Day 1 — Morning Orientation

CISA Exam Overview & Orientation

The CISA is not a technology test — it is an audit-judgment test. Before your first study hour, understand the exam's architecture, scoring, eligibility and ethics requirements, and the mindset shift from practitioner to independent auditor.

Session: Morning Orientation Duration: ~3 hrs Exam Weight: N/A — Meta-lesson Knowledge Check: 5 Questions

Overview

Why this lesson comes first

Most candidates fail the CISA not because they lack technical knowledge, but because they answer like a technician instead of an auditor. This orientation sets the rules of the game — how the exam is built and scored, what ISACA requires of you, and the single conceptual shift that determines whether the next nine lessons land. The auditor evaluates, tests, documents, and reports. The auditor does not build, implement, or manage. Carry that distinction into every lesson that follows.

ℹ️ Independence NoticeThis is an independent educational resource — not affiliated with, endorsed by, or sponsored by ISACA. CISA® is a registered trademark of ISACA. Content is based on publicly available ISACA documentation and the CISA Job Practice effective 2019 (current as of 2026); always confirm the live exam content outline at isaca.org before you register.

Learning Objectives

By the end of this lesson you will be able to…

Key Terms

Vocabulary flashcards

👈 Read the term, recall the definition, then click or press Enter to check yourself.

Lesson Content

Study the material

1

Who Should Pursue the CISA

The CISA, issued by ISACA since 1978, is the global benchmark for information-systems audit. It is aimed at professionals who evaluate IT and business systems — and it certifies judgment, not tools.

  • For IT and internal auditors, compliance officers, risk managers, and security professionals with 3–5+ years of relevant experience.
  • Demand is driven by regulation — SOX, PCI DSS, HIPAA, and GDPR all create IS-audit requirements.
  • vs. related credentials: CISM (security management), CRISC (risk), CISSP (security practitioner), CIA (internal audit). CISA owns IS audit.
🔎 In practice

If a question ever feels like it's testing whether you can configure a firewall, re-read it — the CISA is testing whether you can audit the firewall's governance, not build it.

2

Exam Format & Scoring

Knowing the mechanics removes surprises on exam day and shapes how you pace yourself.

  • 150 multiple-choice questions, one best answer, a 4-hour limit, at PSI centers or via remote proctoring.
  • Scaled score 200–800; 450 is the passing mark.
  • Questions are drawn proportionally by domain weight — Domains 4 and 5 together are 52% of the exam.
  • Preliminary result on screen at completion; official report within ~10 business days; retakes are allowed (fees apply).
DomainExam Weight
Domain 1 — IS Auditing Process18%
Domain 2 — Governance & Management of IT18%
Domain 3 — IS Acquisition, Development & Implementation12%
Domain 4 — IS Operations & Business Resilience26%
Domain 5 — Protection of Information Assets26%
💡 Exam TipDomains 4 and 5 together are 52% of the exam. All domains require mastery, but disproportionate weakness in either of these two makes passing very difficult — allocate study time accordingly.
3

Eligibility & Experience Requirements

You can sit the exam before you qualify, but certification requires verified experience.

  • 5 years of professional IS audit, control, assurance, or security experience.
  • Substitutions up to 3 years: 1 year for a university degree or non-IS audit experience; 2 years for a 2-year IS/IT degree; 1 year for holding CISM or CISSP.
  • You may pass first and submit verified experience within 5 years of passing.
  • Experience is verified by an employer or supervisor.
🔎 In practice

A candidate who passed 18 months ago but hasn't submitted experience is not yet a CISA and may not use the designation — but still has time: up to five years from the pass date.

4

Endorsement, Retake & Maintenance (CPE & AMF)

Earning the credential is the start; keeping it requires ongoing investment.

  • Apply for certification after passing; agree to the Code of Professional Ethics; ISACA reviews and approves the application.
  • Retake policy: up to four attempts in a rolling 12-month period, with required waiting periods and a fee per attempt.
  • Maintenance: 120 CPE hours per 3-year cycle, minimum 20 per year, plus an annual maintenance fee (AMF); CPE may be selected for audit.
5

The Code of Professional Ethics

Every CISA candidate and certificate holder agrees to ISACA's Code of Professional Ethics. It is binding, and the exam tests it through scenarios — especially around independence and confidentiality.

The seven principles — members and certification holders shall:

  • 1. Support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective governance and management of enterprise IS/IT, including audit, control, security, and risk management.
  • 2. Perform their duties with objectivity, due diligence, and professional care, in accordance with professional standards.
  • 3. Serve in the interest of stakeholders in a lawful manner, while maintaining high standards of conduct and character, and not discrediting their profession or the Association.
  • 4. Maintain the privacy and confidentiality of information obtained in the course of their activities unless disclosure is required by legal authority; such information shall not be used for personal benefit or released to inappropriate parties.
  • 5. Maintain competency in their respective fields and undertake only activities they can reasonably expect to complete with the necessary skills, knowledge, and competence.
  • 6. Inform appropriate parties of the results of work performed, disclosing all significant facts known to them that, if not disclosed, may distort the reporting of results.
  • 7. Support the professional education of stakeholders in enhancing their understanding of the governance and management of enterprise IS/IT.
🔎 In practice

Asked to help design a control you'll later audit? The Code's objectivity principle says decline and document — preserving independence outranks being helpful.

6

The Job Practice & Professional Standards

The exam is built from ISACA's Job Practice — task and knowledge statements that define what a CISA must know and do. Beneath it sits the professional-standards framework.

  • The five domains form the architecture of the whole exam; every question maps to an auditor performing a task.
  • Standards (the S-series) are mandatory minimum requirements; Guidelines (G-series) are non-mandatory elaboration; Tools & Techniques provide practical how-to.
  • The most important shift: distinguish what an auditor does (evaluate, test, document, report) from what a technician does (build, implement, manage).

The mandatory standards at a glance (S1–S16)

  • S1 Audit Charter · S2 Organizational Independence · S3 Professional Independence · S4 Reasonable Expectation
  • S5 Due Professional Care · S6 Proficiency · S7 Assertions · S8 Criteria
  • S9 Audit & Assurance Planning · S10 Supervision · S11 Materiality · S12 Using the Work of Other Experts
  • S13 Evidence · S14 Computer-Assisted Audit Techniques (CAATs) · S15 Reporting · S16 Follow-up Activities
💡 Exam TipCISA questions ask what the auditor should do, not what the system does. When two answers both look technically correct, the one reflecting the auditor's independent, risk-based perspective is almost always right.
7

The Auditor Mindset

More candidates fail on mindset than on knowledge. The CISA rewards a specific way of thinking.

  • Independence & objectivity — stay free from impairment.
  • Risk-based — focus effort where risk is highest.
  • Evidence-based — an opinion without evidence is not a finding.
  • Professional skepticism — corroborate management's assertions.
  • Report ≠ remediate — the auditor recommends; management owns the fix.
  • Common traps: the technical fix over the audit action; “implement immediately” over “evaluate and report”; the most thorough test over the most risk-appropriate one.
💡 Exam TipWhen in doubt, ask: “Is this what an auditor does, or what a systems administrator does?” The auditor evaluates, tests, documents, and reports — it does not build, implement, or manage.
8

Study Resources & Strategy

Use the workshop as your spine and supplement it with ISACA's official materials and a paced plan.

  • ISACA CISA Review Manual (CRM), the Questions, Answers & Explanations (QAE) database, the Online Review Course, and chapter/community study groups.
  • This 5-day workshop plus the 30/60/90-day study plan detailed in Lesson 9.
  • Pace practice at ~1.6 minutes per question (150 in 4 hours); use flag-and-review.
  • Always answer from the auditor's perspective, not the practitioner's.

Scored Knowledge Check

Test your orientation

Select the best answer for each question, then submit for your score and the rationale for every item — including why the tempting wrong answers fail. Answer from the auditor's perspective.

Q1.A candidate passed the CISA exam 18 months ago but has not yet submitted work-experience verification. Which BEST describes their current status?

Question 1 options
Correct: B. ISACA allows candidates up to five years after passing to submit experience verification. The designation may not be used until full certification is granted.

Q2.Management requests that an IS auditor reviewing a critical financial system assist in redesigning a key internal control as part of the same engagement. The auditor should:

Question 2 options
Correct: B. Participating in control design creates a self-review threat to independence. The auditor must decline and document the request. Recusal (C) does not restore independence that has already been compromised.

Q3.Which BEST describes the primary difference between an IS audit standard and an IS audit guideline as published by ISACA?

Question 3 options
Correct: B. ISACA standards are mandatory; guidelines are non-mandatory elaboration. Both apply to all IS auditors regardless of role type.

Q4.A candidate achieves a scaled score of 440 on the CISA exam. Which of the following is TRUE?

Question 4 options
Correct: B. The CISA passing score is 450 on the 200–800 scale. A score of 440 is a non-passing result.

Q5.An IS auditor discovers a significant control deficiency during fieldwork. Before the final report is issued, the auditee corrects the deficiency. The auditor should:

Question 5 options
Correct: B. Audit findings must be reported even when remediated before the report is issued. The report should document both the finding and the corrective action taken. Omitting it would misrepresent the control environment at the time of review.