ExamDetail Logo
HomeExamsCertificationISACA CISA Exam Guide: Fees, Eligibility, 5 Job Practice Domains & Passing Score
Cybersecurity

ISACA CISA Exam Guide: Fees, Eligibility, 5 Job Practice Domains & Passing Score

Everything you need to know: Eligibility, application dates, syllabus, and official notification for 2026.

ongoing

Never Miss an Update!

Get instant notifications for ISACA CISA Exam Guide: Fees, Eligibility, 5 Job Practice Domains & Passing Score dates, admit cards, and results directly on your phone.

Join WhatsApp Channel
Exam: On-Demand Booking
ISACA
Last Updated: 28 August 2026

ISACA CISA (Certified Information Systems Auditor) — Complete Guide

The Certified Information Systems Auditor (CISA), administered by ISACA, is the world’s preeminent credential for IT auditing, risk governance, enterprise cybersecurity assessment, and internal controls assurance. Globally recognized by the Big 4 accounting firms (Deloitte, PwC, EY, KPMG), banking institutions, and multinational tech enterprises, CISA validates your ability to assess enterprise IT infrastructure against vulnerabilities and regulatory compliance frameworks.


1. CISA Exam — At a Glance (Verified 2026)

ParameterOfficial Verified Details
Certifying BodyISACA (Information Systems Audit and Control Association)
Exam Fee (ISACA Member)$575 USD (~₹48,000 INR + 18% GST)
Exam Fee (Non-Member)$760 USD (~₹63,500 INR + 18% GST)
ISACA Annual Membership$135 USD + Local Chapter dues (~$20–$50)
Application Processing Fee$50 USD (Payable after passing when submitting experience)
Total Questions150 Multiple-Choice Questions (MCQs)
Exam Duration4 Hours (240 Minutes)
Passing Score450 / 800 Points (Scaled Scoring System)
Negative MarkingNone
Delivery ProviderPSI Testing Centers / Online Remote Proctored
Experience Requirement5 Years of IS audit/security experience (Up to 3-year waiver)
Maintenance120 CPE Credits over 3 years (Min 20 CPEs/year) + Annual Maintenance Fee

2. The 5 CISA Job Practice Domains & Weightage

The CISA examination syllabus is structured around five core job practice areas:

DomainExam WeightageCore Auditing & Governance Concepts
Domain 1: Information System Auditing Process21%ISACA Audit Standards & Code of Professional Ethics; Audit Planning & Risk Assessment; Control types (Preventive, Detective, Corrective); Evidence collection & sampling techniques (Statistical vs Non-statistical); Continuous audit techniques; Reporting & Follow-up.
Domain 2: Governance & Management of IT17%IT Governance frameworks (COBIT, ITIL); Enterprise Risk Management; IT Strategic Planning; Organizational Structure & Segregation of Duties (SoD); Business Impact Analysis (BIA); Third-Party Vendor & Cloud Service Level Agreements (SLAs).
Domain 3: Information Systems Acquisition, Development & Implementation12%Business case development; Project management practices (Agile vs Waterfall); System Development Life Cycle (SDLC phases); Requirements gathering; Data migration; Post-implementation reviews (PIR) and user acceptance testing (UAT).
Domain 4: Information Systems Operations & Business Resilience23%IT Operations management (Schedules, job logs); Data management & database controls (ACID properties); Network infrastructure auditing (Routers, Switches, Firewalls); Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP); RTO, RPO, SDO metrics; Backup media retention.
Domain 5: Protection of Information Assets27%Physical access controls & environmental monitoring; Logical access controls (IAM, MFA, RBAC); Cryptography & PKI; Network security architecture (Zero Trust, DMZ, SIEM, IDS/IPS); Endpoint security; Incident response procedures and privacy compliance (GDPR, HIPAA, SOC 2).

3. Deep Dive into Internal Control Classifications

A foundational concept tested extensively across all five domains is the categorization of internal controls:

Control CategoryFunctional ObjectivePractical IT Examples
Preventive ControlsDeter or stop an undesirable error or security breach before it occurs.Multi-Factor Authentication (MFA), Next-Gen Firewalls, Separation of Duties (SoD), employee background checks, badge access doors.
Detective ControlsIdentify and alert on errors, omissions, or unauthorized intrusions after they have occurred.Intrusion Detection Systems (IDS), automated log monitoring (SIEM alerts), monthly account reconciliations, CCTV review, internal audit inspections.
Corrective ControlsMitigate the damage, recover lost assets, or fix the vulnerability after an incident is discovered.Disaster recovery backups, automated server failover clusters, incident response playbooks, system patching, restoring corrupted databases.
Compensating ControlsAlternative safeguards implemented when primary controls are technically or economically unfeasible.Daily supervisor sign-off on transaction logs when strict separation of duties cannot be enforced in a small team.

4. Audit Sampling Methodologies & Evidence Gathering

Auditors must choose appropriate sampling strategies based on audit objectives:

Sampling TypeMethodologyTypical Audit Use Case
Attribute SamplingEvaluates the presence or absence of a specific characteristic (Pass / Fail).Testing whether change management approvals were signed for 100 sample server deployments.
Variable SamplingEstimates monetary values, transaction amounts, or continuous numerical values.Verifying the accuracy of inventory valuation or calculating financial loss from invoice errors.
Discovery SamplingUsed when the expected error rate is near zero; looking for at least one fraudulent occurrence.Investigating suspected unauthorized payroll alterations or embezzlement attempts.
Stratified SamplingDivides the total population into subgroups (strata) based on monetary value or risk tier.Auditing 100% of transactions over $100,000 and randomly sampling 5% of transactions under $1,000.

5. Business Continuity & Disaster Recovery Metrics

Questions in Domain 4 require calculating and interpreting business resilience parameters:

  • Recovery Point Objective (RPO): The maximum acceptable data loss measured in time (e.g., if backups occur every 4 hours, maximum potential data loss is 4 hours).
  • Recovery Time Objective (RTO): The maximum tolerable downtime before business systems must be restored to operation.
  • Maximum Tolerable Downtime (MTD): The absolute longest duration an organization can survive without critical functions before catastrophic loss occurs ($MTD = RTO + WRT$).
  • Work Recovery Time (WRT): The time required after systems are online to verify data integrity, test interfaces, and catch up on manual backlog.

6. Official Experience Requirements & Waiver Matrix

To obtain full CISA certification, candidates must verify 5 years of cumulative work experience in information systems auditing, control, or security. Up to 3 years of waivers can be claimed through academic or professional substitutions:

Approved Substitution / WaiverExperience Credit Granted
60 to 120 College Semester Hours (Associate/Diploma)1 Year Waiver
Bachelor's Degree in IT / Computer Science / Accounting2 Years Waiver
Master's Degree in Information Security / IT / Accounting2 Years Waiver
2 Years Full-Time University Instructor in IT Audit/Security1 Year Waiver
Active Chartered Accountant (CA / CPA / ACCA) or CIA / CISSP1 to 2 Years Waiver

Important: Candidates can sit for the exam before having the required experience. You have 5 full years from the exam pass date to fulfill the experience requirement and submit your application.


7. Understanding the "Auditor Mindset"

Passing CISA requires adopting the independent auditor perspective:

  • Independence is Paramount: An auditor does not configure firewalls, approve budget spending, or implement code fixes. If a question asks "What should the auditor do first?", the answer is almost always Assess the risk, Perform independent testing, or Report findings to management, rather than fixing the issue.
  • Evidence-Based Decisions: Auditors rely on verifiable facts, audit trails, and documented policies over verbal assurances from system administrators.
  • Risk-Based Auditing: Prioritize audit resources where business impact and probability of failure are highest.

8. Proven 90-Day CISA Study Roadmap

  • Days 1–30 (Foundations & CRM): Read ISACA's official CISA Review Manual (CRM) for Domains 1, 2, and 3. Focus on internal controls and COBIT governance concepts.
  • Days 31–60 (Technical Domains & Practice): Cover Domains 4 and 5 (Operations, BCP/DRP, Network Security). Start practicing ISACA QAE database questions (30–50 questions daily).
  • Days 61–75 (QAE Database Mastery): Complete all 1,000+ questions in the ISACA QAE Database. Read explanations for both correct and incorrect answers.
  • Days 76–90 (Full Mock Exams): Take two timed 150-question full mock exams. Target 80%+ consistency before your test appointment.

9. Global Salary Benchmark: CISA Certified Auditors

Country / RegionMedian Annual SalaryProminent Hiring Sectors
India₹12.0 LPA – ₹28.0 LPABig 4 Accounting (PwC, EY, Deloitte, KPMG), MNC Banks, Fintech
United States$115,000 – $155,000Financial Services, Healthcare Systems, Fortune 500 Enterprises
United Kingdom£65,000 – £95,000Banking, FinTech, Risk Advisory
AustraliaAUD $130,000 – AUD $175,000Government Audit Offices, Financial Sector
SingaporeSGD $110,000 – SGD $160,000Regional Compliance & Banking Hubs

Source: ISACA Official Portal: isaca.org/credentialing/cisa

Advertisement

Important Dates

Exam Timeline

Notification ReleasedOngoing (365 Days)
Application StartsOpen Anytime
Application EndsNo Deadline
Exam DateOn-Demand Booking

Eligibility Criteria

Age Limit
Age Criteria

No age limit

Qualification
Education

Minimum 5 years of professional IS auditing, control, or security work experience. Up to 3 years can be substituted with degrees (Bachelor/Master) or relevant professional credentials (CA/CPA/CISSP).

Attempts
Limits

Max 4 attempts in a 365-day period (Attempt 2: 30-day wait; Attempt 3: 90-day wait; Attempt 4: 90-day wait).

Advertisement

How to Apply

Follow this step-by-step guide to fill the ISACA CISA Exam Guide: Fees, Eligibility, 5 Job Practice Domains & Passing Score application form correctly.

Documents Required

  • Scanned Passport Size Photo (20-50kb, JPG)
  • Scanned Signature (10-20kb, JPG)
  • Class 10th & 12th Marksheets
  • Category Certificate (if applicable)

Syllabus & Pattern

Download Official Syllabus

The detailed syllabus and exam pattern are available in the official notification PDF.

Download Notification PDF

Frequently Asked Questions

Official Links & Resources

Apply Online / Registration

https://www.isaca.org/credentialing/cisa

Notification / Brochure

Download PDF

Detailed Syllabus

View Syllabus

Past Papers / Mock Tests

Access Papers
Advertisement