Bonus · Faculty PD

Teaching CISA — A Faculty Professional-Development Guide

You have mastered the exam. Now teach what it means. This bonus guide is for faculty, instructional designers, and program developers who have worked Lessons 0–9 and want to translate CISA domain knowledge into curriculum — mapping every domain to courses you may already teach, using the workshop’s AI-assisted tools to build activities and assessments, and deploying anything from a single guest lecture to a full CISA-pathway certificate.

Session: Bonus — Faculty & Curriculum Use Duration: ~3 hrs self-paced Audience: Faculty & IDs Not an exam lesson

Overview

A curriculum toolkit, not an exam lesson

This is a supplementary guide, deliberately outside the numbered 5-day exam sequence. It does three things: it maps every CISA domain to courses you may already teach; it shows how to use the workshop’s AI-assisted tools to build new activities, cases, and assessments; and it gives you a deployment model — from a single guest lecture to a stackable certificate program.

ℹ️ Independence NoticeThis is an independent educational resource — not affiliated with, endorsed by, or sponsored by ISACA, and it does not confer ISACA eligibility or certification. CISA® is a registered trademark of ISACA. Align any program to ISACA’s official Job Practice and verify details at isaca.org.
Who this is for
  • Community-college faculty in IT, cybersecurity, networking, or business
  • University faculty in MIS, IS audit, IT governance, or information security
  • Workforce-development coordinators building stackable credentials
  • Instructional designers creating LMS-based cybersecurity curriculum

1 · Course Mapping

Where each domain fits your catalog

The most immediately actionable section: every lesson mapped to common courses, with a concrete instructional use.

Lesson / DomainMaps toUse it for
L0 — Orientation & auditor mindsetAny cybersecurity intro courseFirst-day framing: “we learn to evaluate controls, not just build them”
L1 — IS Auditing Process (D1)IT Audit, Cybersecurity Capstone, Internal ControlsRisk-based planning module; an audit-finding-structure assignment (criteria, condition, cause, effect, recommendation); a sampling lab
L2 — Governance of IT (D2A)IT Governance, COBIT, Corporate IT, Risk ManagementRegulatory-landscape week; a COBIT governance-vs-management lecture
L3 — Management of IT (D2B)IT Service Management, Vendor Risk, IT LeadershipSOC-report analysis; a segregation-of-duties case; a CMMI maturity lab
L4 — Acquisition & Development (D3)SDLC, Systems Analysis, Software Engineering, DevOpsAgile audit-controls module; a post-implementation-review assignment; a change-management lab
L5 — IS Operations (D4A)IT Operations, Network/Sys Admin, CloudPatch-SLA lab; a CMDB activity; an end-user-computing risk case
L6 — Business Resilience (D4B)Business Continuity, Disaster Recovery, IT RiskBIA/RTO/RPO scenario lab; a DRP-testing assessment; a supply-chain case
L7 — Protection of Info Assets (D5A)Security+, CISSP-adjacent, IAM, Network SecurityIAM recertification lab; a defense-in-depth scenario; a CSF-mapping activity
L8 — Security Event Management (D5B)Incident Response, Digital Forensics, SOC OperationsIR-lifecycle sequencing lab; an order-of-volatility forensics exercise
L9 — Final Review (capstone)Capstone course, CISA pathway, senior seminarCross-domain cases as a semester capstone; a trap-pattern exam debrief
🔎 In practice

The Hands-On Labs are already domain-tagged, so you can drop a specific lab straight into the matching unit — e.g., the Patch-SLA lab into an IT-Operations course, or the BIA→RTO/RPO gap lab into a Business-Continuity course.

2 · Cognitive Arc

How rigor escalates across the five days

Each day’s dominant Bloom level rises across the arc — useful for designing your own domain-based intensive. (These are the leading levels, not the only ones; L1 auditing already demands analysis and evaluation.)

DayDominant levelDesign implication
Day 1 (L0–L1)Remember / UnderstandExam architecture, ethics, audit standards — lecture, flashcards, conceptual scenarios
Day 2 (L2–L3)Understand / ApplyGovernance frameworks, regulation, management processes — framework analysis, compliance-gap ID, SoD scenario
Day 3 (L4–L5)Apply / AnalyzeSDLC controls, operations, change — control mapping, sprint-audit simulation, change-management lab
Day 4 (L6–L7)Analyze / EvaluateResilience gaps, control adequacy vs. effectiveness — RTO/RPO gap analysis, access-review scenario, framework-selection justification
Day 5 (L8–L9)Evaluate / CreateIR sequencing, cross-domain synthesis, study-plan design — multi-domain case, IR debrief, personal study-plan creation

Every lesson’s learning objectives in this workshop are already tagged with their Bloom level (look for the small Bloom chips), so you can lift them directly into a course syllabus.

3 · Tool Workflows

Build materials with the workshop’s AI tools

The Resources section includes seven builders. Each produces a copy-paste prompt (or a timed exam) you take into your AI platform. Three end-to-end examples:

Workflow A — a single interactive activity (~30 min)

  1. Open Generate Workshop Activities.
  2. Select the domain (e.g., D4B — Business Resilience), the mechanic (branching scenario), and the options (learner picks a recovery site → consequence branches).
  3. Copy the generated prompt into Claude, Gemini, or ChatGPT.
  4. Receive a self-contained HTML5 file; drop it into Canvas as an ungraded practice item or a graded assignment.
  5. Verify first: confirm RTO/RPO values are accurate, check that vocabulary matches ISACA terminology, and remove any institution-specific data.

Workflow B — a flipped-classroom podcast (~20 min)

  1. Open Generate Audio Files.
  2. Select the domain and sub-topic (e.g., D1 — Risk-Based Audit Planning) and generate the ~10-minute script.
  3. Record it with any tool (Audacity, a phone) or a TTS platform.
  4. Post it as pre-class listening; design class time around applying the concept rather than delivering it.

Workflow C — a capstone case study (~45 min)

  1. Open Case Study Generation.
  2. For a capstone, choose Mixed / Cross-Domain; set industry, organization size, and the challenge to foreground.
  3. Generate the case narrative with risk factors, control environment, and questions; enable the answer key, rubric, and domain mapping.
  4. Deploy in Canvas as a group discussion, individual written analysis, or oral-presentation assessment.
✅ AI verification checklist

Before any AI-generated material reaches a classroom: (1) cross-check domain terminology against ISACA’s publicly available Job Practice; (2) verify regulatory details (breach-notification windows, framework requirements) against primary sources; (3) confirm framework versions (COBIT 2019, NIST CSF 2.0, ISO/IEC 27001:2022); (4) never enter student names, institutional data, or proprietary information into AI prompts; (5) review scenarios for inadvertent technical inaccuracies.

4 · Program Design

Three deployment models

Model 1 — Single-Module Injection (1–2 sessions)

Pick one domain lesson. Assign it as pre-reading; use the knowledge check as a graded pre-discussion quiz; run the “In Practice” scenarios as small-group discussion; use the linked interactive module (Ethics & Conduct, Risk Management, Controls…) or a Hands-On Lab as the activity. Prep: 2–3 hours.

Best for: faculty adding audit-perspective content to an existing Security+, IT-governance, or systems-analysis course without redesigning it.

Model 2 — Domain-Based Module Sequence (5–8 weeks)

Map one CISA domain to one course unit. Use the corresponding lesson as the content spine; add one lab per unit; use the knowledge check as a unit quiz; assign a case (via the Case Study tool) as the unit project; use the Lesson 9 cross-domain scenarios as the final.

Best for: a dedicated IT-audit, IT-governance, or cybersecurity-management course at the community-college or university level.

Model 3 — Full CISA Pathway (2–4 courses)

Course 1: Audit Process & Governance (D1–2, L0–3) · Course 2: Acquisition, Operations & Resilience (D3–4, L4–6) · Course 3: Information-Asset Protection (D5, L7–8) · Course 4: Exam-Prep Capstone (L9 + practice exam + 30/60/90-day plan). Each course maps to a domain cluster, uses the workshop’s tools for assessment, and culminates in the Practice Exam as a summative. Because Domains 4–5 are 52% of the exam, weight course credit toward them rather than splitting evenly.

Note on eligibility: completing coursework prepares students to sit the exam (ISACA lets any candidate register). Certification additionally requires ISACA’s work-experience requirement (five years of IS-audit/control/security experience, with defined waivers) — coursework does not by itself confer eligibility. State this plainly to students.

Best for: workforce-development programs, university continuing education, or corporate L&D building a formal IS-audit track.

5 · Key Terms (Faculty Edition)

Instructional-design vocabulary

👈 The ID terms behind this guide — distinct from the exam vocabulary in Lessons 0–9. Click a card to flip.

6 · Knowledge Check

Faculty reflection (5 questions)

These are instructional-design questions — not CISA exam items. Choose the best answer, then submit for your score and the rationale for every option.

Q1.A faculty member wants to use Domain 1 content in an existing Security+ course. The MOST appropriate integration strategy is:

Select one answer
Correct: B. Single-module injection adds the audit lens to what’s already taught — the lowest-friction, highest-value integration. Why the others fall short: A discards working Security+ content; C over-loads a course not designed around the domain; D defers the value behind a whole new course that may never be built.

Q2.A faculty member generates a case study with the AI tool and wants to use it in class. Before deploying it, the FIRST step should be to:

Select one answer
Correct: B. AI output can contain subtle inaccuracies; verifying terminology and regulatory facts against primary sources is the essential first gate. Why the others fall short: A exposes students to unverified content; C is a process step, not an accuracy check; D addresses originality, not correctness.

Q3.Which Bloom’s level is BEST represented by an assessment asking students to “compare the control implications of Waterfall vs. Agile SDLC from an IS-audit perspective”?

Select one answer
Correct: C. “Compare” requires distinguishing and relating two methodologies — the hallmark of Analyze. Why the others fall short: A is recall of facts; B is using a procedure in a single situation; D would require producing something new (e.g., designing a control framework), a step beyond comparison.

Q4.A faculty member is designing a four-course CISA pathway. Domains 4 and 5 together are 52% of the exam. The MOST appropriate allocation of course credit is to:

Select one answer
Correct: C. Instructional time should track exam weight and depth — the heavier Domains 4–5 warrant more credit. Why the others fall short: A ignores the 12–26% spread across domains; B under-serves the highest-yield material; D can’t give a 52%-weighted body of content adequate depth.

Q5.A student in a Domain 4B module argues their organization’s BCP is effective because the board approved it and it’s stored in SharePoint. The BEST faculty response, grounded in the auditor mindset, is:

Select one answer
Correct: B. Adequacy (a plan exists, approved) is not effectiveness (it works) — only documented test results meeting the BIA-defined RTO/RPO demonstrate that. Why the others fall short: A conflates approval with proof of recovery; C a review confirms the plan is current, not that recovery works; D where the file lives says nothing about whether the organization can actually recover.

7 · Resources

Tools & further reading

ToolFaculty use
Generate Workshop ActivitiesBuild interactive HTML5 labs for any domain
Generate Audio FilesCreate flipped-classroom pre-class podcasts
Case Study GenerationBuild cross-domain capstone cases with answer keys
Graphics GenerationGenerate process flows and governance diagrams for slides
Content GenerationDraft lesson text, discussion prompts, and quiz items
Hands-On LabsAssign domain-tagged scenario labs as graded or self-study work
CISA Practice ExamUse as a summative assessment in pathway courses

External references for course alignment

← Return to Workshop Home