security controls, identity and access management, network and endpoint security, and incident response.

Domains 4 and 5 together account for 52% of the exam content, meaning operations, resilience, and security controls should receive the largest share of your study time. The revised outline places particular emphasis on risk, security, and controls related to disruptive technologies and emerging IT audit practices, so candidates should expect scenario-based questions that connect traditional audit principles to modern technology environments.

Most candidates need eight to twelve weeks of consistent study to cover all five domains, though your timeline should flex based on prior audit or IT experience.

Weeks 1-2: Foundation

Start with Domains 1 and 2 to build a shared vocabulary around audit process and IT governance. These domains establish the language and frameworks referenced throughout the rest of the exam.

Weeks 3-4: Systems Lifecycle

Move into Domain 3, focusing on how controls are embedded during system acquisition, development, and implementation. This is typically the lightest-weighted domain, so pair it with review of earlier material.

Weeks 5-7: Heavy-Weight Domains

Dedicate the largest block of time to Domains 4 and 5, since together they make up over half the exam. Break these into sub-topics: operations and resilience one week, security and access controls the next, using scenario-based questions to test applied understanding rather than memorization.

Weeks 8-10: Integration and Practice

  • Take full-length timed practice exams to build stamina for the four-hour session.
  • Review missed questions by domain to identify weak areas.
  • Revisit glossary terms and flashcards for concepts that keep tripping you up.

Final Week

Focus on light review, weak-area drilling, and rest. Avoid cramming new material in the final 48 hours; instead, reinforce what you already know and confirm your test appointment details.

Preparation quality matters, but so does how you manage the exam itself.

Before Exam Day

  • Confirm your appointment details and identification requirements with PSI well ahead of time, especially if you chose remote online proctoring.
  • Do a final review of domain weightings so you can mentally allocate time proportionally, spending more attention on questions from the heavier domains.
  • Get a full night's sleep; a four-hour exam rewards sustained focus over last-minute cramming.

During the Exam

  • Read each question carefully for qualifiers like "best," "most likely," or "first," since CISA questions often test judgment among several plausible answers.
  • Flag uncertain questions and move on rather than getting stuck, then return with fresh eyes if time allows.
  • Think like an auditor, not an implementer: CISA rewards the most appropriate audit or governance response, not necessarily the most technically sophisticated one.

Common Mistakes to Avoid

  • Over-studying Domain 3 while under-preparing for Domains 4 and 5, which carry more than half the total weight.
  • Memorizing terms without understanding how concepts apply in real audit scenarios.
  • Waiting until the last weeks of your eligibility period to schedule a test date, which can force you into an inconvenient time slot or location.

You don't need to prepare for CISA from scratch. Free study resources on this site are built to reinforce the same domain structure the exam uses, so your practice time maps directly onto what you'll be tested on.

Practice Questions

Scenario-style practice questions modeled on CISA's domain weightings let you simulate exam conditions, identify weak domains early, and build the timed-testing stamina needed for a four-hour exam.

Flashcards

Flashcards are useful for locking in recurring frameworks, control types, and audit terminology that show up across multiple domains, particularly the governance and security-heavy sections.

Glossary

A glossary of IT audit and governance terminology helps you quickly look up unfamiliar vocabulary you encounter while reading practice questions or study guides, reducing the friction of switching between multiple reference sources.

Using these tools alongside a structured study plan lets you spend less time hunting for study material and more time actually practicing recall and applied judgment, which is what the CISA exam is designed to test.

Sources

  1. 1.CISA Exam Content OutlineISACA (accessed Jul 18, 2026)
  2. 2.Certification Exam Candidate GuidesISACA (accessed Jul 18, 2026)
  3. 3.CISA Certification OverviewISACA (accessed Jul 18, 2026)
  4. 4.ISACA's CISA Exam Updated to Reflect Innovations and Evolving Technologies (Press Release, 2024)ISACA (accessed Jul 18, 2026)