1
Who Should Pursue the CISA
The CISA, issued by ISACA since 1978, is the global benchmark for information-systems audit. It is aimed at professionals who evaluate IT and business systems — and it certifies judgment, not tools.
- For IT and internal auditors, compliance officers, risk managers, and security professionals with 3–5+ years of relevant experience.
- Demand is driven by regulation — SOX, PCI DSS, HIPAA, and GDPR all create IS-audit requirements.
- vs. related credentials: CISM (security management), CRISC (risk), CISSP (security practitioner), CIA (internal audit). CISA owns IS audit.
🔎 In practiceIf a question ever feels like it's testing whether you can configure a firewall, re-read it — the CISA is testing whether you can audit the firewall's governance, not build it.
2
Exam Format & Scoring
Knowing the mechanics removes surprises on exam day and shapes how you pace yourself.
- 150 multiple-choice questions, one best answer, a 4-hour limit, at PSI centers or via remote proctoring.
- Scaled score 200–800; 450 is the passing mark.
- Questions are drawn proportionally by domain weight — Domains 4 and 5 together are 52% of the exam.
- Preliminary result on screen at completion; official report within ~10 business days; retakes are allowed (fees apply).
| Domain | Exam Weight |
| Domain 1 — IS Auditing Process | 18% |
| Domain 2 — Governance & Management of IT | 18% |
| Domain 3 — IS Acquisition, Development & Implementation | 12% |
| Domain 4 — IS Operations & Business Resilience | 26% |
| Domain 5 — Protection of Information Assets | 26% |
💡 Exam TipDomains 4 and 5 together are 52% of the exam. All domains require mastery, but disproportionate weakness in either of these two makes passing very difficult — allocate study time accordingly.
3
Eligibility & Experience Requirements
You can sit the exam before you qualify, but certification requires verified experience.
- 5 years of professional IS audit, control, assurance, or security experience.
- Substitutions up to 3 years: 1 year for a university degree or non-IS audit experience; 2 years for a 2-year IS/IT degree; 1 year for holding CISM or CISSP.
- You may pass first and submit verified experience within 5 years of passing.
- Experience is verified by an employer or supervisor.
🔎 In practiceA candidate who passed 18 months ago but hasn't submitted experience is not yet a CISA and may not use the designation — but still has time: up to five years from the pass date.
4
Endorsement, Retake & Maintenance (CPE & AMF)
Earning the credential is the start; keeping it requires ongoing investment.
- Apply for certification after passing; agree to the Code of Professional Ethics; ISACA reviews and approves the application.
- Retake policy: up to four attempts in a rolling 12-month period, with required waiting periods and a fee per attempt.
- Maintenance: 120 CPE hours per 3-year cycle, minimum 20 per year, plus an annual maintenance fee (AMF); CPE may be selected for audit.
5
The Code of Professional Ethics
Every CISA candidate and certificate holder agrees to ISACA's Code of Professional Ethics. It is binding, and the exam tests it through scenarios — especially around independence and confidentiality.
The seven principles — members and certification holders shall:
- 1. Support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective governance and management of enterprise IS/IT, including audit, control, security, and risk management.
- 2. Perform their duties with objectivity, due diligence, and professional care, in accordance with professional standards.
- 3. Serve in the interest of stakeholders in a lawful manner, while maintaining high standards of conduct and character, and not discrediting their profession or the Association.
- 4. Maintain the privacy and confidentiality of information obtained in the course of their activities unless disclosure is required by legal authority; such information shall not be used for personal benefit or released to inappropriate parties.
- 5. Maintain competency in their respective fields and undertake only activities they can reasonably expect to complete with the necessary skills, knowledge, and competence.
- 6. Inform appropriate parties of the results of work performed, disclosing all significant facts known to them that, if not disclosed, may distort the reporting of results.
- 7. Support the professional education of stakeholders in enhancing their understanding of the governance and management of enterprise IS/IT.
🔎 In practiceAsked to help design a control you'll later audit? The Code's objectivity principle says decline and document — preserving independence outranks being helpful.
📚
Explore furtherEthics & Professional Conduct — an interactive module on professional codes of ethics and values.
6
The Job Practice & Professional Standards
The exam is built from ISACA's Job Practice — task and knowledge statements that define what a CISA must know and do. Beneath it sits the professional-standards framework.
- The five domains form the architecture of the whole exam; every question maps to an auditor performing a task.
- Standards (the S-series) are mandatory minimum requirements; Guidelines (G-series) are non-mandatory elaboration; Tools & Techniques provide practical how-to.
- The most important shift: distinguish what an auditor does (evaluate, test, document, report) from what a technician does (build, implement, manage).
The mandatory standards at a glance (S1–S16)
- S1 Audit Charter · S2 Organizational Independence · S3 Professional Independence · S4 Reasonable Expectation
- S5 Due Professional Care · S6 Proficiency · S7 Assertions · S8 Criteria
- S9 Audit & Assurance Planning · S10 Supervision · S11 Materiality · S12 Using the Work of Other Experts
- S13 Evidence · S14 Computer-Assisted Audit Techniques (CAATs) · S15 Reporting · S16 Follow-up Activities
💡 Exam TipCISA questions ask what the auditor should do, not what the system does. When two answers both look technically correct, the one reflecting the auditor's independent, risk-based perspective is almost always right.
7
The Auditor Mindset
More candidates fail on mindset than on knowledge. The CISA rewards a specific way of thinking.
- Independence & objectivity — stay free from impairment.
- Risk-based — focus effort where risk is highest.
- Evidence-based — an opinion without evidence is not a finding.
- Professional skepticism — corroborate management's assertions.
- Report ≠ remediate — the auditor recommends; management owns the fix.
- Common traps: the technical fix over the audit action; “implement immediately” over “evaluate and report”; the most thorough test over the most risk-appropriate one.
💡 Exam TipWhen in doubt, ask: “Is this what an auditor does, or what a systems administrator does?” The auditor evaluates, tests, documents, and reports — it does not build, implement, or manage.
8
Study Resources & Strategy
Use the workshop as your spine and supplement it with ISACA's official materials and a paced plan.
- ISACA CISA Review Manual (CRM), the Questions, Answers & Explanations (QAE) database, the Online Review Course, and chapter/community study groups.
- This 5-day workshop plus the 30/60/90-day study plan detailed in Lesson 9.
- Pace practice at ~1.6 minutes per question (150 in 4 hours); use flag-and-review.
- Always answer from the auditor's perspective, not the practitioner's.