Each lesson covers one CISA domain in depth — learning objectives, key terminology, a detailed content outline, exam tips, and a scored knowledge check. Begin at Lesson 0 for the exam orientation and the auditor mindset.
Day 1 — Morning
CISA Exam Overview & Orientation
The CISA is not a technology test — it is an audit judgment test. Before your first study hour, understand the exam's architecture, scoring mechanics, eligibility and ethics requirements, and the mindset shift from practitioner to independent auditor.
Day 1 — Afternoon
Domain 1 — Information Systems Auditing Process
The audit doesn't start when the auditor arrives at the client site — it starts with a risk-based plan. Domain 1 establishes the professional framework that governs every IS audit engagement, from planning through execution, evidence, and reporting.
Day 2 — Morning
Domain 2 — Governance & Management of IT (Part A)
Governance is the force that aligns IT with business strategy, manages risk, and ensures accountability. An IS auditor who doesn't understand governance will misread the very controls they are testing. Part A covers IT governance, strategy, and frameworks.
Day 2 — Afternoon
Domain 2 — Governance & Management of IT (Part B)
Governance sets the direction; management keeps the engine running. IT management turns strategy into operational capability — and gives IS auditors a rich set of processes, policies, and resource controls to evaluate.
Day 3 — Morning
Domain 3 — IS Acquisition, Development & Implementation
Every new system brings new risk. Domain 3 equips IS auditors to evaluate the controls built into how technology is planned, procured, built, tested, and deployed — before it's too late to fix the design.
Day 3 — Afternoon
Domain 4 — IS Operations (Part A)
IS operations is where IT governance meets reality. Domain 4A covers the components, processes, and daily management of the IT environment — and the controls that keep it running reliably and securely.
Day 4 — Morning
Domain 4 — Business Resilience (Part B)
When systems fail — and they will — organizations that planned survive. Domain 4B is the auditor's guide to evaluating whether the organization can absorb disruption and recover, covering backup, BCP, and disaster recovery.
Day 4 — Afternoon
Domain 5 — Protection of Info Assets (Part A)
Part A — Asset Security & Control. The frameworks and protective controls: physical & environmental security, identity and access management, network and endpoint defense, encryption and PKI, data loss prevention, and the cloud/mobile/IoT surface.
Day 5 — Morning
Domain 5 — Protection of Info Assets (Part B)
Part B — Security Event Management. The human layer and attack landscape, security testing and monitoring, and what happens when prevention fails: incident response and digital forensics.
Day 5 — Afternoon
Final Review, Practice Exam & Study Plan
The capstone: a synthesis of all five domains and the trap-answer patterns, a full 20-question mixed-domain practice exam with rationale, a 30/60/90-day study countdown, and an exam-day playbook.
Not part of the 5-day exam sequence
Teaching CISA — Faculty PD Guide
You’ve mastered the exam — now build the course. A faculty guide to deploying CISA content in your curriculum: course mapping, Bloom’s alignment, AI-tool workflows, and three program-design models.