CISA certification exam
Computer-based professional knowledge assessment
- Type
- Written
- Delivery
- Both
Passing score: 450 ISACA scaled score
Exam sections
Information Systems Auditing Process
The “Information Systems Auditing Process” portion of CISA — Certified Information Systems Auditor focuses on objectives, accountable roles, risk significance, evidence quality, sequence of action, and defensible conclusions. A complete response should recognize the responsible party, judge what evidence is still missing, and select the defensible next response. It leads into “Governance & Management Of IT” in the published outline.
Question notes
Before acting on “Information Systems Auditing Process,” read the full scenario; the credential holder's accountability determines which action is appropriate at that point in the case. Test the response for a weak factual basis, ambiguous accountability, unsupported conclusions, or an intervention focused on what is visible instead of the actual exposure. Confirm the outcome with traceability from objective to risk, evidence, judgment, conclusion, and stakeholder communication. Use the stored weighting for relative study priority; it does not reveal how many questions will appear.
Preparation tips
For “Information Systems Auditing Process,” use an explain–perform–verify loop. Exercise: Write a short case, identify the responsible role and evidence needed, compare plausible responses, and justify which action comes first. Explain how this evidence confirms the “Information Systems Auditing Process” result: traceability from objective to risk, evidence, judgment, conclusion, and stakeholder communication. Also test for poor supporting information, uncertain decision rights, findings beyond the evidence, or action taken against a secondary issue rather than the actual exposure. Explain which assumptions this leaves for “Governance & Management Of IT”.
Governance & Management Of IT
At the center of “Governance & Management Of IT” is objectives, decision ownership, risk significance, fitness of supporting information, sequence of action, and supportable conclusions. The assessable outcome is not recall, but an ability to establish decision ownership, determine the necessary evidence, and choose the action appropriate to that stage of the case. In the published sequence, it follows “Information Systems Auditing Process” and precedes “Information Systems Acquisition, Development & Implementation”.
Question notes
Prepare “Governance & Management Of IT” within the credential's wider flow, since evidence, risk significance, and sequence often distinguish the strongest answer from a partial one. A defensible response accounts for a weak factual basis, ambiguous accountability, unsupported conclusions, or an intervention focused on what is visible instead of the risk driving the case. Its support should include traceability from objective to risk, evidence, judgment, conclusion, and stakeholder communication. Use the structured percentage for blueprint emphasis, not to guess how many questions will appear.
Preparation tips
Keep a short decision journal for “Governance & Management Of IT.” Complete this exercise: Compare management, implementation, and assurance perspectives on the same case and document why their next actions differ. Record whether you detected or prevented poor supporting information, uncertain decision rights, findings beyond the evidence, or corrective work that addresses an effect but not the actual exposure. Attach an auditable connection between purpose and risk, evidence, judgment, conclusion, and stakeholder communication. Use the verified outcome to predict the decisions needed in “Information Systems Acquisition, Development & Implementation”.
Information Systems Acquisition, Development & Implementation
The “Information Systems Acquisition, Development & Implementation” portion of CISA — Certified Information Systems Auditor focuses on the purpose of “Information Systems Acquisition, Development & Implementation,” the operating conditions around it and the evidence that turns an apparent outcome into a credible one. A complete response should translate “Information Systems Acquisition, Development & Implementation” into a realistic case, select or carry out a defensible response, and confirm the outcome. In the published sequence, it follows “Governance & Management Of IT” and precedes “Information Systems Operations & Business Resilience”.
Question notes
Expect “Information Systems Acquisition, Development & Implementation” to appear in context because the expected judgment should remain proportional to risk and consistent with governance responsibilities. Do not accept a “Information Systems Acquisition, Development & Implementation” response until it rules out an assumption about “Information Systems Acquisition, Development & Implementation” that was never tested, or a sequence accepted without a reliable completion check. Evidence to look for: a trace connecting the “Information Systems Acquisition, Development & Implementation” requirement, chosen response, and independently reviewed result. Use the stored percentage for relative blueprint emphasis, not as a guarantee of exact assessment presentation.
Preparation tips
Keep a short decision journal for “Information Systems Acquisition, Development & Implementation.” Complete this exercise: Practice “Information Systems Acquisition, Development & Implementation” under a deliberately different condition, then explain which logic survives the change. Record whether you detected or prevented accepting work on “Information Systems Acquisition, Development & Implementation” until the reasoning and result are reproducible by another practitioner. Attach evidence that a changed “Information Systems Acquisition, Development & Implementation” constraint does not invalidate the result. Repeat the review as the practitioner responsible for “Information Systems Operations & Business Resilience”.
Information Systems Operations & Business Resilience
At the center of “Information Systems Operations & Business Resilience” is resilience boundaries, redundancy, capacity, recovery behavior, operational visibility, and safe change under load. In this credential, candidates demonstrate whether they can demonstrate how the service behaves when one dependency degrades and how integrity is checked after recovery. In the published sequence, it follows “Information Systems Acquisition, Development & Implementation” and precedes “Protection Of Information Assets”.
Question notes
The assessment may connect “Information Systems Operations & Business Resilience” with other objectives: the expected judgment should remain proportional to risk and consistent with governance responsibilities. A weak result can be exposed by an unverified failover behavior, shared failure dependency, insufficient capacity, or recovery without integrity checking. A complete result leaves health and readiness signals, failover events, recovery observations, consistency checks, and service behavior after restoration. Official blueprint weighting is stored independently; no isolated timing or inventory is inferred from it.
Preparation tips
Turn “Information Systems Operations & Business Resilience” into a reviewable practice artifact. Exercise: Create a healthy baseline, remove or degrade one dependency, observe failover, restore service, and confirm state consistency. Challenge condition: an unverified failover behavior, shared failure dependency, insufficient capacity, or recovery without integrity checking. Completion evidence: recorded health state, failover events, recovery observations, consistency checks, and service behavior after restoration. Close by tracing the effect on “Protection Of Information Assets”.
Protection Of Information Assets
The role of “Protection Of Information Assets” in CISA — Certified Information Systems Auditor is to assess where “Protection Of Information Assets” belongs in the end-to-end process and which operating assumptions determine the right choice. The assessment reaches beyond recognition and requires an ability to explain the purpose of “Protection Of Information Assets,” identify its connected conditions, and make the final response defensible through evidence. It draws on work established in “Information Systems Operations & Business Resilience”.
Question notes
Prepare “Protection Of Information Assets” within the credential's wider flow, since the best response should align with professional practice rather than the most immediately technical action. A defensible response accounts for completing the visible part of “Protection Of Information Assets” and overlooks an exception, a relevant stakeholder concern, or later operational impact. Its support should include a repeatable “Protection Of Information Assets” result, reasoning another practitioner can follow, and proof that the objective was satisfied. Use the dedicated weight field for published emphasis rather than deriving a question count from this note.
Preparation tips
Turn “Protection Of Information Assets” into a reviewable practice artifact. Exercise: Practice “Protection Of Information Assets” with a different operating condition and identify what transfers from the first solution. Challenge condition: an assumption about “Protection Of Information Assets” that was never tested, or a sequence accepted without a reliable completion check. Completion evidence: before-and-after observations for “Protection Of Information Assets,” with the basis for the decision and observable support for accepting the outcome. Compare the result with the assumptions established during “Information Systems Operations & Business Resilience”.
