Never Miss an Update!
Get instant notifications for ISACA CISA Exam Guide: Fees, Eligibility, 5 Job Practice Domains & Passing Score dates, admit cards, and results directly on your phone.
ISACA CISA (Certified Information Systems Auditor) — Complete Guide
The Certified Information Systems Auditor (CISA), administered by ISACA, is the world’s preeminent credential for IT auditing, risk governance, enterprise cybersecurity assessment, and internal controls assurance. Globally recognized by the Big 4 accounting firms (Deloitte, PwC, EY, KPMG), banking institutions, and multinational tech enterprises, CISA validates your ability to assess enterprise IT infrastructure against vulnerabilities and regulatory compliance frameworks.
1. CISA Exam — At a Glance (Verified 2026)
| Parameter | Official Verified Details |
|---|---|
| Certifying Body | ISACA (Information Systems Audit and Control Association) |
| Exam Fee (ISACA Member) | $575 USD (~₹48,000 INR + 18% GST) |
| Exam Fee (Non-Member) | $760 USD (~₹63,500 INR + 18% GST) |
| ISACA Annual Membership | $135 USD + Local Chapter dues (~$20–$50) |
| Application Processing Fee | $50 USD (Payable after passing when submitting experience) |
| Total Questions | 150 Multiple-Choice Questions (MCQs) |
| Exam Duration | 4 Hours (240 Minutes) |
| Passing Score | 450 / 800 Points (Scaled Scoring System) |
| Negative Marking | None |
| Delivery Provider | PSI Testing Centers / Online Remote Proctored |
| Experience Requirement | 5 Years of IS audit/security experience (Up to 3-year waiver) |
| Maintenance | 120 CPE Credits over 3 years (Min 20 CPEs/year) + Annual Maintenance Fee |
2. The 5 CISA Job Practice Domains & Weightage
The CISA examination syllabus is structured around five core job practice areas:
| Domain | Exam Weightage | Core Auditing & Governance Concepts |
|---|---|---|
| Domain 1: Information System Auditing Process | 21% | ISACA Audit Standards & Code of Professional Ethics; Audit Planning & Risk Assessment; Control types (Preventive, Detective, Corrective); Evidence collection & sampling techniques (Statistical vs Non-statistical); Continuous audit techniques; Reporting & Follow-up. |
| Domain 2: Governance & Management of IT | 17% | IT Governance frameworks (COBIT, ITIL); Enterprise Risk Management; IT Strategic Planning; Organizational Structure & Segregation of Duties (SoD); Business Impact Analysis (BIA); Third-Party Vendor & Cloud Service Level Agreements (SLAs). |
| Domain 3: Information Systems Acquisition, Development & Implementation | 12% | Business case development; Project management practices (Agile vs Waterfall); System Development Life Cycle (SDLC phases); Requirements gathering; Data migration; Post-implementation reviews (PIR) and user acceptance testing (UAT). |
| Domain 4: Information Systems Operations & Business Resilience | 23% | IT Operations management (Schedules, job logs); Data management & database controls (ACID properties); Network infrastructure auditing (Routers, Switches, Firewalls); Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP); RTO, RPO, SDO metrics; Backup media retention. |
| Domain 5: Protection of Information Assets | 27% | Physical access controls & environmental monitoring; Logical access controls (IAM, MFA, RBAC); Cryptography & PKI; Network security architecture (Zero Trust, DMZ, SIEM, IDS/IPS); Endpoint security; Incident response procedures and privacy compliance (GDPR, HIPAA, SOC 2). |
3. Deep Dive into Internal Control Classifications
A foundational concept tested extensively across all five domains is the categorization of internal controls:
| Control Category | Functional Objective | Practical IT Examples |
|---|---|---|
| Preventive Controls | Deter or stop an undesirable error or security breach before it occurs. | Multi-Factor Authentication (MFA), Next-Gen Firewalls, Separation of Duties (SoD), employee background checks, badge access doors. |
| Detective Controls | Identify and alert on errors, omissions, or unauthorized intrusions after they have occurred. | Intrusion Detection Systems (IDS), automated log monitoring (SIEM alerts), monthly account reconciliations, CCTV review, internal audit inspections. |
| Corrective Controls | Mitigate the damage, recover lost assets, or fix the vulnerability after an incident is discovered. | Disaster recovery backups, automated server failover clusters, incident response playbooks, system patching, restoring corrupted databases. |
| Compensating Controls | Alternative safeguards implemented when primary controls are technically or economically unfeasible. | Daily supervisor sign-off on transaction logs when strict separation of duties cannot be enforced in a small team. |
4. Audit Sampling Methodologies & Evidence Gathering
Auditors must choose appropriate sampling strategies based on audit objectives:
| Sampling Type | Methodology | Typical Audit Use Case |
|---|---|---|
| Attribute Sampling | Evaluates the presence or absence of a specific characteristic (Pass / Fail). | Testing whether change management approvals were signed for 100 sample server deployments. |
| Variable Sampling | Estimates monetary values, transaction amounts, or continuous numerical values. | Verifying the accuracy of inventory valuation or calculating financial loss from invoice errors. |
| Discovery Sampling | Used when the expected error rate is near zero; looking for at least one fraudulent occurrence. | Investigating suspected unauthorized payroll alterations or embezzlement attempts. |
| Stratified Sampling | Divides the total population into subgroups (strata) based on monetary value or risk tier. | Auditing 100% of transactions over $100,000 and randomly sampling 5% of transactions under $1,000. |
5. Business Continuity & Disaster Recovery Metrics
Questions in Domain 4 require calculating and interpreting business resilience parameters:
- Recovery Point Objective (RPO): The maximum acceptable data loss measured in time (e.g., if backups occur every 4 hours, maximum potential data loss is 4 hours).
- Recovery Time Objective (RTO): The maximum tolerable downtime before business systems must be restored to operation.
- Maximum Tolerable Downtime (MTD): The absolute longest duration an organization can survive without critical functions before catastrophic loss occurs ($MTD = RTO + WRT$).
- Work Recovery Time (WRT): The time required after systems are online to verify data integrity, test interfaces, and catch up on manual backlog.
6. Official Experience Requirements & Waiver Matrix
To obtain full CISA certification, candidates must verify 5 years of cumulative work experience in information systems auditing, control, or security. Up to 3 years of waivers can be claimed through academic or professional substitutions:
| Approved Substitution / Waiver | Experience Credit Granted |
|---|---|
| 60 to 120 College Semester Hours (Associate/Diploma) | 1 Year Waiver |
| Bachelor's Degree in IT / Computer Science / Accounting | 2 Years Waiver |
| Master's Degree in Information Security / IT / Accounting | 2 Years Waiver |
| 2 Years Full-Time University Instructor in IT Audit/Security | 1 Year Waiver |
| Active Chartered Accountant (CA / CPA / ACCA) or CIA / CISSP | 1 to 2 Years Waiver |
Important: Candidates can sit for the exam before having the required experience. You have 5 full years from the exam pass date to fulfill the experience requirement and submit your application.
7. Understanding the "Auditor Mindset"
Passing CISA requires adopting the independent auditor perspective:
- Independence is Paramount: An auditor does not configure firewalls, approve budget spending, or implement code fixes. If a question asks "What should the auditor do first?", the answer is almost always Assess the risk, Perform independent testing, or Report findings to management, rather than fixing the issue.
- Evidence-Based Decisions: Auditors rely on verifiable facts, audit trails, and documented policies over verbal assurances from system administrators.
- Risk-Based Auditing: Prioritize audit resources where business impact and probability of failure are highest.
8. Proven 90-Day CISA Study Roadmap
- Days 1–30 (Foundations & CRM): Read ISACA's official CISA Review Manual (CRM) for Domains 1, 2, and 3. Focus on internal controls and COBIT governance concepts.
- Days 31–60 (Technical Domains & Practice): Cover Domains 4 and 5 (Operations, BCP/DRP, Network Security). Start practicing ISACA QAE database questions (30–50 questions daily).
- Days 61–75 (QAE Database Mastery): Complete all 1,000+ questions in the ISACA QAE Database. Read explanations for both correct and incorrect answers.
- Days 76–90 (Full Mock Exams): Take two timed 150-question full mock exams. Target 80%+ consistency before your test appointment.
9. Global Salary Benchmark: CISA Certified Auditors
| Country / Region | Median Annual Salary | Prominent Hiring Sectors |
|---|---|---|
| India | ₹12.0 LPA – ₹28.0 LPA | Big 4 Accounting (PwC, EY, Deloitte, KPMG), MNC Banks, Fintech |
| United States | $115,000 – $155,000 | Financial Services, Healthcare Systems, Fortune 500 Enterprises |
| United Kingdom | £65,000 – £95,000 | Banking, FinTech, Risk Advisory |
| Australia | AUD $130,000 – AUD $175,000 | Government Audit Offices, Financial Sector |
| Singapore | SGD $110,000 – SGD $160,000 | Regional Compliance & Banking Hubs |
Source: ISACA Official Portal: isaca.org/credentialing/cisa
Important Dates
Exam Timeline
Eligibility Criteria
No age limit
Minimum 5 years of professional IS auditing, control, or security work experience. Up to 3 years can be substituted with degrees (Bachelor/Master) or relevant professional credentials (CA/CPA/CISSP).
Max 4 attempts in a 365-day period (Attempt 2: 30-day wait; Attempt 3: 90-day wait; Attempt 4: 90-day wait).
How to Apply
Follow this step-by-step guide to fill the ISACA CISA Exam Guide: Fees, Eligibility, 5 Job Practice Domains & Passing Score application form correctly.
Documents Required
- Scanned Passport Size Photo (20-50kb, JPG)
- Scanned Signature (10-20kb, JPG)
- Class 10th & 12th Marksheets
- Category Certificate (if applicable)
Syllabus & Pattern
Download Official Syllabus
The detailed syllabus and exam pattern are available in the official notification PDF.
Download Notification PDFFrequently Asked Questions
Official Links & Resources
Official Website
https://www.isaca.org/credentialing/cisaApply Online / Registration
https://www.isaca.org/credentialing/cisaNotification / Brochure
Download PDFDetailed Syllabus
View SyllabusPast Papers / Mock Tests
Access PapersExplore Our Network & Utilities
TryQRMint.com
Create custom & dynamic QR codes for Resumes, Admit Cards, and Links.
Bidly.lol
Public competitive leaderboard where tools & startups bid for top visibility.
SarkariDocs.in
Get your documents ready fast. Aadhar, PAN, Income Certificates & more.
LaabhKhoj.in
Discover top government schemes and Yojanas you are eligible for.
More Exams You May Like
Certified Ethical Hacker (CEH v12) Exam Guide: Fees, Syllabus & Passing Score
ongoingCybersecurityCISSP Certification Exam Guide: Fees, CAT Format, Syllabus & Passing Score
ongoingIT & Cloud ComputingAWS Solutions Architect Associate (SAA-C03) Exam Guide: Fees, Syllabus & Passing Score
ongoingIT & Cloud ComputingMicrosoft Azure Fundamentals (AZ-900) Exam Guide: Fees, Syllabus & Passing Score
ongoingFinance & AccountingICAI CA Final Exam Guide: New Scheme 6 Papers, SPOM Modules, Fees & Passing Rules
ongoing