1
Domain 1 — IS Auditing Process (18%)
Core principle: the IS auditor plans based on risk, executes with independence and professional skepticism, and reports evidence-backed findings. Domain 1 is the methodology applied to every other domain.
- Independence threats and responses (disclose & reassign).
- Risk-based planning prioritizes the highest residual risk.
- Sampling: statistical vs. judgmental; beta risk (over-reliance) is the dangerous error.
- CAATs: remove test data from production after testing.
- CRAF finding structure; escalate fraud/critical/regulatory immediately; workpapers must support conclusions.
2
Domain 2 — Governance & Management of IT (18%)
Core principle: governance aligns IT with strategy; management executes it; the auditor evaluates both from the independent third line.
- COBIT 2019: governance (EDM) vs. management distinction.
- Three Lines Model: the auditor is the third line — does not own or manage risk.
- Regulations: SOX 404, GDPR 72-hour breach notice, PCI DSS.
- Risk responses: accept, mitigate, transfer, avoid. Data classification: owner classifies, custodian protects.
- Vendor management: right-to-audit clause, CUECs, SOC 2 Type II; policy hierarchy.
3
Domain 3 — Acquisition, Development & Implementation (12%)
Core principle: controls must be designed into systems from the beginning. Post-implementation fixes cost more and protect less.
- The auditor advises on controls; it does not make design decisions.
- Feasibility dimensions; SDLC phase-gate controls; Agile keeps security in the backlog.
- Change management: no change without authorization; emergency changes need post-review.
- Data migration: reconciliation is mandatory; variance requires a documented explanation.
- Post-implementation review verifies benefits realization 3–6 months after go-live.
4
Domain 4 — IS Operations & Business Resilience (26%)
Core principle: operations must be reliable, controlled, and recoverable. When things go wrong, business resilience ensures survival.
Operations
- Patch management: SLA by severity; test before production; track compliance.
- Developer access to production = SoD violation. DBA access: logged and independently reviewed.
- Shadow IT and EUC need inventory, controls, validation. Incident (restore) vs. problem (root cause). Logs: tamper-proof, retained, reviewed.
Business resilience
- The BIA drives everything: RTO/RPO come from business requirements.
- BCP scope is broader than DRP (people, facilities, communications). Backup never tested = not effective.
- DRP tested RTO must meet BIA-defined RTO; an undocumented test = no test; nightly backups cannot meet a 1-hour RPO.
5
Domain 5 — Protection of Information Assets (26%)
Core principle: information assets require layered protection — people, processes, and technology — and rapid, evidence-based response when incidents occur.
- Access reviews: performed by business managers, not IT. MFA for privileged and remote access.
- Key management: keys stored separately from encrypted data. DLP coverage: network + endpoint + cloud.
- Physical security: defense in depth. Cloud: shared-responsibility model defines who controls what.
- Incident response sequence: contain before eradicate; first responder isolates the segment rather than shutting down (preserve volatile evidence).
- Forensics: work on forensic copies, chain of custody, order of volatility. Recurring pen-test findings = a remediation failure.
6
Cross-Domain Audit Scenarios
The hardest exam questions span multiple domains. The skill is to separate the governance root cause from the operational and security symptoms, and to follow the risk wherever it leads.
Scenario 1 — The Cloud Migration
- A CRM moved to SaaS 8 months ago; no SOC 2 report; no right-to-audit clause; users access it from personal devices without MDM.
- D2 governance: vendor risk not independently verifiable. D4 operations: shadow-IT (personal devices). D5 security: no encryption, remote wipe, or DLP. D2 privacy: vendor processing without processor controls.
- Insight: name the governance root cause (D2) and the operational/security symptoms (D4/D5) separately in the report.
Scenario 2 — The Emergency Change
- A critical zero-day patch is applied directly to production — no change request, no testing, no CAB — and the system stays stable.
- D4 change management: no documented emergency process. D3 release: no testing before deployment. D1 process: no documented procedures.
- Insight: outcome does not validate a bypassed process. The finding stands even though the change worked — the risk was accepted without being assessed.
Scenario 3 — The Discovered Spreadsheet
- A 6-year-old revenue-recognition spreadsheet: 47 linked sheets, multiple versions, no access controls, no change log, maintained by one analyst — who just resigned.
- D4 EUC/shadow IT: a critical process in an uncontrolled tool. D4 operations: key-person single point of failure. D2 data governance: financial data outside controls. D3: no SDLC for a material financial process.
- Insight: a classic “follow the risk wherever it leads” exercise.
7
The 30/60/90-Day Study Plan
Anchor your preparation to your Lesson 8 gap analysis — spend the most time on the sub-areas you scored 1–2.
🔎 In practiceWeight your gaps by domain size. A 65% in Domain 4 or 5 (26% each) costs far more raw marks than a 65% in Domain 3 (12%). When you review practice results, fix the heavy domains first — the practice exam's domain-by-domain breakdown is built for exactly this.
Days 1–30 — Foundation & volume
- Begin the CISA Review Manual (current edition); complete 50+ QAE questions per domain; prioritize by your gap analysis; ramp to 30–40 questions/day.
- Checkpoint: CRM Domains 1–3 done; 500+ practice questions; D1 & D2 above 70%; exam scheduled.
Days 31–60 — Deep dive & weak areas
- Complete Domains 4 & 5 (52% of the exam); re-read any sub-area below 65%; take your first full 150-question timed exam and review every wrong answer by domain and error type (knowledge gap vs. trap vs. misread).
- Checkpoint: CRM complete; 1,000+ questions; consistent 70%+ on domain quizzes; first full exam reviewed.
Days 61–90 — Readiness
- Second full timed exam; final reading on the highest-frequency topics (patch management, BIA/DRP alignment, IAM controls, audit independence, sampling); review ISACA standards S1–S16; re-review the trap patterns; a 50-question exam daily for the last 5 days.
- Checkpoint: 1,500+ questions; consistent 75%+ on full exams; exam confirmed; logistics set.
8
Exam-Day Logistics & Time Management
Logistics checklist
- Confirm the appointment (PSI/ISACA portal); photo ID matches your registered name exactly; secondary ID if required.
- Know the route and plan for travel time plus a 30-minute buffer.
- 7–8 hours of sleep (don't cram past 10 PM); a proper meal; moderate caffeine; comfortable, layered clothing.
Time management
- 150 questions / 4 hours ≈ 1.6 minutes per question.
- First pass: answer everything you're confident about; flag the uncertain ones. Second pass: review flagged questions; use process of elimination.
- Never leave a question blank — there is no penalty for guessing. Target the first pass in 3 hours; keep the final hour for review. At the 2-hour mark, be at or past question 75.
9
The Auditor Mindset — Final Reminder
Before every question, apply the three-second filter:
- “Is this what an auditor does — or a technician?” If it sounds like building or fixing something, it's probably wrong.
- “What is the PRIMARY concern?” Questions often have two “correct” answers; one is more root-cause or more consequential.
- “Does this protect the organization — or just fix the symptom?” Root-cause findings and governance-level recommendations beat tactical fixes.
- Don't change answers without a specific, logical reason — first instinct is usually right. Don't let one hard question spiral; every question is independent.
🔎 In practiceEvery question on the exam is really asking one of three things: What would a competent IS auditor DO? What is the MOST significant risk or finding? Which control BEST addresses this specific risk? The CISA is a test of judgment, not memorization — and you have spent five days sharpening exactly that.
10
Resources for Further Study
Official ISACA resources
| Resource | Description |
| CISA Review Manual | The official comprehensive study guide, aligned to the current job practice (isaca.org). |
| QAE Database | Question, Answer & Explanation database — the single best scenario-based practice-question resource, with full rationale. |
| Online Review Course | Structured, self-paced course across all five domains, with videos, questions, and flashcards. |
| ISACA Community | Peer forum for study groups, question discussion, and exam experiences (isaca.org/community). |
Supplementary references
| Resource | Description |
| COBIT 2019 | Free at isaca.org — especially the Design and Implementation Guides. |
| NIST SP 800-53 Rev. 5 | Free control catalog; excellent for Domain 5 control knowledge. |
| NIST SP 800-61 Rev. 2 | Computer Security Incident Handling Guide — essential for Domain 5B. Rev. 3 (finalized 2025) reframes IR around risk management; the exam still aligns to Rev. 2. |
| NIST SP 800-88 Rev. 1 | Guidelines for Media Sanitization — Domain 4 and 5 reference. |
| ISO/IEC 27001:2022 | Information Security Management Systems standard (purchase from ISO). |
| ITIL 4 | IT service management framework — relevant to Domain 4 operations. |
The CISA is not a test of technical memorization. It is a test of professional judgment — the judgment of an independent, risk-based, evidence-driven information systems auditor. You have covered every domain, every sub-topic, and every major framework this exam tests. Walk in knowing the work is done.