Certified Information Systems Auditor (CISA) Exam Guide
The Certified Information Systems Auditor (CISA) exam validates knowledge and ability in auditing, monitoring and assessing IT and business systems across five job-practice domains. It serves professionals working in information systems audit, control, assurance or security, while the exam itself is open to anyone interested in information security. This guide helps you decide whether to schedule now, what experience and certification steps to verify first, and how to turn the official outline into a focused study plan.
What the CISA exam validates
CISA tests whether you can apply information-systems audit, governance, acquisition, operations, resilience and information-asset protection knowledge to realistic professional situations. It is not simply a terminology test: the official outline describes questions as testing knowledge and ability on real-life job practices leveraged by expert professionals.
ISACA describes CISA as validating expertise in auditing, monitoring and assessing IT and business systems. That purpose makes the credential relevant to people who must evaluate whether technology supports business objectives, whether risks are controlled, and whether evidence supports an audit conclusion.
The exam content outline says its domains, subtopics and tasks result from research, feedback and validation by subject-matter experts and industry leaders worldwide. Use that outline as the boundary of your preparation. A study resource may explain a topic well, but it should not replace checking whether the topic maps to an official domain or task.
The certification is aimed most directly at information-systems auditors and professionals in control, assurance or security roles. It can also serve candidates moving into IT audit from adjacent technology, risk, compliance or internal-audit work. However, career fit and certification eligibility are separate decisions: work experience is not required to sit for the exam, while certification requires experience and other post-exam steps.
Who should take it, and who should wait
You can sit for the CISA exam without first accumulating the experience required for certification, but candidates should distinguish exam access from designation eligibility. Before paying, decide whether you are preparing for an immediate certification application or building knowledge toward a later career move.
The exam is open to anyone interested in information security, and work experience is not required to sit for it. To become CISA-certified, however, ISACA states that candidates need at least five years of professional information-systems auditing, control, assurance or security experience, as described in the CISA job-practice areas.
Education and other approved qualifications may substitute for some, but not all, of the work-experience requirement. Review the current requirements directly rather than assuming a degree, general IT employment or a security course will satisfy the entire requirement. Qualifying work experience generally must have been obtained within the 10-year period preceding the certification application.
Waiting is sensible when you cannot explain how your experience maps to the job-practice areas, have not reviewed the current outline, or cannot protect a consistent study schedule. Sitting sooner may make sense when you are using the exam to structure a transition into audit and understand that passing alone does not grant the designation.
Use the official requirements page to document your likely experience categories before registration: https://support.isaca.org/s/article/What-are-the-requirements-to-become-CISA-certified. Then compare your record with ISACA’s certification instructions at https://www.isaca.org/credentialing/cisa/get-cisa-certified.
How the exam is organized
The CISA examination contains 150 questions covering five job-practice domains. The official outline identifies the domains as Information Systems Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development and Implementation; Information Systems Operations and Business Resilience; and Protection of Information Assets.
The published outline assigns 18% to Domain 1, Information Systems Auditing Process. That domain concerns providing industry-standard audit services to help organizations protect and control information systems, including reaching conclusions about an organization’s security, risk and control solutions.
Do not treat the domain labels as isolated subjects. An audit conclusion may depend on governance, operational evidence and the effectiveness of information-asset controls. Study the boundaries first, then practise connecting an audit objective to risk, control design, evidence, testing and communication.
The available research does not provide verified percentages for every domain in this article’s source set. Do not fill those gaps with unofficial charts or assume that an unlabelled percentage describes a particular subject. For planning, use all five official domains and give extra diagnostic attention to areas where your baseline performance is weak.
The exam content outline is the controlling reference for current domain scope: https://www.isaca.org/credentialing/cisa/cisa-exam-content-outline.
What to learn in each domain
Start with the task language in the official outline, not with a random list of technologies. For every domain, ask what an auditor must evaluate, what evidence would support a conclusion, which risk is being addressed, and how the result should be communicated or followed up.
Domain 1, Information Systems Auditing Process, is the largest specifically verified domain in the supplied outline at 18%. Build a complete audit cycle here: understand the engagement context, establish objectives and scope, assess risk, plan procedures, gather and evaluate evidence, form conclusions, report results and monitor follow-up. The outline specifically includes communicating and collecting feedback on audit progress, findings, results and recommendations with stakeholders.
Domain 2, Governance and Management of IT, requires a business-oriented view of technology oversight. Study how governance and management decisions establish direction, accountability, risk treatment and resource priorities. When reviewing a scenario, identify who owns the decision, what objective it supports, and whether performance or risk information is sufficient for oversight.
Domain 3, Information Systems Acquisition, Development and Implementation, calls for disciplined review of how systems are selected, built, changed and placed into service. Prepare to reason about requirements, project governance, controls through the development life cycle, testing, implementation approval, data conversion and post-implementation evaluation. Focus on the auditor’s evaluation role rather than memorizing a vendor’s product features.
Domain 4, Information Systems Operations and Business Resilience, covers the controls and practices that keep services reliable and support recovery when disruption occurs. Organize study around operations management, service delivery, continuity, disaster recovery, resilience objectives, backup and restoration evidence, and the relationship between business requirements and technology recovery arrangements.
Domain 5, Protection of Information Assets, asks you to evaluate safeguards for information and the environments in which it is processed. ISACA specifically identifies evaluating logical, physical and environmental controls to verify confidentiality, integrity and availability. Study how control selection, access management, monitoring, incident handling and physical protection address those three security objectives.
For each domain, create a one-page map with four columns: official task, risk addressed, evidence an auditor would inspect, and the most defensible next action. This converts passive reading into professional reasoning and exposes topics that you can name but cannot apply.
How to read CISA scenario questions
The strongest preparation method is to practise choosing the auditor’s best action, not merely recognizing a technically correct action. In a scenario, identify the audit objective, the risk, the control or evidence described, and the question’s decision point before looking at the answer choices.
CISA-style professional reasoning often turns on priority, independence, sufficiency of evidence, business impact or the distinction between a preventive and detective control. Several choices may sound reasonable in isolation. Prefer the choice that directly addresses the stated objective and fits the auditor’s responsibility at that stage of the engagement.
Use this sequence when studying a question: first state what the question asks; next underline qualifiers such as primary, best, first or most important; then identify the affected domain; finally eliminate options that skip a necessary audit step, assume evidence that was not provided, or jump to remediation before establishing the condition.
After answering, explain why each rejected option is weaker. If you cannot do that, record the question as unresolved rather than counting a guess as mastery. Your error log should capture the tested concept, your reasoning error, the correct decision rule and a short example of when the rule would not apply.
Avoid memorizing the wording of practice items. Unofficial question banks can become outdated or may not reflect the current outline, and memorization does not demonstrate the judgement the exam is intended to assess. Use legitimate practice material to expose gaps, then return to the official domain task and learn the underlying principle.
A study sequence that works with limited time
Study in passes: map the outline, build domain understanding, practise application, then simulate decision-making under exam conditions. This sequence prevents a common failure mode—spending weeks reading reference material without discovering that you misinterpret scenario priorities.
Pass one: download the current exam content outline and mark every domain, subtopic and task as familiar, partly familiar or unfamiliar. Add your work context beside each item. For example, someone who has performed access reviews may still need deliberate study of audit planning, evidence evaluation and reporting.
Pass two: study Domain 1 first because it is the only domain for which the supplied facts provide a verified 18% weight, and because audit process concepts connect naturally to the other domains. Then rotate through Domains 2 through 5. For each topic, write a short explanation in your own words and attach it to an audit decision or piece of evidence.
Pass three: practise mixed questions after each domain rather than waiting until the end. Review every answer, including correct answers reached by uncertain reasoning. Separate knowledge gaps from reading errors and from decision errors. Each category needs a different remedy: reference reading, careful question parsing or a clearer professional rule.
Pass four: use timed mixed practice only after you can explain the concepts without notes. Simulations should test concentration, prioritization and review discipline, not encourage rushed guessing. Finish each session by selecting a small number of weak topics for targeted review instead of rereading the entire manual.
A practical weekly rhythm is three study blocks for new material, two shorter blocks for recall and question review, and one mixed session. Adjust that pattern to your work and family commitments. The important decision is to reserve time for review of mistakes; completing more questions without analysis produces a misleading sense of progress.
A practical six-stage roadmap
A roadmap should end with a scheduling decision and a certification checklist, not just a completed textbook. Move forward when your evidence shows that you can explain the domains, apply audit priorities and manage the administrative steps without relying on assumptions.
Stage one—confirm the target. Read the current content outline, review the candidate guide and identify the experience path you expect to use for certification. Decide whether your target is exam completion now, certification application after passing, or foundational preparation before entering the field.
Stage two—establish a baseline. Attempt a small mixed set from a legitimate preparation source, including the official free quiz if useful, and categorize errors by domain and reasoning type. Do not use a baseline percentage as a claimed prediction of your exam score; use it to choose study order.
Stage three—build the audit-process foundation. Study Domain 1 end to end, then practise translating objectives into risks, controls, evidence and conclusions. Pay particular attention to stakeholder communication and follow-up, because audit work is not complete when testing ends.
Stage four—cover the technology lifecycle. Study governance and management, acquisition and implementation, operations and resilience, and protection of information assets. Link each topic to an audit procedure. Ask what could go wrong, what control should exist, how you would test it and what a finding would need to show.
Stage five—integrate and diagnose. Use mixed-domain practice and maintain an error log. Revisit the official task wording whenever a question feels ambiguous. Your readiness signal should be consistent reasoning across domains, not recognition of familiar item wording.
Stage six—schedule and preserve the post-exam plan. Register and pay before scheduling; ISACA says CISA registration and payment are required before you can schedule and take the exam. After passing, complete the application process within the allowed period and prepare for continuing professional education and maintenance obligations.
Registration, eligibility and scheduling decisions
Treat registration as an administrative commitment with a deadline, not as the first study activity. Verify eligibility, payment, appointment availability and your own preparation window before selecting a date, because the eligibility period and appointment rules affect how much flexibility you have.
Upon registration, CISA exam candidates have a six-month eligibility period to take their exam. CISA exam appointments are only available 90 days in advance, so a desired date may not appear immediately even when you are eligible. If a site or date is unavailable more than 90 days ahead, ISACA advises checking again closer to the desired date.
Candidates can schedule a testing appointment as early as 48 hours after payment of exam registration fees. Scheduling is accessed through the ISACA Account under Certification & CPE Management and then through the PSI dashboard. The official page also describes authorized PSI testing centers globally and remotely proctored exams.
Confirm the delivery option and technical or site requirements in the current candidate and scheduling guides before committing. Availability is not the same as eligibility, and a convenient date is not automatically a sensible date. Leave enough study time to complete mixed practice and investigate any accommodation needs before the appointment.
If you need to reschedule, ISACA states that you may do so during the eligibility period without penalty when you act at least 48 hours before the scheduled testing appointment. Keep the eligibility expiry date visible in your calendar and do not assume a late change will be free or permitted.
Use the official CISA page for current registration and scheduling instructions: https://www.isaca.org/credentialing/cisa. The candidate guides, which cover registration, scheduling, preparation, exam rules, administration, scoring and retake policy, are listed at https://www.isaca.org/credentialing/exam-candidate-guides.
Delivery, language and score information
The verified delivery information supports computer-based testing through authorized PSI testing centers globally or remotely proctored exams. Before choosing, compare your workspace, equipment and connectivity with the current official requirements; do not infer that every appointment type is available in every location.
The CISA exam uses a scaled score range of 200–800, with 450 as the passing score. A scaled score is not a percentage correct, so avoid converting practice percentages into a promised exam result. Use practice performance for diagnosis and use the official scoring explanation for interpretation.
ISACA provides CISA exam candidate guides in English, Chinese Simplified, French, German, Japanese, Korean and Spanish. ISACA says its CISA review manuals and Questions, Answers & Explanations Database are available in English, French, German, Japanese and Spanish. Check the current availability of the specific resource you intend to buy or use.
Do not select a language solely because a study resource is available in it. Choose the language in which you can interpret qualifiers, audit terminology and scenario relationships precisely. If you study in one language and test in another, maintain a glossary of terms that commonly cause ambiguity and verify the official translations where available.
The detailed scoring explanation is available from ISACA Support: https://support.isaca.org/s/article/Exams-How-is-my-Certification-exam-scored-detailed-version. Language information is available at https://support.isaca.org/s/article/What-languages-are-study-materials-available-in-1597877235837.
Which preparation resources to use
Use one current primary reference aligned to the official outline, one source of legitimate practice questions, and the official candidate guidance. More resources are not automatically better; too many competing explanations can create terminology conflicts and leave no time for reviewing mistakes.
ISACA lists a CISA Review Manual, Questions, Answers & Explanations Database, online review instruction and other preparation resources. Check the edition and scope against the current exam content outline before purchasing or relying on any material. A resource labelled with an older year should not be assumed to represent the current exam.
The official content outline is the anchor for every study resource. If a book expands a topic beyond the outline, treat the extra material as background. If a question bank emphasizes a topic that you cannot locate in the official outline, investigate rather than allowing that emphasis to dictate your entire study plan.
The supplied official language guidance confirms availability of ISACA review manuals and its Questions, Answers & Explanations Database in English, French, German, Japanese and Spanish. Candidates needing another language should check the current official catalogue and candidate guidance rather than assuming a translated version exists.
Avoid exam dumps, leaked questions and promises based on memorization. They do not establish competence, may be unauthorized or inaccurate, and can leave you unable to reason through a new scenario. Build your own explanations from the domain tasks and use practice questions to test understanding, not to reconstruct a supposed live exam.
Common preparation mistakes
Most avoidable mistakes are planning errors: studying technologies instead of audit decisions, treating every domain as a separate silo, ignoring administrative deadlines and confusing a passing exam with the completed CISA certification process.
Mistake one is reading without retrieval. After each topic, close the material and explain the risk, control, evidence and auditor action from memory. If the explanation is vague, return to the source and rewrite it in operational language.
Mistake two is overfitting to one job role. Your professional experience may make access control, project work or operations feel familiar, but the exam spans five domains. Use your experience as an anchor, not as proof that adjacent governance, assurance or resilience topics need no study.
Mistake three is choosing the most technical answer. CISA questions may present technical details, but the best response is often the one that preserves audit objectives, evidence quality, governance accountability or business alignment. Read the question’s role and timing before selecting a control implementation detail.
Mistake four is postponing mixed practice. Domain-by-domain scores can conceal confusion between similar concepts. Introduce mixed review once you have a foundation, and record whether an error came from the domain, the question qualifier or the decision sequence.
Mistake five is scheduling at the end of the eligibility period without checking availability. Registration creates a six-month eligibility period, while appointments are available only 90 days in advance. Check the official scheduling information early enough to make a realistic plan.
Mistake six is forgetting the application. Passing the exam is one requirement. ISACA also lists the application processing fee, experience demonstration, Code of Professional Ethics, Continuing Professional Education Policy and compliance with Information Systems Auditing Standards among the certification requirements.
How to know you are ready to schedule
Schedule when your preparation evidence shows stable reasoning across the outline and your administrative position is clear. Do not wait for a feeling of total certainty, but do not use payment or a calendar date as a substitute for a readiness check.
Before scheduling, confirm that you can summarize the purpose and tasks of each of the five domains without notes; explain the audit lifecycle from planning through follow-up; distinguish risk, control, evidence, finding and recommendation; and justify why a chosen answer is better than plausible alternatives.
Run several mixed review sessions using legitimate material and review every uncertain response. Look for repeated error patterns rather than a single impressive result. If the same domain or reasoning error recurs, delay the appointment long enough to address that specific weakness, provided your eligibility period allows it.
Make a short final-review list: terms you confuse, task sequences you reverse, governance responsibilities you mix up and any domain that you have studied only through memorization. The list should be small enough to revisit repeatedly. Do not begin a new reference source in the final phase unless the official outline reveals a genuine gap.
Check practical readiness separately: registration and payment status, eligibility expiry, appointment location or remote requirements, language choice, identification and any accommodation process described by the official guides. These checks do not improve knowledge, but they prevent avoidable administrative surprises.
What happens after passing
Passing the exam starts the certification process rather than ending it. Apply within the permitted period, document qualifying experience and maintain the designation through annual fees, ethics and standards compliance, and continuing professional education.
ISACA states that candidates have five years from the passing date to apply for CISA certification. The application requires demonstrating experience, paying the one-time US$50 application processing fee, adhering to the Code of Professional Ethics, following the Continuing Professional Education Policy and complying with the Information Systems Auditing Standards.
Keep evidence for the experience application organized before you pass. Record employer, role, dates, responsibilities and how the work aligns with information-systems auditing, control, assurance or security. This is a practical recommendation for reducing later reconstruction effort; the official requirements page remains the authority on what documentation is accepted.
To maintain CISA, ISACA requires reporting at least 20 CPE hours annually and 120 CPE hours during a three-year reporting period. The annual maintenance fee is US$45 for ISACA members or US$85 for non-members. Fees and reporting obligations should be checked in the current maintenance policy before renewal.
Retain supporting CPE documentation for 12 months following the end of each three-year reporting cycle. ISACA may select individuals for a CPE audit, in which case supporting documentation for reported activities from a specified calendar year must be provided. Record each activity as you complete it instead of trying to reconstruct the cycle later.
The certification steps are described at https://www.isaca.org/credentialing/cisa/get-cisa-certified, and maintenance requirements are available at https://www.isaca.org/credentialing/cisa/maintain-cisa-certification.
Your next actions
Begin with verification, then study. The fastest useful next step is not buying another question bank; it is comparing your experience, target date and current knowledge with the official outline and candidate instructions.
Today, download or review the current CISA exam content outline and mark the five domains by confidence. Give Domain 1, Information Systems Auditing Process, deliberate attention because the supplied official outline assigns it 18%, then identify gaps across the remaining four domains without assuming their weights.
Next, decide whether you are pursuing only the exam or the full designation. If certification is the goal, review the five-year experience requirement, possible approved substitutions and the five-year post-passing application window. Keep those requirements separate from the fact that work experience is not required to sit for the exam.
Choose a primary official or current aligned study resource, set a recurring study schedule and create an error log before answering practice questions. Book only after checking the six-month eligibility period, PSI availability, the 90-day appointment window and the current delivery requirements.
After passing, submit the certification application within the permitted period and start a CPE record immediately. That simple habit connects the exam decision to the continuing obligations of holding the designation rather than treating certification as a one-time event.
Conclusion
CISA preparation is most effective when it mirrors the work the credential is intended to validate: define the objective, assess the risk, examine evidence, make a defensible conclusion and communicate the result. Use the official content outline to control scope, use practice questions to diagnose reasoning, and verify registration, scheduling and certification requirements directly with ISACA. Once your domain map, study schedule and experience plan are clear, you can make a deliberate decision about when to schedule rather than relying on an unsupported readiness promise.