GRC Careers
Home › Certifications › CISA › Study Guide

CISA Study Guide: How to Pass the Certified Information Systems Auditor Exam

ISACA CISA  ·  Study Guide  ·  Exam Content Outline

The CISA certification overview covers what the exam tests and who it is for. This guide goes a level deeper: what to study first, the sub-topics ISACA actually tests within each domain, the frameworks you need to know cold, and how to manage the exam itself.

CISA is written from the perspective of the auditor who has to plan, execute and defend an audit conclusion with evidence, not the practitioner who runs the control day to day. For every topic, ask what evidence you would need to support a conclusion and how you would gather it without bias, rather than how you would fix the control yourself.

Study Priority Order

Study in this order. It follows how the domains build on each other, not just their exam weight.

18%

Domain 1, Information Systems Auditing Process

Start here. It is the methodology domain: audit standards, risk-based planning, evidence collection, testing and sampling, and reporting. Every other domain assumes you already know how to apply it.

18%

Domain 2, Governance and Management of IT

With audit method in hand, layer on what you are actually auditing at the enterprise level: IT governance structures, strategy alignment, enterprise risk management, and data governance and privacy programs.

26% + 26%

Domains 4 and 5, Operations, Resilience and Asset Protection

These two carry the most weight, 52 percent combined, and cover the day-to-day operational and security controls you will audit most often: IT operations, business continuity and disaster recovery, identity and access management, and incident response.

12%

Domain 3, IS Acquisition, Development and Implementation

Finish with the smallest domain: auditing systems as they are acquired, built, tested and migrated into production.

Domains 4 and 5 together are 52 percent of the exam, so if your study time is limited, protect the hours you have allocated to operations, resilience and information-asset protection first.

Domain Deep Dives

Domain 1, Information Systems Auditing Process (18%)

Two sub-areas, per ISACA's official content outline. Planning covers IS audit standards, guidelines and codes of ethics, types of audits, assessments and reviews, risk-based audit planning, and types of controls. Execution covers audit project management, testing and sampling methodology, evidence collection techniques, audit data analytics, reporting and communication techniques, and quality assurance and improvement of the audit process.

What to actually master: risk-based audit planning, meaning why auditors prioritize higher-risk areas rather than auditing everything equally. Then the difference between evidence that is sufficient and appropriate and evidence that merely looks thorough. Sampling methodology, statistical versus judgmental, is a frequently tested sub-topic.

Common trap: choosing the most exhaustive testing approach when the scenario is actually asking about a risk-based, proportionate response to a lower-risk finding.

Domain 2, Governance and Management of IT (18%)

Two sub-areas. IT Governance covers laws, regulations and industry standards, organizational structure and IT strategy, IT policies and standards, enterprise architecture, enterprise risk management, the privacy program and its principles, and data governance and classification. IT Management covers IT resource management, vendor management, performance monitoring and reporting, and quality assurance and quality management of IT.

What to actually master: evaluating whether IT strategy actually aligns with organizational strategy, a favourite scenario setup, and distinguishing IT governance decisions, meaning who sets direction, from IT management decisions, meaning who executes it. Vendor and third-party governance shows up here as well as in Domain 4.

Common trap: auditing an IT management activity as if it were a governance failure, or the reverse. The exam separates the two layers deliberately.

Domain 3, IS Acquisition, Development and Implementation (12%)

Two sub-areas. Information Systems Acquisition and Development covers project governance and management, business case and feasibility analysis, system development methodologies, and control identification and design. Information Systems Implementation covers system readiness and implementation testing, configuration and release management, system migration, infrastructure deployment and data conversion, and post-implementation review.

What to actually master: where controls should be identified and designed in the development life cycle, since earlier is cheaper and more effective, and what a proper post-implementation review actually checks, which is whether the project delivered against its original business case and requirements rather than whether it launched on time.

Common trap: assuming that implementation testing passing means the system is audit-ready. Post-implementation review is a distinct, later checkpoint.

Domain 4, IS Operations and Business Resilience (26%)

Two sub-areas, and tied for the largest domain. Information Systems Operations covers IT components, asset management, job scheduling and automation, system interfaces, shadow IT and end-user computing, availability and capacity management, problem and incident management, change, configuration and patch management, log management, service level management, and database management. Business Resilience covers business impact analysis, system and operational resilience, data backup, storage and restoration, business continuity plans, and disaster recovery plans.

What to actually master: shadow IT and end-user computing risk is a specifically named and frequently underweighted sub-topic, so know how to evaluate compensating controls when systems exist outside formal IT oversight. Also know the sequencing logic where a business impact analysis feeds the business continuity plan, which in turn drives the disaster recovery plan.

Common trap: treating the existence of a disaster recovery plan as sufficient evidence of resilience, without evidence that it has been tested against the organization's actual recovery time and recovery point objectives.

Domain 5, Protection of Information Assets (26%)

Two sub-areas, tied for the largest domain. Information Asset Security and Control covers security frameworks, standards and guidelines, physical and environmental controls, identity and access management, network and endpoint security, data loss prevention, encryption, public key infrastructure, and cloud, virtualized, mobile and IoT environments. Security Event Management covers security awareness training, attack methods and techniques, security testing tools, security monitoring tools, incident response management, and evidence collection and forensics.

What to actually master: identity and access management as an audit topic, meaning provisioning, deprovisioning, privileged access and segregation of duties. Then the chain-of-custody requirements for evidence collection and forensics, since CISA tests this as an audit-integrity issue rather than a purely technical skill.

Common trap: evaluating a security control for technical adequacy without evaluating whether it is actually monitored and enforced. CISA repeatedly separates control exists from control is operating effectively.

Frameworks You Need Cold

ISACA ITAF
ISACA's IS audit and assurance standards. Know the standards and codes of ethics that Domain 1 draws from directly.
COBIT
ISACA's IT governance and management framework. Know how it separates governance from management, mirrored in Domain 2.
IIA Global Standards
International standards for internal audit practice. Know how internal-audit methodology parallels IS audit planning and execution.
ISO/IEC 27001
International information security management standard. Know how Domain 5's control categories map to its control set.
NIST CSF
US voluntary risk-management framework. Know its core functions and how they map to Domains 4 and 5.

You do not need to be a practitioner in any of these. CISA tests whether you know when and why an auditor would reference each one, not how to implement them.

How to Study

Exam-Day Strategy

Frequently Asked Questions

Do I need audit experience to sit the CISA exam?

Check ISACA's current CISA page for the exact requirement. It typically requires demonstrated work experience in information systems auditing, control or security to hold the certification after passing, with some waivers available. Confirm the current policy directly with ISACA before you register.

Is CISA more about auditing or about IT itself?

Auditing. CISA assumes enough IT and security literacy to evaluate a system or control, but the exam consistently tests audit judgment, meaning planning, evidence, risk-based prioritization and reporting, over technical implementation.

Which CISA domain should I study longest?

Domains 4 and 5, IS Operations and Business Resilience and Protection of Information Assets, are tied at 26 percent each. Together they are just over half the exam.

How is CISA different from CISM and CRISC?

CISA focuses on independently auditing and assessing information systems and controls. CISM focuses on building and leading the security program those controls belong to. CRISC focuses on identifying and responding to the risk those controls are meant to manage. They pair well but test different roles: auditor, security leader and risk owner.

What are the five CISA domains and their weights?

Information Systems Auditing Process at 18 percent, Governance and Management of IT at 18 percent, IS Acquisition, Development and Implementation at 12 percent, IS Operations and Business Resilience at 26 percent, and Protection of Information Assets at 26 percent.

What is the passing score for CISA?

450 on a 200 to 800 scaled range. Not all questions are scored, since some are unscored pretest items, so you cannot work out your standing during the exam.

Is CISA worth it for a career change into audit?

It is the default credential for information systems audit and it opens the most doors of any audit certification. Employers hiring for IT and technology audit list it more than any other, and it reads well alongside experience in compliance, privacy or risk.

Keep Going

Official Resources

Domain weights and sub-topics are sourced from ISACA's official CISA Exam Content Outline. Confirm current fees, experience requirements, CPE policy and exam details at isaca.org before you register.

CISA and ISACA are trademarks of ISACA. GRC Careers is not affiliated with, endorsed by, or accredited by ISACA. This page is an independent study aid and contains no real exam questions.

Educational reference only and not legal, compliance, or certification advice. © 2026 GRC Careers · AI-Governance-Jobs.com · From the GRC Careers network.