Exam Details
ISACA · CISA
Prepare for CISA: Audit, control, and assure information systems across governance, protection, and operations.
Overview
Related Roadmaps
Approved links shared by the community. Earn credits when yours gets approved!
No community resources yet. Be the first to suggest one!
Know a strong article, guide, or explainer for this exam? Submit it for review and earn credits when it gets approved.
ExamOS may provide links to third-party websites, books, videos, courses, and other materials ("External Resources") for your convenience and reference. These resources are not created, owned, or controlled by ExamOS unless explicitly stated.
For official and up-to-date information, always refer to the certification provider website.
No resources have been linked to this exam yet.
Video Library
No video resources are available for this exam yet.
Found a strong walkthrough, lesson, or exam breakdown on YouTube? Submit it here and earn credits if it gets approved.
FAQ
The CISA certification validates your ability to audit, control, monitor, and assess information systems and technology. This professional-level certification targets IT auditors, compliance professionals, and security consultants who evaluate IS controls, assess governance frameworks, audit system acquisitions, and verify data protection practices. CISA is globally recognized as the standard for IS audit professionals and is required or preferred for audit roles across financial services, healthcare, and government. You'll demonstrate expertise across five domains spanning the full audit lifecycle. As regulatory requirements expand and organizations face increasing audit scrutiny, CISA certified auditors are essential.
You're a fit for CISA if you:
Not sure if you're ready? Try a free sample quiz: 10 questions, instant results, identify weak areas.
| Domain | Weight | What This Means |
|---|---|---|
| Information System Auditing Process | 18% | Plan and conduct IS audits, evaluate evidence, report findings, and follow up on remediation |
| Governance and Management of IT | 18% | Audit IT governance structures, strategic alignment, resource management, and risk management practices |
| Information Systems Acquisition, Development, and Implementation | 12% | Audit system development lifecycles, project governance, change management, and quality assurance |
| Information Systems Operations and Business Resilience | 26% | Audit IT operations, service delivery, incident management, and business continuity/disaster recovery |
| Protection of Information Assets | 26% | Audit data classification, access controls, encryption, network security, and privacy protections |
You're probably ready if you can:
You might need more prep if:
If this feels too advanced:
If you know the basics but want to build confidence:
The CISA exam consists of 150 multiple-choice questions that must be completed within a 4-hour (240-minute) window. The questions are designed to test both knowledge and the practical application of auditing principles.
ISACA uses a scaled scoring system ranging from 200 to 800 points. To successfully pass the exam, a candidate must achieve a minimum scaled score of 450.
The exam is divided into five specific domains that reflect the duties of an IT auditor:
Most candidates use the official ISACA CISA Review Manual and the Questions, Answers & Explanations (QAE) Database. To supplement these materials and gain experience with the specific logic used in the test, ExamOS offers scenario-based practice quizzes that build real exam confidence.
The cost of the exam depends on your ISACA membership status. For members, the registration fee is typically $575 USD, while non-members are charged $760 USD. These prices do not include membership dues or study materials.
If you do not pass on your first attempt, you must wait 30 days before you can retake the exam. A third attempt requires a 60-day waiting period, and a fourth attempt requires a 90-day waiting period. You are limited to a maximum of four attempts within any rolling twelve-month period.
To maintain the CISA designation, you must comply with the Continuing Professional Education (CPE) policy. This requires earning and reporting a minimum of 20 CPE hours annually and a total of 120 CPE hours over a fixed three-year cycle. You must also pay an annual maintenance fee.
The CISA is targeted at IT auditors, risk analysts, and compliance specialists. While anyone can take the exam, obtaining the actual certification requires providing evidence of five years of professional work experience in IS auditing, control, or security. Some waivers are available for university degrees or related experience.
The CISA is highly respected in the finance, healthcare, and government sectors, often acting as a mandatory requirement for senior audit roles. However, it is important to understand that the role is heavily administrative and focused on documentation; it does not typically lead to "hands-on" technical engineering roles. It is a path toward governance, risk management, and compliance (GRC) leadership rather than technical implementation.
After mastering the audit perspective, professionals often look to broaden their expertise with other certifications: