CompTIA Security+ proves you can operate controls. CISA proves you can audit them.
A Security+ question asks: “Which encryption algorithm provides forward secrecy in TLS?” A CISA question asks: “During an audit of an organisation’s change management process, an IS auditor discovers that emergency changes are frequently implemented without approval. What should the auditor do first?” The answer is not “recommend a SIEM alert” — it is to determine whether the emergency change process is documented and whether after-the-fact approvals are obtained within the required timeframe. That shift from technical implementation to systematic control assessment defines CISA entirely.
CISA is deliberately scoped to audit and assurance methodology. It does not test deep cryptographic implementation, network packet analysis, or exploit development. It tests the frameworks, standards, and techniques that IT auditors use to assess whether an organisation’s information systems are adequately controlled, reliable, and compliant with applicable laws and regulations. ISACA’s research consistently finds CISA holders earning median salaries of $110,000–$145,000 USD, reflecting the institutional trust placed in audit professionals who sign off on control assessments for external stakeholders including regulators, boards, and external auditors.
The experience requirement is substantial: five years of professional experience in IS audit, control, assurance, or security. Up to three years may be waived — one year for a two-year or four-year degree in IS or IT, two years for a graduate-level IS degree, one year for CISSP or CISM, and other substitutions listed in the official candidate guide. Unlike CISM, there is no domain-specific management experience requirement — CISA experience spans the broader IS audit and control discipline. Candidates who pass the exam before completing the experience requirement have five years to submit qualifying experience before the exam result expires.
The five CISA domains
Domain 1 — Information System Auditing Process (~21%)
The foundation of CISA: the standards, guidelines, and techniques that define how IS audits are planned, executed, and reported. This domain tests whether candidates understand audit as a disciplined, evidence-based process — not a checklist or a technology review.
- Audit standards and guidelines: ISACA’s IT Audit Standards, the International Standards for the Professional Practice of Internal Auditing (IIA Standards), and how these frameworks shape the auditor’s obligations for due professional care, objectivity, and competence. CISA tests the standards’ practical application — when must an auditor disclose a limitation of scope? What constitutes sufficient audit evidence? When is a finding material?
- Risk-based audit planning: effective IS audits begin with risk assessment, not scope selection. CISA tests how auditors identify high-risk areas, prioritise audit resources accordingly, and document the risk rationale for scope decisions. Auditing every control in scope is neither efficient nor effective; auditing controls most likely to fail in ways that matter to the organisation is.
- Audit types and techniques: compliance audits (does the control exist and operate as designed?), operational audits (is the control effective at achieving its objective?), integrated audits (coordinated with financial auditors to cover IT controls supporting financial statements), and forensic audits (evidence collection for potential legal proceedings). CISA also tests computer-assisted audit tools and techniques (CAATs) — data analytics, sampling, and automated control testing using tools like ACL, IDEA, or SQL queries against production data extracts.
- Evidence collection and evaluation: corroborative evidence strengthens audit conclusions; contradictory evidence requires resolution before the auditor can form an opinion. CISA tests the hierarchy of evidence reliability: direct observation is most reliable; recalculation and confirmation from third parties are strong; inquiry alone is the weakest form of evidence. Sampling techniques — statistical sampling for attribute testing, judgmental sampling for substantive testing — and how sample size affects the auditor’s confidence in conclusions.
- Audit reporting and follow-up: the audit report is the primary deliverable: findings stated clearly with root cause, risk rating, and a specific recommendation. CISA tests the auditor’s obligation to follow up on prior audit findings — management’s commitment to remediate a finding is not the same as evidence that the finding was remediated. Follow-up audits verify that corrective actions were implemented and are operating effectively.
Domain 2 — Governance and Management of IT (~17%)
IT governance provides the framework within which IS controls operate. CISA tests the auditor’s ability to assess whether an organisation’s IT governance structures, processes, and practices are designed and operating effectively to achieve business objectives and manage IT risk.
- IT governance frameworks: COBIT is ISACA’s primary governance framework and the one most directly aligned with CISA. CISA tests COBIT’s five principles and how auditors use it to evaluate governance maturity. Candidates also encounter references to ISO/IEC 38500 (corporate governance of IT) and ITIL (IT service management governance), particularly in questions about alignment between IT services and business strategy.
- IT strategy and organisational structure: the IS auditor evaluates whether IT strategic plans are formally documented, approved by appropriate governance bodies, aligned to business strategy, and reviewed on a defined cycle. Governance structures — IT steering committees, the CIO reporting line, the IT audit committee relationship — define the accountability framework the auditor assesses.
- IT policies and procedures: the auditor examines whether the policy hierarchy is complete (policies, standards, baselines, guidelines, procedures), whether policies are approved by appropriate authority, communicated to relevant personnel, and reviewed on a defined schedule. A policy that exists on paper but is not communicated or enforced provides no control value.
- IT resource and performance management: capacity management (are IT resources adequate to meet current and projected demand?), IT performance measurement (are KPIs meaningful and regularly reviewed?), and IT investment management (is IT spending allocated to projects that align to strategy and are subject to post-implementation review?). CISA tests the auditor’s ability to assess whether governance processes produce reliable information for management decision-making.
- Third-party management and outsourcing: a growing share of IT functions are delivered through third parties. CISA tests the governance of outsourced functions: contract provisions (SLAs, right to audit, data ownership, breach notification), oversight mechanisms (service reviews, SLA monitoring, vendor risk assessments), and the organisation’s residual accountability for controls performed by vendors. Outsourcing transfers the function, never the risk.
Domain 3 — Information Systems Acquisition, Development, and Implementation (~12%)
The smallest domain by exam weight, but critically important: controls embedded during system development are exponentially cheaper than controls retrofitted after deployment. CISA tests the auditor’s ability to assess whether projects and systems development processes incorporate appropriate controls throughout the lifecycle.
- Project management and governance: IS auditors evaluate whether IT projects are subject to formal project governance — approved business cases, defined scope, qualified project sponsors, change control boards, and structured stage gates. Project failures most commonly stem from scope creep, inadequate requirements definition, and insufficient stakeholder involvement — all areas where audit review during the project lifecycle can add measurable value.
- Software development methodologies: waterfall, agile, and DevOps each present different audit challenges. Waterfall projects have formal approval gates but risk delivering systems that no longer meet business requirements after long development cycles. Agile sprints produce frequent releases but may lack the documentation and formal control checkpoints auditors rely on. CISA tests how auditors adapt their approach to each methodology rather than applying a one-size-fits-all audit programme.
- Application controls: input controls (validation of data entering the system), processing controls (ensuring transactions are processed completely and accurately), and output controls (ensuring reports and data feeds are complete and distributed to authorised recipients only). Audit procedures for application controls include test transactions, parallel processing, and data analytics on production data to identify anomalies.
- System testing and quality assurance: the auditor evaluates whether system testing is independent (developers should not test their own code), whether test plans cover positive cases, negative cases, and boundary conditions, and whether user acceptance testing (UAT) is documented and signed off by business process owners. Inadequate testing is the most common root cause of production defects that create control weaknesses.
- Change management and migration: changes to production systems must go through a controlled change management process to prevent unauthorised modifications. CISA tests the auditor’s evaluation of change request authorisation, testing requirements, rollback planning, and post-implementation review. Data migration projects introduce specific risks — completeness, accuracy, and integrity of migrated data must be verified through reconciliation controls.
Domain 4 — Information Systems Operations and Business Resilience (~23%)
The day-to-day operation of IT systems and the organisation’s ability to continue operations under adverse conditions. CISA tests the auditor’s ability to evaluate whether operational controls are designed and operating effectively and whether the organisation can recover IT services within defined timeframes when disruptions occur.
- IT service management: incident management (are incidents logged, classified, and resolved within SLA targets?), problem management (are recurring incidents investigated for root cause?), configuration management (is the CMDB accurate and maintained?), and release management (are releases to production controlled and documented?). ITIL processes provide the framework; the auditor evaluates whether the organisation’s implementation of those processes is effective.
- IT operations controls: job scheduling controls (are batch jobs monitored and failures escalated?), data backup and recovery (are backups tested, offsite, and retained per policy?), capacity monitoring (are capacity thresholds monitored before they become availability incidents?), and performance monitoring (are SLAs measured and reported to management?). Operations controls prevent small failures from escalating to business-impacting events.
- Business continuity and disaster recovery: the Business Impact Analysis (BIA) identifies which IT systems are critical and defines the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for each. CISA tests the auditor’s evaluation of whether BCPs and DRPs are documented, approved by appropriate management, tested on a defined schedule, and updated after tests or material IT changes. An untested BCP provides false assurance — the auditor’s job is to determine whether the plan will actually work when invoked.
- End-user computing controls: spreadsheets, Access databases, and locally maintained scripts that support business processes present specific control risks — they may not be subject to IT change management, may lack version control, and may contain errors that accumulate over time. CISA tests how auditors identify and assess the risk of end-user computing applications within the audit scope.
- Hardware and software asset management: an accurate asset inventory is a prerequisite for effective patch management and licensing compliance. CISA tests whether the organisation maintains a current hardware and software inventory, whether assets are assigned to owners, and whether disposal of assets includes appropriate data sanitisation procedures to prevent data leakage from decommissioned hardware.
Domain 5 — Protection of Information Assets (~27%)
The largest domain by exam weight, covering the security controls that protect information assets from unauthorised access, modification, or destruction. CISA tests the auditor’s ability to evaluate the design and operating effectiveness of the full spectrum of information security controls — from logical access to physical security to cryptographic key management.
- Logical access controls: user provisioning (are access requests approved by the appropriate data owner?), access review (are user access rights reviewed on a defined schedule?), privileged access management (are administrator accounts individually assigned, monitored, and subject to enhanced controls?), and access termination (are access rights promptly revoked when employees leave or change roles?). Access control failures are the most common finding in IS audits — overprivileged accounts, dormant accounts, and inadequate access review cycles appear in almost every audit.
- Network and infrastructure security: the auditor evaluates the network segmentation architecture (is the DMZ properly isolated from internal networks?), firewall rule review (are rules documented, reviewed, and free of unnecessary permissive rules?), and intrusion detection and prevention system coverage. CISA tests these at an audit evaluation level, not at a technical configuration level — the auditor asks whether controls are present and effective, not how to configure a firewall.
- Data classification and handling: a data classification policy that is not implemented in practice provides no control value. CISA tests the auditor’s evaluation of whether data is classified according to policy, whether classified data is handled and stored in accordance with its classification requirements, and whether data owners have accepted the risk associated with their data’s classification. Data loss prevention (DLP) controls — monitoring for sensitive data leaving the organisation via email, USB, or cloud upload — are increasingly common audit topics.
- Cryptography and key management: CISA tests cryptography at a conceptual level sufficient to evaluate controls: is encryption applied to data at rest and in transit for sensitive data? Are encryption algorithms of adequate strength? Is key management formalised — who can generate, store, rotate, and destroy cryptographic keys? Inadequate key management is a common finding even where encryption is technically implemented correctly.
- Physical and environmental controls: data centre physical access controls (badge readers, mantraps, CCTV, visitor logs), environmental monitoring (temperature, humidity, fire suppression, flood detection), and power controls (UPS, generator testing, dual-power feeds for critical equipment). Physical security findings are frequently underreported in IS audits; CISA tests the auditor’s obligation to include physical controls in scope where they are material to information asset protection.
- Security monitoring and incident response: the auditor evaluates whether the organisation monitors for security events (SIEM coverage, log retention periods, alert thresholds), whether security incidents are logged and investigated, and whether the incident response plan is tested and current. The distinction CISA draws is between the security operations function (which the auditor evaluates) and the audit function (which provides independent assurance of that evaluation) — the auditor must maintain independence from the function being audited.
Exam format and scoring
The CISA exam uses a scaled scoring model: raw scores are converted to a scale of 200–800, and the passing score is 450. The 150 questions are all scenario-based multiple-choice, reflecting the judgment-intensive nature of the audit profession. CISA questions are constructed so that multiple answers are plausible — the correct answer is the one that best reflects sound audit methodology, professional standards, and the perspective of a competent IS auditor exercising due professional care.
ISACA offers the exam year-round through PSI testing centres and as a remote proctored option. The four-hour window allows approximately 96 seconds per question, which is sufficient for candidates who have internalised the audit methodology. The challenge is consistency: maintaining an audit-first perspective across 150 consecutive scenario questions, resisting the temptation to answer from IT operations or security management experience rather than audit methodology, requires deliberate preparation.
The CISA trap that catches the most candidates: the exam tests audit response, not management response. When a question asks “what should the IS auditor do first?” and options include both an audit action (document the finding and report to management) and a management action (immediately implement a corrective control), the audit action is almost always correct. The auditor’s role is to report; management’s role is to remediate. Crossing that boundary violates auditor independence.
Experience requirement and waiver options
ISACA requires candidates to demonstrate five years of professional experience in information systems auditing, control, assurance, or security before being awarded the CISA designation. This experience must be verifiable and may span multiple employers. The experience requirement reflects CISA’s positioning as a professional credential, not an entry-level certification — the designation signals to employers and regulators that the holder has applied IS audit principles in practice, not merely passed an exam.
Up to three years of the experience requirement may be substituted with approved alternatives. One year of experience can be waived for a two-year or four-year degree in IS or IT, and two full years can be waived for a graduate degree in IS or IT. Holding a currently active CISM or CISSP can substitute for one year of experience. The official ISACA candidate guide lists all approved substitutions with their equivalent waiver values — candidates should review this list carefully before submitting their experience verification.
Candidates who pass the CISA exam before completing the experience requirement have five years to accumulate and submit qualifying experience. During that period they hold a passing exam result but are not awarded the CISA designation. There is no associate-level designation during this period. Many candidates intentionally pass the exam during the final year of their experience accumulation to receive the designation as soon as their five-year requirement is met.
How CISA fits the IT audit and security credential landscape
CISA occupies a specific and well-defined position in the professional credential ecosystem. Understanding its position prevents candidates from pursuing it for the wrong reasons — or missing it when it is exactly the right fit:
- CISA vs CISM: ISACA’s Certified Information Security Manager (CISM) covers four management domains from the perspective of the security programme manager — governance, risk management, programme management, and incident response. CISA covers five domains from the perspective of the independent assessor — audit process, IT governance, systems development, operations, and information protection. CISM certifies that the holder can build and run a security programme; CISA certifies that the holder can objectively assess whether one is working. Many senior GRC professionals hold both.
- CISA vs CRISC: ISACA’s Certified in Risk and Information Systems Control (CRISC) focuses on IT risk identification, assessment, response, and monitoring from the perspective of a risk practitioner. CRISC candidates typically work in risk management, enterprise risk, or ERM roles. CISA covers IS risk as one component of the broader audit scope but is primarily audit-focused rather than risk-management-focused. In organisations with both IS audit and risk management functions, CISA and CRISC practitioners frequently collaborate but occupy distinct professional roles.
- CISA vs CIA: the Certified Internal Auditor (CIA) from the IIA is the general internal audit credential; it covers audit process, governance, risk, and control across all business functions. CISA is IS-specific, with deeper technical depth in information systems controls. Many IS auditors hold both CIA and CISA — CIA for professional audit credibility with the IIA community and financial auditors, CISA for IS-specific technical credibility with regulators and technology management.
- CISA as a DoD 8570 gate: for IS professionals in US federal, DoD contractor, or intelligence community roles, CISA satisfies DoD 8570.01-M IAT Level II baseline certification requirements. This makes CISA a hiring gate for a significant population of IS audit and compliance roles in defence contracting, federal systems integrators, and government agencies. The DoD IAT Level II approval is shared with CompTIA Security+, CCNA Security, and a small number of other credentials at that tier.
CISA is the credential that opens doors in IS audit departments at Big Four firms, internal audit functions at financial services firms, IT compliance at regulated-industry companies, and government IS assurance roles. The exam rewards candidates who have actually conducted IS audits — the scenario questions are grounded in real audit situations, and candidates with practical experience consistently outperform those who rely solely on exam prep materials. Effective preparation combines ISACA’s official CISA Review Manual with the ISACA QA&E (Question, Answer, and Explanation) database. The manual provides the framework; the QA&E database develops the judgment needed to apply it. The official ISACA CISA candidate page contains the authoritative exam outline, domain weights, experience requirements, and the approved substitution list.
Practice IT audit, governance, and information security control concepts with CISA-focused questions on CertQuests.
Practice CISA Questions →