What's on the exam
CISA (Certified Information Systems Auditor) domains explained
Information Systems Auditing Process — 21%
Covers planning and performing IS audits to standards — risk-based audit strategy, evidence collection, sampling, and reporting findings and follow-up.
Governance and Management of IT — 17%
Covers IT governance and strategy, policies, organizational structure, IT management practices, and alignment of IT with business objectives.
IS Acquisition, Development & Implementation — 12%
Covers evaluating practices for acquiring, developing, testing, and implementing information systems, applications, and infrastructure.
IS Operations & Business Resilience — 23%
Covers IT operations and service management, business continuity, disaster recovery, and the resilience of information systems.
Protection of Information Assets — 27%
Covers information-asset security — access controls, network and endpoint security, encryption, and physical and environmental protection.
FAQ
CISA (Certified Information Systems Auditor) study plan questions
How long should I study for CISA (Certified Information Systems Auditor)?
A typical CISA (Certified Information Systems Auditor) study plan takes about 12 weeks. Shorten that if you already score well on practice tests, or extend it if the official objectives are new to you.
What is the best course for CISA (Certified Information Systems Auditor)?
The best course for CISA (Certified Information Systems Auditor) is one that maps lessons to the current exam domains and includes practice questions. This page recommends Masterclass - CISA Exam (Hemang Doshi, updated 2026) as the core course to review first.
Which CISA (Certified Information Systems Auditor) domain should I study first?
Start with Protection of Information Assets, because it carries about 27% of the exam blueprint, then move through lower-weight domains while tracking weak areas.
How does the free PrepPath planner help?
PrepPath turns your exam date, daily study hours, and confidence by domain into a calendar you can follow, then adjusts your focus after practice scores.
How many hours a day should I study for CISA (Certified Information Systems Auditor)?
Most candidates do well with about 1–2 focused hours on study days across a 12-week plan, ramping up in the final weeks for timed practice. Consistency beats marathon sessions — PrepPath spaces each domain out so you revisit it instead of cramming.
How many practice tests should I take before CISA (Certified Information Systems Auditor)?
Aim for at least 2–3 full, timed mock exams: one early to set a baseline, then more in the final third of your plan. Review every wrong answer and tag the domain it came from so PrepPath can rebalance your remaining days toward your real weak spots.