The CISA is not a technology test — it is an audit-judgment test. Before your first study hour, understand the exam's architecture, scoring, eligibility and ethics requirements, and the mindset shift from practitioner to independent auditor.
Most candidates fail the CISA not because they lack technical knowledge, but because they answer like a technician instead of an auditor. This orientation sets the rules of the game — how the exam is built and scored, what ISACA requires of you, and the single conceptual shift that determines whether the next nine lessons land. The auditor evaluates, tests, documents, and reports. The auditor does not build, implement, or manage. Carry that distinction into every lesson that follows.
ℹ️ Independence NoticeThis is an independent educational resource — not affiliated with, endorsed by, or sponsored by ISACA. CISA® is a registered trademark of ISACA. Content is based on publicly available ISACA documentation and the CISA Job Practice effective 2019 (current as of 2026); always confirm the live exam content outline at isaca.org before you register.
Learning Objectives
By the end of this lesson you will be able to…
Explain the structure, format, and scoring of the CISA examination. Bloom: Understand
Describe ISACA's experience and ethics requirements for CISA certification. Bloom: Understand
Identify the five CISA domains and their relative exam weights. Bloom: Remember
Articulate the IS auditor's role, responsibilities, and professional code of conduct. Bloom: Understand
Apply the “auditor mindset” to distinguish audit-perspective answers from technical-practitioner answers. Bloom: Apply
Establish a personalized study strategy using the 30/60/90-day plan introduced in Lesson 9. Bloom: Create
Key Terms
Vocabulary flashcards
👈 Read the term, recall the definition, then click or press Enter to check yourself.
Lesson Content
Study the material
1
Who Should Pursue the CISA
The CISA, issued by ISACA since 1978, is the global benchmark for information-systems audit. It is aimed at professionals who evaluate IT and business systems — and it certifies judgment, not tools.
For IT and internal auditors, compliance officers, risk managers, and security professionals with 3–5+ years of relevant experience.
Demand is driven by regulation — SOX, PCI DSS, HIPAA, and GDPR all create IS-audit requirements.
vs. related credentials: CISM (security management), CRISC (risk), CISSP (security practitioner), CIA (internal audit). CISA owns IS audit.
🔎 In practice
If a question ever feels like it's testing whether you can configure a firewall, re-read it — the CISA is testing whether you can audit the firewall's governance, not build it.
2
Exam Format & Scoring
Knowing the mechanics removes surprises on exam day and shapes how you pace yourself.
150 multiple-choice questions, one best answer, a 4-hour limit, at PSI centers or via remote proctoring.
Scaled score 200–800; 450 is the passing mark.
Questions are drawn proportionally by domain weight — Domains 4 and 5 together are 52% of the exam.
Preliminary result on screen at completion; official report within ~10 business days; retakes are allowed (fees apply).
Domain
Exam Weight
Domain 1 — IS Auditing Process
18%
Domain 2 — Governance & Management of IT
18%
Domain 3 — IS Acquisition, Development & Implementation
12%
Domain 4 — IS Operations & Business Resilience
26%
Domain 5 — Protection of Information Assets
26%
💡 Exam TipDomains 4 and 5 together are 52% of the exam. All domains require mastery, but disproportionate weakness in either of these two makes passing very difficult — allocate study time accordingly.
3
Eligibility & Experience Requirements
You can sit the exam before you qualify, but certification requires verified experience.
5 years of professional IS audit, control, assurance, or security experience.
Substitutions up to 3 years: 1 year for a university degree or non-IS audit experience; 2 years for a 2-year IS/IT degree; 1 year for holding CISM or CISSP.
You may pass first and submit verified experience within 5 years of passing.
Experience is verified by an employer or supervisor.
🔎 In practice
A candidate who passed 18 months ago but hasn't submitted experience is not yet a CISA and may not use the designation — but still has time: up to five years from the pass date.
4
Certification Costs, Endorsement & Maintenance
Earning the credential is the start; keeping it requires ongoing investment — of both money and CPE hours. Budget for two kinds of cost: one-time charges to earn the credential and recurring charges to keep it active.
What it costs
Cost
When
Member
Non-member
Exam registration
One-time, per attempt
$575
$760
ISACA membership (optional)
Annual
~$135 + chapter dues
—
Certification application
One-time, after passing
$50
$50
Annual Maintenance Fee (AMF)
Every year you hold CISA
$45
$85
💰 Cost TipMembership usually pays for itself. Member dues (~$135) plus the member exam fee ($575) total about $710 — less than the $760 non-member exam fee alone — and membership also halves the annual maintenance fee ($45 vs $85) and unlocks discounted review materials. Figures are approximate and exclude local taxes and chapter dues; always verify current pricing at isaca.org, as ISACA adjusts fees periodically.
Endorsement, retakes & ongoing maintenance
Apply for certification after passing; agree to the Code of Professional Ethics; ISACA reviews and approves the application.
Retake policy: up to four attempts in a rolling 12-month period, with required waiting periods and the registration fee due per attempt.
Maintenance: 120 CPE hours per 3-year cycle, minimum 20 per year, plus the annual maintenance fee (AMF) above — both are required to keep the credential active, and CPE may be selected for audit.
5
The Code of Professional Ethics
Every CISA candidate and certificate holder agrees to ISACA's Code of Professional Ethics. It is binding, and the exam tests it through scenarios — especially around independence and confidentiality.
The seven principles — members and certification holders shall:
1. Support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective governance and management of enterprise IS/IT, including audit, control, security, and risk management.
2. Perform their duties with objectivity, due diligence, and professional care, in accordance with professional standards.
3. Serve in the interest of stakeholders in a lawful manner, while maintaining high standards of conduct and character, and not discrediting their profession or the Association.
4. Maintain the privacy and confidentiality of information obtained in the course of their activities unless disclosure is required by legal authority; such information shall not be used for personal benefit or released to inappropriate parties.
5. Maintain competency in their respective fields and undertake only activities they can reasonably expect to complete with the necessary skills, knowledge, and competence.
6. Inform appropriate parties of the results of work performed, disclosing all significant facts known to them that, if not disclosed, may distort the reporting of results.
7. Support the professional education of stakeholders in enhancing their understanding of the governance and management of enterprise IS/IT.
🔎 In practice
Asked to help design a control you'll later audit? The Code's objectivity principle says decline and document — preserving independence outranks being helpful.
Activity — Ethics round-robin
Five situations, each of which puts one principle of the Code under direct pressure. For each, commit to two decisions before you check: which principle is most directly at stake, and what the Code requires you to do. Naming the principle is the easy half — the exam tests the required action.
🎓 How to run this in classAssign one situation per table. Each table commits privately first (no discussion), then argues its case to the room for 60 seconds before checking. Rotate so every table hears all five. The debrief question that matters: which wrong answer did someone at your table find tempting, and why?
Principle 0/5 · Required action 0/5
Step 1 — Which principle is most directly at stake?Step 2 — What does the Code require you to do?
📚
Explore furtherEthics & Professional Conduct — an interactive module on professional codes of ethics and values.
The exam is built from ISACA's Job Practice — task and knowledge statements that define what a CISA must know and do. Beneath it sits the professional-standards framework.
The five domains form the architecture of the whole exam; every question maps to an auditor performing a task.
Standards (the S-series) are mandatory minimum requirements; Guidelines (G-series) are non-mandatory elaboration; Tools & Techniques provide practical how-to.
The most important shift: distinguish what an auditor does (evaluate, test, document, report) from what a technician does (build, implement, manage).
The mandatory standards at a glance (S1–S16)
S1 Audit Charter · S2 Organizational Independence · S3 Professional Independence · S4 Reasonable Expectation
S5 Due Professional Care · S6 Proficiency · S7 Assertions · S8 Criteria
S9 Audit & Assurance Planning · S10 Supervision · S11 Materiality · S12 Using the Work of Other Experts
💡 Exam TipCISA questions ask what the auditor should do, not what the system does. When two answers both look technically correct, the one reflecting the auditor's independent, risk-based perspective is almost always right.
7
The Auditor Mindset
More candidates fail on mindset than on knowledge. The CISA rewards a specific way of thinking.
Independence & objectivity — stay free from impairment.
Risk-based — focus effort where risk is highest.
Evidence-based — an opinion without evidence is not a finding.
Professional skepticism — corroborate management's assertions.
Report ≠ remediate — the auditor recommends; management owns the fix.
Common traps: the technical fix over the audit action; “implement immediately” over “evaluate and report”; the most thorough test over the most risk-appropriate one.
💡 Exam TipWhen in doubt, ask: “Is this what an auditor does, or what a systems administrator does?” The auditor evaluates, tests, documents, and reports — it does not build, implement, or manage.
Activity — Practitioner or auditor?
Twelve actions, one at a time. Decide whether each is something the auditor does, something the practitioner or management does, or whether it depends on facts you do not yet have. Commit before you check — the value is in noticing which instinct fired first. Most experienced professionals miss the same three or four cards, and always in the same direction.
🎓 How to run this in classEveryone sorts all twelve silently first — no talking. Then take a show of hands on each card and spend your discussion time only on the cards where the room splits, plus the three “it depends” cards. Those disagreements are the lesson; the unanimous cards are not.
Card 1 of 12
8
Study Resources & Strategy
Use the workshop as your spine and supplement it with ISACA's official materials and a paced plan.
ISACA CISA Review Manual (CRM), the Questions, Answers & Explanations (QAE) database, the Online Review Course, and chapter/community study groups.
This 5-day workshop plus the 30/60/90-day study plan detailed in Lesson 9.
Pace practice at ~1.6 minutes per question (150 in 4 hours); use flag-and-review.
Always answer from the auditor's perspective, not the practitioner's.
Scored Knowledge Check
Test your orientation
Select the best answer for each question, then submit for your score and the rationale for every item — including why the tempting wrong answers fail. Answer from the auditor's perspective.