CISA (Certified Information Systems Auditor) is ISACA’s flagship credential for IS audit, control, and assurance professionals. The exam doesn’t test whether you can build systems — it tests whether you can evaluate them objectively. Adopting the auditor’s mindset of independence, evidence, and materiality is the key to passing.
The five domains and their weights
- Information Systems Auditing Process (~21%) — planning and executing audits, evidence, and reporting.
- Governance & Management of IT (~17%) — IT strategy, structure, policies, and risk.
- IS Acquisition, Development & Implementation (~12%) — project, development, and migration controls.
- IS Operations & Business Resilience (~23%) — operations, BCP/DRP, and resilience.
- Protection of Information Assets (~27%) — the largest domain: security controls, identity, and data protection.
Protection of Information Assets and IS Operations together are half the exam — prioritize them.
Think like an auditor
The most common mistake is answering as an implementer. The CISA exam wants the response that preserves independence and objectivity, relies on sufficient and appropriate evidence, and considers materiality and risk. When in doubt, choose the answer that gathers evidence or reports findings rather than the one that fixes the problem directly — auditors assess, they don’t remediate.
A study approach
Work domain by domain, starting with the two heaviest. Learn the audit lifecycle cold (risk-based audit planning, control testing, sampling, and reporting), then layer in governance and resilience. Reserve the final stretch for practice questions, tracking which domains you miss and revisiting the underlying control concepts.
Experience requirement
Passing the exam is one half; certification also requires five years of professional IS audit, control, or security experience (with some waivers available). You can sit the exam first and satisfy the experience requirement within five years.