Official details for CISA Certification Exam Guide – Certified Information Systems Auditor (CISA) as published by the certification body.
The CISA Certification (Certified Information Systems Auditor) is a globally recognized credential offered by ISACA for professionals responsible for auditing, monitoring, controlling, and assessing information systems and business processes.
The official Certified Information Systems Auditor exam consists of 150 multiple-choice questions, has a 240-minute (4-hour) testing duration, requires a scaled passing score of 450 out of 800, and costs USD $575 for ISACA members and USD $760 for non-members. The exam is delivered through computer-based testing at PSI testing centers worldwide or via remote proctoring. Candidates receive a six-month eligibility period after registration.
Organizations worldwide recognize the CISA certification exam as the gold standard for information systems auditing, governance, risk management, compliance, and cybersecurity assurance. The certification demonstrates a professional's ability to evaluate vulnerabilities, implement controls, ensure compliance, and improve enterprise information systems.
The Certified Information Systems Auditor (CISA) credential was introduced by ISACA in 1978 and has become one of the most prestigious certifications for IT auditors, cybersecurity professionals, governance specialists, compliance officers, and risk managers.
The certification validates knowledge and practical expertise in:
Information Systems Auditing
IT Governance
Risk Management
Information Security Controls
Business Resilience
Regulatory Compliance
IT Operations
Enterprise Risk Assessment
Professionals holding the CISA credential are often responsible for ensuring that enterprise technology systems align with business objectives while maintaining security, integrity, availability, and compliance requirements.
Certification Detail | Information |
|---|---|
Exam Name | Certified Information Systems Auditor (CISA) |
Exam Code | CISA |
Provider | ISACA |
Exam Format | Multiple Choice |
Questions | 150 |
Duration | 240 Minutes |
Passing Score | 450/800 Scaled Score |
Exam Cost | USD $575 Member / USD $760 Non-Member |
Delivery Method | PSI Test Center or Remote Proctoring |
Certification Level | Professional |
Languages | Multiple Languages Available |
Registration | Year-Round |
Eligibility Window | 6 Months After Registration |
The CISA certification is considered one of the most valuable credentials in information systems auditing and governance.
Benefits include:
Global recognition
Increased earning potential
Enhanced credibility
Leadership opportunities
Greater job security
Higher demand across industries
Improved cybersecurity career prospects
ISACA reports that many CISA-certified professionals experience career advancement and salary growth after certification.
The CISA examination measures a candidate's ability to:
Conduct information systems audits
Evaluate internal controls
Assess enterprise risks
Review IT governance frameworks
Analyze system acquisition processes
Monitor operational resilience
Protect information assets
Support regulatory compliance initiatives
Evaluate cybersecurity controls
Recommend risk mitigation strategies
The exam evaluates knowledge across five core domains:
Focus areas include:
Audit planning
Risk assessment
Audit execution
Evidence collection
Reporting findings
Follow-up activities
Topics include:
IT governance frameworks
Strategic alignment
Resource management
Risk management
Performance monitoring
Coverage includes:
Business case development
Project governance
Systems development lifecycle
Change management
Implementation reviews
Topics include:
IT operations
Incident management
Disaster recovery
Business continuity
Service delivery
Coverage includes:
Information security
Access controls
Identity management
Network security
Data protection
Security monitoring
Domain | Weight |
|---|---|
Information Systems Auditing Process | 18% |
Governance and Management of IT | 18% |
Information Systems Acquisition, Development and Implementation | 12% |
Information Systems Operations and Business Resilience | 26% |
Protection of Information Assets | 26% |
Candidates may take the exam before meeting experience requirements.
To earn the certification, ISACA requires:
Five years of professional experience in IS auditing, control, assurance, or security.
Experience substitutions may reduce requirements by up to three years.
Ideal candidates include:
IT Auditors
Internal Auditors
External Auditors
Cybersecurity Analysts
Information Security Managers
Risk Analysts
Compliance Officers
Governance Professionals
IT Consultants
After obtaining the CISA Certification, professionals may pursue roles such as:
Job Role | Average Salary Range |
|---|---|
IT Auditor | $85,000 - $150,000 |
Senior IT Auditor | $110,000 - $180,000 |
Information Security Auditor | $100,000 - $170,000 |
Compliance Manager | $110,000 - $190,000 |
Risk Manager | $120,000 - $200,000 |
IT Governance Manager | $125,000 - $210,000 |
Cybersecurity Manager | $130,000 - $220,000 |
Industry surveys consistently rank CISA among the highest-paying IT certifications.
Professionals holding the certification often earn significantly more than non-certified peers because organizations value expertise in:
Audit assurance
Governance
Compliance
Cybersecurity
Risk management
To maintain certification status, holders must:
Earn 120 Continuing Professional Education (CPE) hours every three years
Earn at least 20 CPE hours annually
Pay annual maintenance fees
Comply with ISACA's Code of Professional Ethics
Create an ISACA account.
Purchase the CISA exam registration.
Receive exam eligibility.
Schedule your exam through PSI.
Take the exam at a testing center or remotely.
Candidates can generally schedule testing appointments approximately 48 hours after payment.
Recommended study materials include:
Official ISACA CISA Review Manual
ISACA Question, Answer & Explanation Database (QAE)
Official CISA Online Review Course
Practice exams
Study groups
Instructor-led training
Review Domain 1 and Domain 2.
Study Domain 3 and Domain 4.
Master Domain 5.
Complete multiple CISA practice exams.
Review weak areas and take mock tests.
Many candidates struggle with:
Understanding ISACA's audit-focused mindset
Scenario-based questions
Governance concepts
Choosing the "best" answer among multiple valid options
Time management during lengthy scenarios
Community discussions frequently emphasize learning ISACA's methodology rather than relying solely on technical experience.
Common exam themes include:
Risk-based auditing
IT governance
Business continuity planning
Disaster recovery
Information security management
Access controls
System acquisition
Project management
Regulatory compliance
Control frameworks
Arrive early.
Read every question carefully.
Eliminate incorrect options first.
Focus on the auditor's perspective.
Manage time effectively.
Flag difficult questions for review.
Answer every question.
There is no penalty for incorrect answers.
Professionals pursuing CISA often consider:
CISM
CRISC
CISSP
CCSP
CIA
Recent CISA updates continue to emphasize:
Cybersecurity governance
Cloud security controls
Emerging technologies
AI-related risks
Enterprise resilience
Risk-based auditing practices
ISACA regularly updates exam content to align with current industry requirements.
IT Support
Junior Auditor
Security Analyst
IT Auditor
Compliance Analyst
Risk Specialist
Senior IT Auditor
Governance Manager
Security Manager
Director of Audit
Chief Risk Officer
Chief Information Security Officer
Demand for professionals with auditing and governance expertise continues to grow due to:
Increasing cybersecurity threats
Regulatory requirements
Digital transformation
Cloud adoption
Third-party risk management
Organizations across banking, healthcare, government, manufacturing, and consulting actively recruit CISA-certified professionals.
CISA professionals perform activities such as:
Conducting IT audits
Evaluating security controls
Assessing compliance programs
Reviewing cloud migrations
Supporting regulatory examinations
Investigating security incidents
Improving governance frameworks
Employers increasingly seek candidates with:
Audit experience
Governance knowledge
Risk management expertise
Security awareness
Regulatory compliance skills
CISA remains one of the most frequently requested certifications for IT audit and assurance positions.
Certification | Focus Area | Best For |
|---|---|---|
CISA | IT Audit & Assurance | Auditors |
CISM | Security Management | Security Managers |
CRISC | Risk Management | Risk Professionals |
CISSP | Security Architecture | Security Leaders |
CIA | Internal Audit | Internal Auditors |
Thousands of professionals worldwide have leveraged the CISA certification exam to:
Transition into IT auditing
Move into cybersecurity leadership
Secure consulting roles
Increase compensation
Gain international career opportunities
ISACA reports strong career impact and professional recognition among certified members.
The CISA Certification remains one of the most respected credentials for information systems auditing, governance, risk management, and cybersecurity assurance professionals. The Certified Information Systems Auditor exam validates the knowledge and practical skills required to assess enterprise systems, identify risks, ensure compliance, and improve organizational security. Whether your goal is career advancement, higher earning potential, or global recognition, earning the CISA certification can be a significant step toward becoming a trusted IT audit and governance professional.
Same exams as Featured on home
Explore exam
Explore exam