ISACA Certified Information Systems Auditor

ISACA · CISA · Expert

ISACA · ISACA

ISACA Certified Information Systems Auditor

CISAactiveExpert
Official ISACA source · isaca.org

CISA · ● Active · Expert · ISACA


Exam facts

FieldValue
CostUSD $575 (ISACA member) / $760 (non-member)
Duration4 hours (240 minutes)
Questions150 multiple choice
Passing450 / 800 scaled score
FormatMultiple choice
DeliveryPearson VUE testing centers and OnVUE (remote proctored)
LanguagesEnglish (primary); regional language versions available
Valid3 years
Renewal120 Continuing Professional Education (CPE) credits within 3-year cycle; minimum 20 CPE per year
Prerequisites5 years cumulative information systems audit, control, security, or assurance experience. Substitutions allowed: relevant advanced degree (bachelor's or higher) reduces requirement by 1 year; relevant ISACA certification reduces requirement by up to 2 years. Minimum 1 year if degree + additional cert held.
Released1994 (original); continuous updates per ISACA exam content evolution
RetiringN/A

Vendor source — ISACA CISA Credentialing ↗ Official exam guide — CISA Candidate Guide & Handbook ↗ Exam objectives — CISA Exam Content Outline ↗


About

The Certified Information Systems Auditor (CISA) is ISACA's foundational-to-expert certification for IT audit, control, and governance professionals. Originally launched in 1994, CISA validates the ability to assess organizational IT infrastructure, design and evaluate controls, identify vulnerabilities, and ensure compliance with governance frameworks. Unlike technical security certs (CISSP, CEH), CISA focuses on audit methodology, control assessment, and risk-based auditing — making it the standard credential for internal auditors, external auditors, compliance officers, and risk managers in regulated industries. CISA holders typically manage audit programs, evaluate IT governance, and report control efficacy to boards and regulators.


Domain context — Audit / GRC

Governance, Risk, Compliance (GRC) and IT audit — assessing control design and operating effectiveness, evaluating IT governance maturity, managing audit programs, and ensuring organizational alignment with regulatory frameworks and industry standards.

Read full deep dive — ISACA Ecosystem →


Topics covered

CISA covers five knowledge domains, weighted by exam emphasis (total 150 questions):

  • Information Systems Auditing Process (18%) — Audit planning, scope definition, risk-based audit methodology, audit execution, evidence gathering, control evaluation, reporting, follow-up and compliance.
  • Governance and Management of IT (18%) — Organizational structure & IT governance frameworks (COBIT, ITIL, ISO 20000), IT strategy alignment, portfolio management, resource allocation, quality assurance, maturity models.
  • Information Systems Acquisition, Development, and Implementation (12%) — Systems development lifecycle (SDLC) control evaluation, application security design & testing, configuration management, change control, system acceptance & deployment.
  • Information Systems Operations and Business Resilience (26%) — IT operations management, incident management & problem resolution, availability & continuity planning (BC/DR), capacity & performance management, operational resilience, service management.
  • Protection of Information Assets (26%) — Physical & logical security controls, data classification & protection, access control design, encryption & key management, network security, endpoint protection, data loss prevention, privacy & data handling.

Source: ISACA CISA Exam Content Outline ↗


Common skills at Audit / GRC · Expert

Shared competencies for IT audit and GRC roles at expert level — not specific to CISA.

  • Control design & evaluation against COSO, COBIT, ISO 27001, NIST frameworks
  • Risk assessment & mitigation planning
  • Audit planning, execution, and evidence documentation
  • IT governance frameworks (COBIT, ITIL, ISO standards)
  • Regulatory compliance mapping (GDPR, HIPAA, SOC 2, PCI-DSS, ISO 27001)
  • Business continuity & disaster recovery program oversight
  • Incident investigation & root cause analysis
  • Audit reporting & stakeholder communication
  • IT maturity assessments & continuous improvement

Recommended courses at Audit / GRC · Expert

ProviderTitleCostURL
ISACA OfficialCISA Online Review Course$600–$800 (member) / $900–$1,100 (non-member)
Hemang DoshiMasterclass - CISA Exam (Updated 2026) (Udemy)$15–$100
Pocket PrepCISA Exam Prep App & Web$50–$100
CBT NuggetsCISA Certification Course$300–$600/yr
PluralsightCISA Study Path$300–$500/yr
INECISA Certification Training$200–$400/yr
KodeKloudCISA Preparation Course$150–$300

Course-selection rule: CISA courses should emphasize audit methodology, control assessment, and governance frameworks (COBIT, COSO, ISO 27001) — avoid purely technical security content.


Practice exams

ProviderTitleCostURL
ISACA OfficialCISA Official Practice Questions Database (QAE)$100–$150 (1,000+ questions)
Pocket PrepCISA Practice Exam Bank$50–$100
Hemang DoshiCISA Practice Exam Questions (Udemy)$15–$100
WhizlabsCISA Practice Exams$50–$80

Practice rule: The ISACA Official Questions and Explanations (QAE) database is the most accurate predictor of exam performance and should be prioritized.


Books

TitleAuthorPublisherYearISBNURL
CISA - Certified Information Systems Auditor Study Guide (3rd Edition)Hemang DoshiSelf-published / Udemy2024978-1835882863
CISA Certified Information Systems Auditor Study GuideHemang DoshiPackt Publishing2024978-1838989583
CISA Review Manual (28th Edition)ISACAISACA2024978-1-604-20246-8
CISA Exam-Study GuideHemang DoshiSelf-published2023978-1983328343

Book rule: The official ISACA CISA Review Manual (28th Edition) is the canonical reference; Hemang Doshi's Study Guides are widely recommended as practical, exam-focused supplements with 1,000+ practice questions.


Typical job titles at Audit / GRC · Expert

IT Auditor · Senior IT Auditor · Information Systems Auditor · Internal Audit Manager (IT focus) · External Auditor (Big 4 / audit firm) · Chief Audit Executive (CAE) with IT emphasis · Compliance Officer · Risk Manager (IT/technology focus) · GRC Manager

(Job titles drawn from current job-board postings that list CISA as required or preferred.)


Salary

RegionRangeSource
USD$90,000 – $150,000+ for IT Auditor / Senior Auditor / Audit Manager rolesPayScale ↗ · ZipRecruiter ↗ · InfoSec Institute ↗
ZARR700,000 – R1,200,000+ annually (IT audit / compliance roles in South Africa)Pnet ↗ · PayScale ZA ↗ · CareerJunction ↗
GBP£60,000 – £100,000+ for IT Auditor / compliance roles in UKIT Jobs Watch ↗ · Hays ↗
EUR€70,000 – €120,000+ (Germany/Netherlands IT audit & compliance)LinkedIn Salary EU ↗ · PayScale EU ↗
AUDA$100,000 – A$160,000+ for IT Auditor roles in AustraliaSeek ↗ · PayScale AU ↗

Salary note: CISA compensation is position-dependent; entry-level IT Auditors start lower, while Senior Auditors and Audit Managers (especially in regulated sectors: finance, healthcare, government) command premium salaries. Big 4 audit firms typically pay higher than corporate internal audit teams.


Skills validated

Cert-specific — what CISA actually tests, distinct from the shared "Common skills" above.

  • Audit methodology & planning (scoping, risk assessment, evidence collection)
  • IT control design & evaluation (preventive, detective, corrective controls)
  • IT governance frameworks (COBIT, COSO, ITIL, ISO 20000, ISO 27001)
  • Compliance assessment (GDPR, HIPAA, SOC 2, PCI-DSS, CMMC, CIS Controls)
  • IT security & physical controls evaluation
  • Business continuity & disaster recovery assessment
  • Incident investigation & root cause analysis
  • IT operations & service management evaluation
  • Risk management & mitigation planning
  • Audit reporting & stakeholder communication

Related certifications

  • Stacks with: ISACA CISM ↗ (security management focus) · [ISACA CRISC ↗]({file not yet created}) (risk & compliance focus)
  • Prerequisite for: [ISACA CAP ↗]({file not yet created}) (control & audit professional, builds on CISA)
  • Alternatives at this level: [CIA - Certified Internal Auditor ↗]({file not yet created}) (IIA; broader internal audit scope) · [CCSK - Cloud Security Knowledge ↗]({file not yet created}) (cloud-specific controls)
  • Vendor overview: ISACA Overview ↗

Sources


Last verified: 2026-05-01 Parent ecosystem: ISACA Ecosystem Parent domain: Audit / GRC Domain Vendor overview: ISACA Overview

Rate this cert
Was this helpful?
Comments ()
0/2000