The ISACA CISA certification validates your expertise and opens doors to higher-paying roles in IT and cybersecurity. Whether you are just starting your study journey or doing a final review, this guide breaks down everything you need to know to pass the CISA exam.
Exam Overview
- Certification: ISACA CISA
- Exam Code: CISA
- Vendor: ISACA
- Cost: $575 USD (members) / $760 USD (non-members)
- Duration: 240 minutes (4 hours)
- Questions: 150 questions
- Passing Score: 450 out of 800
- Format: Multiple choice
- Prerequisites: 5 years IS auditing/control/security experience (waivers available)
Domain Breakdown
Understanding the exam domains and their weights is critical for efficient study planning. Focus more time on heavily-weighted domains while ensuring you cover all areas.
Domain 1: Information System Auditing Process (18%)
- 1.1 Plan an IS audit
- 1.2 Conduct an IS audit
- 1.3 Communicate audit results and follow up
Key concepts: Audit Standards, Risk-Based Approach, Audit Planning, Evidence Collection, Sampling, Audit Reporting, Follow-Up, ISACA Standards
Domain 2: Governance and Management of IT (18%)
- 2.1 Evaluate IT strategy and governance structure
- 2.2 Evaluate IT management structure and practices
- 2.3 Evaluate IT policies, standards, and procedures
Key concepts: IT Strategy, Governance Frameworks, Policies/Procedures, Resource Management, IT Performance, Quality Management, Organizational Structures, Maturity Models
Domain 3: Information Systems Acquisition, Development and Implementation (12%)
- 3.1 Evaluate project management frameworks
- 3.2 Evaluate feasibility of IS acquisitions
- 3.3 Evaluate IT project management practices
Key concepts: Project Management, Business Case, Requirements Analysis, SDLC, Testing Methods, Change Management, Configuration Management, Post-Implementation Review
Domain 4: Information Systems Operations and Business Resilience (26%)
- 4.1 Evaluate IS operations
- 4.2 Evaluate business resilience
- 4.3 Evaluate IT service management practices
- 4.4 Evaluate problem and incident management
Key concepts: IT Service Management, ITIL Framework, Operations Management, BCP/DRP, Incident Management, Problem Management, Data Backup, IT Asset Management
Domain 5: Protection of Information Assets (26%)
- 5.1 Evaluate information asset security and data governance
- 5.2 Evaluate the privacy program
- 5.3 Evaluate information asset security policies and practices
Key concepts: Data Governance, Data Classification, Access Controls, Network Security, Environmental Controls, Physical Security, Security Awareness, Privacy Programs
Recommended Study Timeline
Plan for approximately 10-16 weeks of dedicated study. Here is a suggested weekly breakdown:
- Week 1: Domain 1: IS Audit Process — Audit planning, standards, risk-based approach
- Week 2: Domain 1: IS Audit Process — Conducting audits, evidence, reporting, follow-up
- Week 3: Domain 2: IT Governance — IT strategy, governance frameworks, policies
- Week 4: Domain 2: IT Governance — IT management structures, resource management
- Week 5: Domain 3: IS Acquisition/Development — Project management, SDLC, requirements
- Week 6: Domain 3: IS Acquisition — Testing, implementation, change management
- Week 7: Domain 4: IS Operations — IT service management, operations, data management
- Week 8: Domain 4: IS Operations — Business resilience, BCP, DRP, incident management
- Week 9: Domain 5: Protection of Information Assets — Data governance, classification
- Week 10: Domain 5: Protection — Security policies, access controls, network security
- Week 11: Cross-domain review: Practice questions, audit scenario analysis
- Week 12: Final review: Practice exams, weak areas, exam preparation
Top Study Tips
- Start with the official exam objectives. Download them from the ISACA website and use them as your study checklist. Every exam question maps to a specific objective.
- Use active recall over passive reading. Instead of re-reading notes, test yourself with practice questions after each study session. This dramatically improves retention.
- Focus on heavily-weighted domains first. Domains with higher percentages appear more on the exam. Master these before moving to lower-weighted areas.
- Build hands-on experience. Set up a lab environment and practice the skills you are studying. Hands-on experience is especially valuable for performance-based questions.
- Take practice exams under real conditions. Time yourself, eliminate distractions, and simulate the exam environment. Review every wrong answer and understand why it was wrong.
Practice Resources
Test your knowledge with our free tools:
Take our free ISACA CISA practice quiz
- CVSS Calculator — Practice scoring vulnerabilities
- Password Strength Checker — Test password security
Career Impact
The ISACA CISA certification demonstrates validated expertise to employers. Certified professionals typically see:
- Higher starting salaries compared to non-certified peers
- More interview callbacks as the certification signals commitment and competence
- Faster career progression with a recognized credential on your resume
- Access to roles that specifically require or prefer ISACA CISA certification
What to Study Next
After earning your ISACA CISA certification, consider these natural next steps:
- Deepen your specialization with an advanced certification in the same vendor track
- Broaden your skills with a certification from a complementary domain
- Visit our Career Paths page for detailed certification roadmaps
Get Organized with a Study Planner
A structured study plan makes the difference between passing and failing. Our fillable PDF study planners include domain trackers, weekly schedules, and progress tracking designed specifically for ISACA CISA exam prep.
This guide is independently created for educational purposes. ISACA trademarks belong to their respective owners. FixTheVuln is not affiliated with or endorsed by ISACA.
Explore More
Exam Syllabus & Domain Breakdown
Review the complete certification syllabus, domain weights, and free training resources.
View Full Certification Guide →FixTheVuln Store
ISACA Certification? Get the Study Planner
Planner for ISACA certifications. Governance frameworks, risk management trackers, and audit methodology guides.
Shop CISM PlannerAlso available: CISM, CISA, CRISC
CyberFolio
Building cybersecurity skills? Track them in one place.
Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.
Build Your Portfolio →