ISACA

CISA

Certified Information Systems Auditor

The leading certification for IT auditors, assurance, and control professionals. Frequently required or preferred for IT audit, risk, and compliance roles and carries a strong wage premium.

$5754 hours

What's on the exam

CISA Job Practice (effective 1 August 2024)

Information Systems Auditing Process

18%

Audit planning and risk-based strategy · Audit execution and evidence · Sampling and analytics · Reporting and follow-up · IS audit standards and ethics

Governance and Management of IT

18%

IT governance frameworks · IT strategy and policies · Organizational structure and roles · Enterprise risk management · IT resource and portfolio management

Information Systems Acquisition, Development, and Implementation

12%

Project management and SDLC · Requirements and feasibility · Application controls · Testing and implementation · Post-implementation review

Information Systems Operations and Business Resilience

26%

IT operations and service management · Database and infrastructure management · Business continuity planning · Disaster recovery · Incident and problem management

Protection of Information Assets

26%

Information security frameworks · Identity and access management · Network and endpoint security · Data classification and encryption · Security event monitoring and response

Frequently asked questions

How much does the CISA cost?

The CISA costs $575. US$575 for ISACA members, US$760 for non-members; plus a one-time application fee for certification.

How long is the CISA and how many questions does it have?

150 items — 4 hours.

What do you need to pass the CISA?

450 on a scale of 200–800.

Can you retake the CISA?

Up to 4 attempts per 12-month period.

What is the best way to study for the CISA?

Study the official blueprint, not random material: the exam is weighted by domain (Information Systems Auditing Process 18%, Governance and Management of IT 18%, Information Systems Acquisition, Development, and Implementation 12%, Information Systems Operations and Business Resilience 26%, Protection of Information Assets 26%). Spaced-repetition flashcards built domain-by-domain against that blueprint are the most time-efficient way to cover everything the exam tests.

Program in development

We're building a blueprint-complete program for this exam. Meanwhile, explore live programs across 11 exam.

Explore programs →