What is the CISA exam?
CISA is ISACA's flagship certification for IS audit, control and assurance. It has been awarded since 1978 and is the standard qualification asked for in internal audit, IT audit, IT risk and compliance roles, and by the Big Four and other assurance firms.
The exam covers the full audit lifecycle across five domains: how to plan and execute an IS audit; how IT should be governed and managed; controls over the acquisition, development and implementation of systems; IT operations, business continuity and resilience; and the protection of information assets. Questions are scenario-based and ask what an auditor should do, recommend or conclude, which makes the exam as much about judgement as knowledge.
Certification requires passing the exam and then demonstrating five years of professional IS audit, control or security experience, with waivers available for education and related certifications. The exam can be taken before the experience is complete.
Who sits it
- IT auditors and internal auditors moving into technology audit
- IT risk, compliance and governance professionals
- Security and infrastructure staff who want an assurance-oriented credential
- Consultants at assurance and advisory firms
Exam format at a glance
- Questions
- 150 multiple-choice
- Duration
- 4 hours
- Delivery
- Computer-based, year-round, at PSI test centres or via online remote proctoring
- Fees (USD)
- About $575 for ISACA members and $760 for non-members
- Passing standard
- Scaled score of 450 or higher on a 200–800 scale
- Experience
- Five years of relevant work experience, with up to three years of waivers, within ten years before or five years after passing
- Pass rate
- ISACA does not publish one
- Job practice
- Current exam content outline effective from 2024
Exam-body facts last checked September 2026. Fees, dates and formats change; confirm the current details with ISACA before registering.
Syllabus and topic weights
1.Information Systems Auditing Process18% · 35 lessons · 0 questions · 185 cards18%350185
- IS Audit Standards, Guidelines, Functions and Codes of Ethics
- Types of Audits, Assessments and Reviews
- Risk-Based Audit Planning
- Types of Controls and Considerations
- Audit Project Management
- Audit Testing and Sampling Methodology
- Audit Evidence Collection Techniques
- Audit Data Analytics
- Reporting and Communication Techniques
- Quality Assurance and Improvement of the Audit Process
2.Governance and Management of IT18% · 32 lessons · 0 questions · 152 cards18%320152
- Laws, Regulations and Industry Standards
- Organizational Structure, IT Governance and IT Strategy
- IT Policies, Standards, Procedures and Guidelines
- Enterprise Architecture and Considerations
- Enterprise Risk Management
- Data Privacy Program and Principles
- Data Governance and Classification
- IT Resource Management
- IT Vendor Management
3.Information Systems Acquisition, Development, and Implementation12% · 29 lessons · 0 questions · 109 cards12%290109
- Project Governance and Management
- Business Case and Feasibility Analysis
- System Development Methodologies
- Control Identification and Design
- System Readiness and Implementation Testing
- Implementation Configuration and Release Management
- System Migration, Infrastructure Deployment and Data Conversion
- Postimplementation Review
4.Information Systems Operations and Business Resilience26% · 56 lessons · 0 questions · 219 cards26%560219
- IT Components
- IT Asset Management
- Job Scheduling and Production Process Automation
- System Interfaces
- End-User Computing and Shadow IT
- Systems Availability and Capacity Management
- Problem and Incident Management
- IT Change, Configuration and Patch Management
- Operational Log Management
- IT Service Level Management
- Database Management
- Business Impact Analysis
- System and Operational Resilience
- Data Backup, Storage and Restoration
- Business Continuity Plan
- Disaster Recovery Plans
5.Protection of Information Assets26% · 52 lessons · 0 questions · 221 cards26%520221
- Information Asset Security Policies, Frameworks, Standards and Guidelines
- Physical and Environmental Controls
- Identity and Access Management
- Network and Endpoint Security
- Data Loss Prevention
- Data Encryption
- Public Key Infrastructure
- Cloud and Virtualized Environments
- Mobile, Wireless and Internet of Things Devices
- Security Awareness Training and Programs
- Information System Attack Methods and Techniques
- Security Testing Tools and Techniques
- Security Monitoring Logs, Tools and Techniques
Lesson, question and flashcard counts are StudyOptima's published content for each topic. Expand a topic to see its subtopics.
How to prepare for CISA
- 1
Think like ISACA. Many questions have more than one defensible answer; the correct one is usually the option that an independent auditor would take first, such as assessing risk before recommending a control, or reporting rather than fixing.
- 2
Domains 4 and 5 are more than half the exam. Operations, resilience and information security deserve proportionally more study time than the earlier domains.
- 3
Learn the vocabulary of controls precisely: preventive versus detective, compensating controls, segregation of duties, and the difference between a control objective and a control activity.
- 4
Practise with long, scenario-based question sets. The exam is four hours and stamina matters more than for shorter certifications.
- 5
Use the ISACA CISA Review Manual as the reference for anything you get wrong. The exam is written to it.
Study for CISA on StudyOptima
204 study lessons
Condensed notes for every topic, organised by learning objective, with read-progress tracking.
910 practice questions
Exam-style questions with worked explanations, timed mocks, and re-drills of what you got wrong.
886 flashcards
Spaced-repetition review of the definitions and formulas the exam keeps coming back to.
Free lessons to start with
Read these with a free account, no card required.
- IS Audit and Assurance Standards, Guidelines, and ITAFInformation Systems Auditing Process
- The ISACA Code of Professional EthicsInformation Systems Auditing Process
- Laws, Regulations and Industry Standards in IS AuditGovernance and Management of IT
- Auditing Regulatory Compliance: The IIA ConsiderationsGovernance and Management of IT
- Project Governance: Portfolios, Programs, Structures and RolesInformation Systems Acquisition, Development, and Implementation
- The Project Management Life Cycle: Initiation to ClosingInformation Systems Acquisition, Development, and Implementation
Plans and pricing
Paid plans for CISA are not on sale yet. Create a free account to read the free lessons and answer a daily allowance of practice questions, and we will let you know when full access opens.
Create a free accountCISA FAQ
Can I sit the CISA exam before I have five years of experience?
Yes. You have five years after passing to submit the experience application and become certified.
What experience waivers are available?
Up to three years can be waived for a relevant bachelor's or master's degree, for university teaching in a related field, or for one year of information systems or non-IS audit experience, subject to ISACA's current rules.
How is the CISA exam scored?
Raw scores are converted to a scale of 200 to 800. A scaled score of 450 represents the minimum standard set by ISACA's certification committee.
What does StudyOptima offer for CISA?
Study notes for all five domains and 56 subtopics, flashcards, and a bank of more than 900 scenario-style practice questions with explanations, with the first lessons in each domain free.
Related exams
Certified Information Systems Security Professional: the benchmark certification for security leadership across eight domains of the ISC2 Common Body of Knowledge.
Certified Data Management Professional: the vendor-neutral data-management credential based on the DAMA-DMBOK, tested through the Data Management Fundamentals exam.