Overview
A curriculum toolkit, not an exam lesson
This is a supplementary guide, deliberately outside the numbered 5-day exam sequence. It does three things: it maps every CISA domain to courses you may already teach; it shows how to use the workshop’s AI-assisted tools to build new activities, cases, and assessments; and it gives you a deployment model — from a single guest lecture to a stackable certificate program.
- Community-college faculty in IT, cybersecurity, networking, or business
- University faculty in MIS, IS audit, IT governance, or information security
- Workforce-development coordinators building stackable credentials
- Instructional designers creating LMS-based cybersecurity curriculum
- Map CISA domains and lessons to existing courses and program units. Bloom: Analyze
- Apply the workshop’s AI tools to build activities, cases, graphics, and content. Bloom: Apply
- Design a deployment model — single module, semester sequence, or certificate. Bloom: Create
- Evaluate AI-generated materials for accuracy before classroom use. Bloom: Evaluate
1 · Course Mapping
Where each domain fits your catalog
The most immediately actionable section: every lesson mapped to common courses, with a concrete instructional use.
| Lesson / Domain | Maps to | Use it for |
|---|---|---|
| L0 — Orientation & auditor mindset | Any cybersecurity intro course | First-day framing: “we learn to evaluate controls, not just build them” |
| L1 — IS Auditing Process (D1) | IT Audit, Cybersecurity Capstone, Internal Controls | Risk-based planning module; an audit-finding-structure assignment (criteria, condition, cause, effect, recommendation); a sampling lab |
| L2 — Governance of IT (D2A) | IT Governance, COBIT, Corporate IT, Risk Management | Regulatory-landscape week; a COBIT governance-vs-management lecture |
| L3 — Management of IT (D2B) | IT Service Management, Vendor Risk, IT Leadership | SOC-report analysis; a segregation-of-duties case; a CMMI maturity lab |
| L4 — Acquisition & Development (D3) | SDLC, Systems Analysis, Software Engineering, DevOps | Agile audit-controls module; a post-implementation-review assignment; a change-management lab |
| L5 — IS Operations (D4A) | IT Operations, Network/Sys Admin, Cloud | Patch-SLA lab; a CMDB activity; an end-user-computing risk case |
| L6 — Business Resilience (D4B) | Business Continuity, Disaster Recovery, IT Risk | BIA/RTO/RPO scenario lab; a DRP-testing assessment; a supply-chain case |
| L7 — Protection of Info Assets (D5A) | Security+, CISSP-adjacent, IAM, Network Security | IAM recertification lab; a defense-in-depth scenario; a CSF-mapping activity |
| L8 — Security Event Management (D5B) | Incident Response, Digital Forensics, SOC Operations | IR-lifecycle sequencing lab; an order-of-volatility forensics exercise |
| L9 — Final Review (capstone) | Capstone course, CISA pathway, senior seminar | Cross-domain cases as a semester capstone; a trap-pattern exam debrief |
The Hands-On Labs are already domain-tagged, so you can drop a specific lab straight into the matching unit — e.g., the Patch-SLA lab into an IT-Operations course, or the BIA→RTO/RPO gap lab into a Business-Continuity course.
2 · Cognitive Arc
How rigor escalates across the five days
Each day’s dominant Bloom level rises across the arc — useful for designing your own domain-based intensive. (These are the leading levels, not the only ones; L1 auditing already demands analysis and evaluation.)
| Day | Dominant level | Design implication |
|---|---|---|
| Day 1 (L0–L1) | Remember / Understand | Exam architecture, ethics, audit standards — lecture, flashcards, conceptual scenarios |
| Day 2 (L2–L3) | Understand / Apply | Governance frameworks, regulation, management processes — framework analysis, compliance-gap ID, SoD scenario |
| Day 3 (L4–L5) | Apply / Analyze | SDLC controls, operations, change — control mapping, sprint-audit simulation, change-management lab |
| Day 4 (L6–L7) | Analyze / Evaluate | Resilience gaps, control adequacy vs. effectiveness — RTO/RPO gap analysis, access-review scenario, framework-selection justification |
| Day 5 (L8–L9) | Evaluate / Create | IR sequencing, cross-domain synthesis, study-plan design — multi-domain case, IR debrief, personal study-plan creation |
Every lesson’s learning objectives in this workshop are already tagged with their Bloom level (look for the small Bloom chips), so you can lift them directly into a course syllabus.
3 · Tool Workflows
Build materials with the workshop’s AI tools
The Resources section includes seven builders. Each produces a copy-paste prompt (or a timed exam) you take into your AI platform. Three end-to-end examples:
Workflow A — a single interactive activity (~30 min)
- Open Generate Workshop Activities.
- Select the domain (e.g., D4B — Business Resilience), the mechanic (branching scenario), and the options (learner picks a recovery site → consequence branches).
- Copy the generated prompt into Claude, Gemini, or ChatGPT.
- Receive a self-contained HTML5 file; drop it into Canvas as an ungraded practice item or a graded assignment.
- Verify first: confirm RTO/RPO values are accurate, check that vocabulary matches ISACA terminology, and remove any institution-specific data.
Workflow B — a flipped-classroom podcast (~20 min)
- Open Generate Audio Files.
- Select the domain and sub-topic (e.g., D1 — Risk-Based Audit Planning) and generate the ~10-minute script.
- Record it with any tool (Audacity, a phone) or a TTS platform.
- Post it as pre-class listening; design class time around applying the concept rather than delivering it.
Workflow C — a capstone case study (~45 min)
- Open Case Study Generation.
- For a capstone, choose Mixed / Cross-Domain; set industry, organization size, and the challenge to foreground.
- Generate the case narrative with risk factors, control environment, and questions; enable the answer key, rubric, and domain mapping.
- Deploy in Canvas as a group discussion, individual written analysis, or oral-presentation assessment.
Before any AI-generated material reaches a classroom: (1) cross-check domain terminology against ISACA’s publicly available Job Practice; (2) verify regulatory details (breach-notification windows, framework requirements) against primary sources; (3) confirm framework versions (COBIT 2019, NIST CSF 2.0, ISO/IEC 27001:2022); (4) never enter student names, institutional data, or proprietary information into AI prompts; (5) review scenarios for inadvertent technical inaccuracies.
4 · Program Design
Three deployment models
Model 1 — Single-Module Injection (1–2 sessions)
Pick one domain lesson. Assign it as pre-reading; use the knowledge check as a graded pre-discussion quiz; run the “In Practice” scenarios as small-group discussion; use the linked interactive module (Ethics & Conduct, Risk Management, Controls…) or a Hands-On Lab as the activity. Prep: 2–3 hours.
Model 2 — Domain-Based Module Sequence (5–8 weeks)
Map one CISA domain to one course unit. Use the corresponding lesson as the content spine; add one lab per unit; use the knowledge check as a unit quiz; assign a case (via the Case Study tool) as the unit project; use the Lesson 9 cross-domain scenarios as the final.
Model 3 — Full CISA Pathway (2–4 courses)
Course 1: Audit Process & Governance (D1–2, L0–3) · Course 2: Acquisition, Operations & Resilience (D3–4, L4–6) · Course 3: Information-Asset Protection (D5, L7–8) · Course 4: Exam-Prep Capstone (L9 + practice exam + 30/60/90-day plan). Each course maps to a domain cluster, uses the workshop’s tools for assessment, and culminates in the Practice Exam as a summative. Because Domains 4–5 are 52% of the exam, weight course credit toward them rather than splitting evenly.
5 · Key Terms (Faculty Edition)
Instructional-design vocabulary
👈 The ID terms behind this guide — distinct from the exam vocabulary in Lessons 0–9. Click a card to flip.
6 · Knowledge Check
Faculty reflection (5 questions)
These are instructional-design questions — not CISA exam items. Choose the best answer, then submit for your score and the rationale for every option.
7 · Resources
Tools & further reading
| Tool | Faculty use |
|---|---|
| Generate Workshop Activities | Build interactive HTML5 labs for any domain |
| Generate Audio Files | Create flipped-classroom pre-class podcasts |
| Case Study Generation | Build cross-domain capstone cases with answer keys |
| Graphics Generation | Generate process flows and governance diagrams for slides |
| Content Generation | Draft lesson text, discussion prompts, and quiz items |
| Hands-On Labs | Assign domain-tagged scenario labs as graded or self-study work |
| CISA Practice Exam | Use as a summative assessment in pathway courses |
External references for course alignment
- ISACA CISA Job Practice (isaca.org) — the official blueprint; align all course outcomes to it and verify currency.
- NIST NICE Cybersecurity Workforce Framework — maps CISA-adjacent skills to workforce roles.
- ACM/IEEE Computing Curricula — for aligning content to CS/IS degree programs.
- AACC Workforce-Development resources — for certificate-program and stackable-credential design.