CISA-2026Hard

CISA exam guide

Certified Information Systems Auditor: the globally recognised credential for professionals who audit, control and assure information systems.

5
Topics
204
Study lessons
910
Practice questions
886
Flashcards

What is the CISA exam?

CISA is ISACA's flagship certification for IS audit, control and assurance. It has been awarded since 1978 and is the standard qualification asked for in internal audit, IT audit, IT risk and compliance roles, and by the Big Four and other assurance firms.

The exam covers the full audit lifecycle across five domains: how to plan and execute an IS audit; how IT should be governed and managed; controls over the acquisition, development and implementation of systems; IT operations, business continuity and resilience; and the protection of information assets. Questions are scenario-based and ask what an auditor should do, recommend or conclude, which makes the exam as much about judgement as knowledge.

Certification requires passing the exam and then demonstrating five years of professional IS audit, control or security experience, with waivers available for education and related certifications. The exam can be taken before the experience is complete.

Who sits it

  • IT auditors and internal auditors moving into technology audit
  • IT risk, compliance and governance professionals
  • Security and infrastructure staff who want an assurance-oriented credential
  • Consultants at assurance and advisory firms

Exam format at a glance

Questions
150 multiple-choice
Duration
4 hours
Delivery
Computer-based, year-round, at PSI test centres or via online remote proctoring
Fees (USD)
About $575 for ISACA members and $760 for non-members
Passing standard
Scaled score of 450 or higher on a 200–800 scale
Experience
Five years of relevant work experience, with up to three years of waivers, within ten years before or five years after passing
Pass rate
ISACA does not publish one
Job practice
Current exam content outline effective from 2024

Exam-body facts last checked September 2026. Fees, dates and formats change; confirm the current details with ISACA before registering.

Syllabus and topic weights

  • 1.Information Systems Auditing Process18% · 35 lessons · 0 questions · 185 cards
    1. IS Audit Standards, Guidelines, Functions and Codes of Ethics
    2. Types of Audits, Assessments and Reviews
    3. Risk-Based Audit Planning
    4. Types of Controls and Considerations
    5. Audit Project Management
    6. Audit Testing and Sampling Methodology
    7. Audit Evidence Collection Techniques
    8. Audit Data Analytics
    9. Reporting and Communication Techniques
    10. Quality Assurance and Improvement of the Audit Process
  • 2.Governance and Management of IT18% · 32 lessons · 0 questions · 152 cards
    1. Laws, Regulations and Industry Standards
    2. Organizational Structure, IT Governance and IT Strategy
    3. IT Policies, Standards, Procedures and Guidelines
    4. Enterprise Architecture and Considerations
    5. Enterprise Risk Management
    6. Data Privacy Program and Principles
    7. Data Governance and Classification
    8. IT Resource Management
    9. IT Vendor Management
  • 3.Information Systems Acquisition, Development, and Implementation12% · 29 lessons · 0 questions · 109 cards
    1. Project Governance and Management
    2. Business Case and Feasibility Analysis
    3. System Development Methodologies
    4. Control Identification and Design
    5. System Readiness and Implementation Testing
    6. Implementation Configuration and Release Management
    7. System Migration, Infrastructure Deployment and Data Conversion
    8. Postimplementation Review
  • 4.Information Systems Operations and Business Resilience26% · 56 lessons · 0 questions · 219 cards
    1. IT Components
    2. IT Asset Management
    3. Job Scheduling and Production Process Automation
    4. System Interfaces
    5. End-User Computing and Shadow IT
    6. Systems Availability and Capacity Management
    7. Problem and Incident Management
    8. IT Change, Configuration and Patch Management
    9. Operational Log Management
    10. IT Service Level Management
    11. Database Management
    12. Business Impact Analysis
    13. System and Operational Resilience
    14. Data Backup, Storage and Restoration
    15. Business Continuity Plan
    16. Disaster Recovery Plans
  • 5.Protection of Information Assets26% · 52 lessons · 0 questions · 221 cards
    1. Information Asset Security Policies, Frameworks, Standards and Guidelines
    2. Physical and Environmental Controls
    3. Identity and Access Management
    4. Network and Endpoint Security
    5. Data Loss Prevention
    6. Data Encryption
    7. Public Key Infrastructure
    8. Cloud and Virtualized Environments
    9. Mobile, Wireless and Internet of Things Devices
    10. Security Awareness Training and Programs
    11. Information System Attack Methods and Techniques
    12. Security Testing Tools and Techniques
    13. Security Monitoring Logs, Tools and Techniques

Lesson, question and flashcard counts are StudyOptima's published content for each topic. Expand a topic to see its subtopics.

How to prepare for CISA

  1. 1

    Think like ISACA. Many questions have more than one defensible answer; the correct one is usually the option that an independent auditor would take first, such as assessing risk before recommending a control, or reporting rather than fixing.

  2. 2

    Domains 4 and 5 are more than half the exam. Operations, resilience and information security deserve proportionally more study time than the earlier domains.

  3. 3

    Learn the vocabulary of controls precisely: preventive versus detective, compensating controls, segregation of duties, and the difference between a control objective and a control activity.

  4. 4

    Practise with long, scenario-based question sets. The exam is four hours and stamina matters more than for shorter certifications.

  5. 5

    Use the ISACA CISA Review Manual as the reference for anything you get wrong. The exam is written to it.

Study for CISA on StudyOptima

204 study lessons

Condensed notes for every topic, organised by learning objective, with read-progress tracking.

910 practice questions

Exam-style questions with worked explanations, timed mocks, and re-drills of what you got wrong.

886 flashcards

Spaced-repetition review of the definitions and formulas the exam keeps coming back to.

Plans and pricing

Paid plans for CISA are not on sale yet. Create a free account to read the free lessons and answer a daily allowance of practice questions, and we will let you know when full access opens.

Create a free account

CISA FAQ

Can I sit the CISA exam before I have five years of experience?

Yes. You have five years after passing to submit the experience application and become certified.

What experience waivers are available?

Up to three years can be waived for a relevant bachelor's or master's degree, for university teaching in a related field, or for one year of information systems or non-IS audit experience, subject to ISACA's current rules.

How is the CISA exam scored?

Raw scores are converted to a scale of 200 to 800. A scaled score of 450 represents the minimum standard set by ISACA's certification committee.

What does StudyOptima offer for CISA?

Study notes for all five domains and 56 subtopics, flashcards, and a bank of more than 900 scenario-style practice questions with explanations, with the first lessons in each domain free.

Related exams

Start preparing for CISA today

Free account in 30 seconds. No credit card required.

Create your free account