CISA Exam Guide 2026: The Complete IS Audit Playbook
Master the Certified Information Systems Auditor exam — 5 domains, ISACA Job Practice 2024, and every deep-dive.
Quick answer: The Certified Information Systems Auditor (CISA) exam covers 5 domains under the 2024 Job Practice: IS Audit Process, Governance, Systems Acquisition, IT Operations, and Protection of Information Assets. This hub organizes every CISA resource.
Key facts
- Passing score:
- 450 on a 200-800 scale
- Structure:
- 150 MCQ across 5 domains
- Total time:
- 4 hours
- Domain weights (2024):
- D1 18%, D2 18%, D3 12%, D4 26%, D5 26%
- Official body:
- ISACA
Overview
The CISA exam punishes technical experts who forget their role. It’s not a test of what you can do, but how you think as an auditor—evaluating risk, assessing controls, and providing assurance. Your biggest challenge isn't memorizing frameworks, but internalizing the specific, risk-based judgment ISACA expects on every single question.
What Makes the CISA Exam So Deceptive?
The CISA exam is designed to filter for a very specific perspective: the independent auditor's mindset. Many candidates, especially those with hands-on IT or security experience, fail because they answer questions from the perspective of a system administrator or a security analyst. They see a problem and their instinct is to choose the answer that fixes it. This is a trap.
The exam is not testing your ability to configure a firewall; it's testing your ability to determine if the firewall change management process is adequate, documented, and followed.
You'll face 150 situational questions where multiple answers seem technically correct. The key is to find the answer that reflects the auditor's primary duty. An auditor doesn't implement solutions. An auditor:
- Assesses risk.
- Evaluates the effectiveness of controls.
- Gathers evidence.
- Reports findings to management.
- Recommends improvements to processes.
Your technical knowledge is the foundation, but the "ISACA way of thinking" is the lens through which you must view every scenario. If an answer involves taking direct operational action, it is almost certainly wrong.
Where to Focus Your First 40 Hours
With five domains and a vast body of knowledge, a smart initial plan is critical. While it's tempting to jump into the two largest domains, that approach skips the foundational mindset. Based on the 2024 Job Practice weights, here is how you should structure your first full week of study (approx. 40 hours) for maximum impact.
- Hours 1-10: Master Domain 1 (The IS Audit Process). This domain, at 18% of the exam, is your Rosetta Stone. It teaches you the language and lifecycle of an audit—from planning and evidence gathering to reporting and follow-up. Every single question in the other four domains assumes you understand the auditor's process and mandate. Mastering this first gives you the framework to correctly analyze questions in every other section.
- Hours 11-40: Deep Dive into Domains 4 & 5 (IT Operations & Protection of Information Assets). Combined, these two domains make up 52% of your total score. This is where the bulk of the technical concepts live—from network infrastructure and disaster recovery (D4) to encryption and identity management (D5). After building your auditor mindset in Domain 1, immediately apply it to these high-value areas. You need to be able to analyze a BCP test result or an access control list not as an engineer, but as an auditor evaluating its effectiveness against stated policy.
By front-loading your study this way, you build the correct analytical framework first, then apply it immediately to the majority of the exam's content. Domains 2 (Governance) and 3 (Systems Acquisition) can then be layered on top of this strong foundation.
The Practitioner-vs-Auditor Mindset Trap
The single biggest failure point on the CISA exam is answering questions as a hands-on practitioner. You must train yourself to pause and shift your perspective before selecting an answer. Your real-world experience is valuable, but it can also be a liability if you don't filter it through the auditor's lens.
Burn this table into your memory. For every question you practice, identify which column the potential answers fall into.
| Practitioner's Instinct (Usually the WRONG Answer) | Auditor's Mindset (Usually the RIGHT Answer) |
|---|---|
| "Fix the immediate technical problem." | "Assess the root cause of the control failure." |
| "Implement a new security tool." | "Determine if the current process is effective." |
| "Reconfigure the system for compliance." | "Gather evidence to report on non-compliance." |
| "This configuration is insecure." | "This configuration deviates from policy and increases risk." |
| Focus on the technology. | Focus on the process, governance, and risk. |
Before you finalize your answer on the exam, ask yourself one final question: "Does this action involve doing the work, or does it involve evaluating the work?" The CISA credential is for evaluators. Choose the answer that reflects that role, every time.
Study by section
CISA Domain 3 Guide
Master the processes for acquiring, developing, and implementing information systems to ensure they meet your organization's strategic objectives.
CISA Domain 1 Guide
Master the complete IS audit lifecycle, from risk-based planning and standards to execution and reporting for your CISA exam.
Every guide in this cluster (26)
Every published article that belongs to this cluster, organized by type. New content is added continuously.
Study Guides (6)
- → CISA Information Systems Auditing Process: IS Audit Standards and Guidelines — Complete Study Guide
- → CISA Information Systems Acquisition & Development: Vendor Evaluation — Complete Study Guide
- → Complete CISA IS Operations and Business Resilience Study Guide 2026
- → Complete CISA Governance and Management of IT Study Guide 2026
- → CISA Information Systems Acquisition & Development: Agile and DevOps — Complete Study Guide
- → CISA Domain 3 Study Guide: SDLC & Project Management
Cheat Sheets (5)
- → CISA Protection of Information Assets Cheat Sheet (2026): Key Formulas, Rules, and Mnemonics
- → CISA IS Acquisition, Development & Implementation Cheat Sheet (2026): Key Formulas, Rules, and Mnemonics
- → CISA IT Governance Domain 1 Study Guide (2026)
- → CISA Information Systems Auditing Process Cheat Sheet (2026): Key Formulas, Rules, and Mnemonics
- → CISA IS Operations and Business Resilience Cheat Sheet (2026): Key Formulas, Rules, and Mnemonics