ISACA CISA Study Guide: Five Audit Domains and Study Plan

Prepare for ISACA CISA with the five current exam domains, weights, exam format, experience requirements, and practical audit-focused study guidance.

ISACA CISA (Certified Information Systems Auditor) is for professionals working in information systems audit, control, assurance, or security. The exam focuses on evaluating whether IT governance, system life cycles, operational resilience, and information asset protection support business objectives, and whether conclusions are supported by evidence.

This guide follows the current ISACA CISA exam outline. Confirm that your study material uses the current five domains and weights.

Who is this exam for?

CISA suits IT auditors, internal auditors, risk and control professionals, information security staff, and others who assess system governance and control effectiveness. You may take the exam before meeting the experience requirement, but full certification requires a qualifying work experience application.

Exam format and experience requirement

The CISA exam has 150 multiple-choice questions and lasts four hours. ISACA reports scores on a 200–800 scale; 450 or higher is passing. Passing the exam alone does not grant certification.

Certification generally requires at least five years of professional information systems audit, control, assurance, or security experience gained within the ten years before application, in work described by the CISA job practice areas. ISACA allows experience waivers of up to three years under specified categories. Check official certification requirements for eligible experience and documentation. Apply within five years of passing the exam.

Five exam domains and weights

Domain Main topics Weight
1. Information Systems Auditing Process Audit planning, execution, evidence, sampling, reporting, quality improvement 18%
2. Governance and Management of IT IT governance, strategy, policy, resources, vendors, performance, privacy 18%
3. Information Systems Acquisition, Development and Implementation Project governance, systems development, control design, testing, release, post-implementation review 12%
4. Information Systems Operations and Business Resilience IT operations, change, incidents, backup, continuity, disaster recovery 26%
5. Protection of Information Assets Identity, network, endpoint, data protection, security monitoring, incident response 26%

Domains 4 and 5 together account for 52% of the exam, while the audit process provides the method for analyzing every area. Use the chain “audit objective → risk → control → evidence → conclusion” across the syllabus.

How to study the five domains

1. Information Systems Auditing Process

Start with risk-based audit planning: define the objective, scope, criteria, risks, and resources. For execution, study control testing, sampling, interviews, observation, inspection, and data analysis. Assess whether evidence is sufficient, reliable, and relevant. Finish with communicating findings, reporting, follow-up, and quality assurance.

Keep audit work independent and objective. Gather enough evidence before evaluating control design and operation; do not rely only on verbal explanations or take ownership of management’s controls.

2. Governance and Management of IT

Understand how IT strategy supports enterprise objectives and how the board, management, IT, and business units share responsibilities. Review laws and regulations, enterprise architecture, data governance, privacy, IT resources, vendor management, and performance metrics.

Assess whether governance is defined, decisions are supported, performance and risk are monitored, and vendor arrangements meet business and compliance needs. Distinguish governance direction and oversight from management execution and operational work.

3. Information Systems Acquisition, Development and Implementation

Cover project governance, business cases, feasibility analysis, development methods, requirements and control design, system testing, migration, release, and post-implementation review. Security and control needs should enter early in the project, not appear only in a final pre-launch check.

For a project audit, examine approvals, requirements traceability, test results, defect handling, data conversion, and rollback planning. A post-implementation review checks whether expected benefits were achieved, controls work, and issues were addressed.

4. Information Systems Operations and Business Resilience

Study IT assets, job scheduling, interfaces, capacity and availability, databases, problem and incident management, change and configuration, patching, and logs. Business resilience includes business impact analysis, backup and restoration, business continuity, and disaster recovery.

Business continuity keeps critical operations running; disaster recovery restores IT systems and data. An audit should check whether plans reflect business impact and recovery objectives, responsibilities are clear, tests are realistic, and findings are followed up.

5. Protection of Information Assets

Begin with asset and data classification. Study security frameworks, physical and environmental controls, identity and access management, network and endpoint security, data loss prevention, encryption, public key infrastructure, cloud and virtualization, mobile devices, and IoT.

Security event management includes awareness, attack methods, security testing and monitoring, incident response, evidence collection, and forensics. Audit whether controls are well designed and work in practice, and whether incidents can be identified, escalated, investigated, and reviewed promptly.

Concepts that are easy to confuse

  • Control design and operation: A well-designed control is not necessarily operating consistently; assess both.
  • Audit evidence and management statements: Statements can guide the audit, but conclusions need sufficient, relevant, and reliable evidence.
  • Governance and management: Governance sets direction and oversight; management plans and executes.
  • Business continuity and disaster recovery: Continuity sustains critical business functions; recovery restores IT capability and data.
  • Audit recommendations and risk ownership: Auditors can recommend and report; management and assigned owners retain risk acceptance and control responsibilities.

Six-week study plan

Week Focus Suggested outcome
1 Audit process, risk-based planning, evidence, and sampling Derive scope and evidence needs from an audit objective
2 IT governance, strategy, policy, vendors, and privacy Distinguish oversight from management execution
3 Systems acquisition, development, testing, and implementation Check lifecycle controls and evidence in order
4 IT operations, change, incidents, databases, and logs Identify operational control failures and their impact
5 Business resilience, asset protection, and security controls Assess recovery plans and information protection
6 Integrated questions, error review, and outline check Connect risk, control, evidence, and conclusion

For practice questions, write down the audit objective and criteria before selecting evidence or the next step. Classify misses by control knowledge, audit procedure, evidence reliability, or responsibility boundaries.

Exam readiness checklist

  • Explain the five domains and weights using the current official outline.
  • Set a risk-based audit scope and select suitable test methods.
  • Judge whether evidence supports a finding and conclusion.
  • Assess governance, development, operations, and security controls across a system life cycle.
  • Distinguish continuity, disaster recovery, and incident response.
  • Verify experience waiver eligibility, application deadlines, and exam arrangements.

What to practice next

CISA questions often present audit scenarios. Identify the objective, risk, and responsible party first, then select a procedure that obtains reliable evidence relevant to the objective. Start CISA practice

WeChat mini program

IT知习 mini program QR code

Search WeChat for: IT知习