CISA Exam Preparation Guide: Domains, Format, and Study Plan

A current CISA study workflow for audit, governance, systems lifecycle, resilience, and protection of information assets.

CertGuru Editorial Team · Published 2026-07-20 · Reviewed 2026-07-20 · 10 min read

What is the CISA exam?

ISACA's Certified Information Systems Auditor exam contains 150 questions across five job-practice domains. It tests audit, governance, systems lifecycle, operations and resilience, and protection of information assets through decisions grounded in professional practice.

Candidates often arrive with deep experience in one area. A security engineer may be strong in protection controls but less familiar with audit evidence; an auditor may need more systems-development or technical operations review. A useful CISA exam preparation guide therefore starts with domain evidence rather than years of general IT experience.

Current CISA domains

The official outline covers:

  • Information Systems Auditing Process: 18%;
  • Governance and Management of IT: 18%;
  • Information Systems Acquisition, Development and Implementation: 12%;
  • Information Systems Operations and Business Resilience: 26%; and
  • Protection of Information Assets: 26%.

Use ISACA's current outline as the authority. Do not assume a previous edition's weighting or terminology remains unchanged.

Learn the IS auditor's decision perspective

CISA questions frequently present several actions that appear useful. The stronger response depends on independence, evidence, materiality, risk, governance, and the stage of the audit or system lifecycle.

Before choosing an answer, ask:

  1. What is the objective of the audit or control?
  2. What evidence is available and is it sufficient and reliable?
  3. Which risk is most material?
  4. Who owns the decision or remediation?
  5. What should the auditor do next without assuming management's role?

This prevents technical familiarity from overriding audit discipline.

How to study the five CISA domains

Auditing process

Cover standards, ethics, planning, risk-based scoping, controls, sampling, evidence, data analytics, reporting, and follow-up. Practise distinguishing a finding from its evidence, cause, risk, and recommendation.

Governance and management of IT

Study strategy alignment, policies, organizational structure, enterprise architecture, resource management, performance, quality, and third-party oversight.

Acquisition, development and implementation

Review business cases, project governance, requirements, development approaches, testing, migration, post-implementation review, and control design across the system lifecycle.

Operations and business resilience

Connect service management, change and configuration, capacity, incident and problem management, backup, business impact analysis, continuity, and disaster recovery.

Protection of information assets

Study frameworks, identity, networks, endpoints, data loss prevention, encryption, PKI, cloud, mobile and IoT, awareness, monitoring, security testing, and incident response.

A seven-week CISA study schedule

  • Week 1: outline review and diagnostic mock.
  • Week 2: audit process and evidence.
  • Week 3: governance and management.
  • Week 4: acquisition, development, and implementation.
  • Week 5: operations and resilience.
  • Week 6: protection of information assets.
  • Week 7: mixed scenarios, full mock, and targeted correction.

Allocate time from the diagnostic, not only from domain weights. A lower-weight domain can still be the main risk if it is unfamiliar.

Review CISA practice questions correctly

For each miss, note the audit stage, role, governing principle, and why the selected action was premature or incomplete. Watch for errors such as implementing a control yourself, escalating before validating evidence, or choosing a technically ideal control without considering risk and governance.

Track uncertain correct answers as gaps. If you cannot explain why three options are weaker, a changed scenario may reverse the result.

CISA-related professional pathways

The body of knowledge aligns with information-systems audit, assurance, risk, governance, controls, compliance, and technology oversight. Holding the credential does not guarantee a role, and earning certification involves ISACA requirements beyond passing the exam. Confirm experience and application rules directly with ISACA.

Open the CertGuru CISA mock exam for a timed baseline, then turn the domain report into actions with the mock-results review guide. Candidates comparing management-focused security can also read the CISM 2026 exam guide.

CertGuru is independent and is not affiliated with or endorsed by ISACA.

Authoritative references

Review ISACA's current outline, eligibility, scheduling, and certification requirements before acting.