This guide provides a structured learning curriculum mapping to the official CISA exam objectives, covering audit process, IT governance, systems development, operations resilience, and information protection.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
16 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery CISAterm defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guideCISA Overview and IS Audit Basics
Objective 1.1 · Describe the purpose and scope of IS auditing and the CISA certification.
Audit Planning and Risk Assessment
Objective 1.2 · Plan an IS audit based on risk assessment and business objectives.
Audit Execution, Evidence, and Documentation
Objective 1.3 · Execute the audit, collect evidence, and document findings.
Audit Reporting and Follow-Up
Objective 1.4 · Report audit results and perform follow-up activities.
IT Governance and Strategic Alignment
Objective 2.1 · Evaluate the effectiveness of IT governance structures and strategic alignment.
IT Policies, Standards, and Procedures
Objective 2.2 · Evaluate the design and implementation of IT policies, standards, and procedures.
Risk Management and Compliance
Objective 2.3 · Evaluate IT risk management and compliance processes.
Information Systems Acquisition and Development
Objective 3.1 · Evaluate the processes for acquiring and developing information systems.
Project Management and Change Control
Objective 3.2 · Evaluate project management practices and change control processes.
System Implementation and Testing
Objective 3.3 · Evaluate system implementation, testing, and post-implementation review.
IT Operations and Service Management
Objective 4.1 · Evaluate IT operational processes and service management.
Business Resilience and Disaster Recovery
Objective 4.2 · Evaluate business continuity and disaster recovery planning.
Network and Infrastructure Security
Objective 5.1 · Evaluate network and infrastructure security controls.
Data Protection and Privacy
Objective 5.2 · Evaluate data protection and privacy controls.
Access Control and Identity Management
Objective 5.3 · Evaluate access control and identity management processes.
Incident Response and Security Monitoring
Objective 5.4 · Evaluate incident response and security monitoring capabilities.
Free CISA practice questions with full explanations. Test what you learn chapter by chapter.
CISA Practice Questions