ISACA CISA: Inside the Current Exam Scope

The current CISA exam uses ISACA’s exam content outline effective from August 2024 and remains built around five job-practice domains. The CISA exam contains 150 multiple-choice questions and allows four hours. ISACA reports scores on a 200–800 scale and requires 450 or higher to pass. The exam is compensatory: the final score is based on overall performance rather than a separate pass mark in each domain.

The current domain weights are 18% Information System Auditing Process, 18% Governance & Management of IT, 12% Information Systems Acquisition, Development & Implementation, 26% Information Systems Operations & Business Resilience, and 26% Protection of Information Assets.

Domain 1: Information System Auditing Process is 18%

This domain covers audit standards, guidelines, ethics, audit and assessment types, risk-based audit planning, control types, project management, testing and sampling, evidence collection, data analytics, reporting, and audit quality improvement.

The CISA perspective is independent assurance. The auditor evaluates whether controls are designed and operating effectively; the auditor should avoid becoming the owner of the control being audited.

Risk-based audit planning is the core of Domain 1

Audit resources are limited, so planning should focus on areas with the greatest potential impact and likelihood. The auditor considers business objectives, risk assessments, prior findings, regulatory obligations, system criticality, and recent change.

A CISA audit approach therefore begins with why the audit matters before choosing test procedures.

Evidence must be sufficient, reliable, and relevant

Interviews, documents, observation, system-generated data, reperformance, sampling, and analytics provide different levels of assurance. The auditor should understand the source, completeness, integrity, and limitations of evidence.

A control owner’s statement can be useful context, but it is usually weaker than independent or system-generated evidence that demonstrates actual operation.

Domain 2: Governance & Management of IT is 18%

This domain covers laws and regulations, organizational structure, IT governance and strategy, policies/standards/procedures, enterprise architecture, enterprise risk management, privacy, data governance/classification, resource management, vendor management, performance reporting, and IT quality management.

The auditor evaluates whether IT supports enterprise objectives and whether governance establishes accountability, oversight, and measurable performance.

Domain 3: Acquisition, Development & Implementation is 12%

This is the smallest domain, but it covers high-impact change: project governance, business cases, feasibility, system development methodologies, control identification/design, readiness and implementation testing, configuration/release management, migration, infrastructure deployment, data conversion, and post-implementation review.

The auditor should evaluate whether controls are built into the solution lifecycle rather than discovered after production launch.

Domain 4: Operations & Business Resilience is 26%

Operations includes IT components, assets, job scheduling, interfaces, shadow IT and end-user computing, capacity/availability, problem and incident management, change/configuration/patch management, logs, service levels, and database management.

Business resilience adds business impact analysis, operational resilience, backups/restoration, business continuity, and disaster recovery. This is one of the two largest CISA domains.

Resilience is broader than backup

A backup can protect data but does not prove that a business process can continue. CISA candidates should understand dependencies, recovery priorities, RTO/RPO concepts, alternate processing, testing, communications, and post-exercise improvement.

Auditors evaluate whether resilience plans reflect business impact rather than whether a single backup job reports success.

Domain 5: Protection of Information Assets is 26%

The other largest domain covers security frameworks, physical/environmental controls, IAM, network and endpoint security, DLP, encryption, PKI, cloud/virtualized environments, mobile/wireless/IoT, awareness, attack methods, security testing, monitoring, incident response, evidence collection, and forensics.

Cybersecurity is therefore a major CISA topic, but the exam asks an auditor to evaluate controls and assurance rather than configure every security product.

Certification requires more than passing the exam

ISACA allows anyone interested to take the exam, but full CISA certification requires meeting experience requirements. ISACA currently states that applicants need five or more years of professional information-systems auditing, control, or security work experience and must apply within five years of passing.

The CISA Associate designation also provides a path for eligible exam passers who have not yet accumulated the experience for full certification.

The current CISA is an assurance and business-context exam

Across all five domains, the recurring questions are whether governance, controls, evidence, operations, security, and resilience support business objectives. The auditor observes, tests, evaluates, communicates, and recommends improvement while preserving independence.

ISACA’s current candidate guide states that CISA uses 150 multiple-choice questions in a four-hour testing window. Some questions are pretest items and do not contribute to the score, but candidates are not told which ones. ISACA advises answering every question because there is no penalty for an incorrect answer and unanswered items cannot help the final score.

The 450 passing mark is a scaled score rather than a percentage. ISACA converts raw performance to a 200–800 scale so different exam forms remain comparable. A domain result can help identify strengths and weaknesses after the exam, but the overall scaled result determines pass or fail.

Domain 1 begins before any test procedure is chosen. Audit standards, ethics, independence, risk-based planning, and control concepts establish how the engagement should be performed. If the scope or criteria are unclear, detailed technical testing can produce impressive evidence about the wrong question.

Audit sampling deserves separate attention because an auditor rarely tests every transaction or configuration item in a large population. The sample should be selected using an approach appropriate to the objective and population. Bias, incomplete populations, or weak sample sizes can undermine an otherwise well-executed test.

Data analytics now sits explicitly in the audit-process domain. Auditors may analyze full populations for unusual transactions, duplicate accounts, privileged activity, or control exceptions. Analytics can expand coverage, but the auditor still needs to validate data completeness and understand whether the algorithm actually tests the relevant risk.

Reporting and communication matter because an audit finding is useful only if stakeholders understand the condition, risk, evidence, and recommended action. Reports should be accurate, balanced, and timely. Overstating a weak issue can damage credibility just as much as understating a serious one.

Domain 2’s governance topics include privacy and data governance because information has business, regulatory, and ethical value beyond IT operations. Auditors should understand data ownership, classification, retention, privacy principles, and accountability enough to evaluate whether governance aligns with applicable requirements.

Vendor management is also a governance issue. Outsourcing a service does not outsource the organization’s accountability. The auditor may review due diligence, contracts, security/privacy clauses, service levels, monitoring, incident notification, business continuity, and exit arrangements for critical third parties.

IT performance monitoring should connect metrics to enterprise objectives. A large number of closed tickets or completed changes may look positive while customer satisfaction or service availability declines. Audit evaluates whether management information supports decisions rather than whether the organization has many dashboards.

Domain 3’s project-governance topics can include predictive, agile, or hybrid development environments. The audit question is whether governance, controls, testing, approval, segregation of duties, and traceability remain appropriate to the chosen method. Agile delivery does not eliminate control; it changes the cadence and artifacts.

Implementation testing should include business readiness, security, data conversion, interfaces, and user acceptance according to the project risk. A system can pass technical tests and still fail because converted data is incomplete, operational procedures are not ready, or users cannot perform critical business processes.

Post-implementation review closes the change lifecycle. The auditor can examine whether objectives and benefits were achieved, controls operate as intended, costs remain within expectations, unresolved issues are owned, and lessons are fed back into future projects.

Domain 4 explicitly includes shadow IT and end-user computing because uncontrolled spreadsheets, scripts, SaaS applications, or local databases can become critical business systems without traditional IT governance. Auditors should assess the risk and whether compensating controls, ownership, backup, and review are adequate.

Change, configuration, release, and patch management belong together because all alter the production environment. Strong processes define authorization, testing, segregation, emergency procedures, rollback, evidence, and post-change validation. Repeated emergency changes can indicate a weak planning or release process.

Log management is more than retention. Organizations need to determine which events are collected, protected from tampering, time-synchronized, reviewed, and retained according to operational, security, or legal needs. An audit can test both configuration and whether important events receive timely attention.

Domain 5’s identity and access topics should be evaluated through the full lifecycle: request, approval, provisioning, authentication, authorization, privileged access, periodic review, and removal. A strong login control does not compensate for stale accounts or excessive roles that were never reviewed.

Cloud and virtualized environments create shared-responsibility questions. Auditors need enough cloud architecture knowledge to understand what the provider manages, what the customer configures, and which evidence demonstrates control effectiveness across the boundary.

Security testing tools and techniques can include vulnerability assessment, penetration testing, configuration review, and other technical methods. The auditor should understand purpose, authorization, scope, and limitations. A tool finding is evidence to evaluate, not an automatic audit conclusion.

Incident response and forensics connect security operations with legal and evidence requirements. Evidence collection should preserve integrity and chain of custody where necessary. The auditor can evaluate whether incidents are classified, escalated, contained, investigated, communicated, and used to improve controls.

The CISA Associate designation, introduced for eligible exam passers who lack the required professional experience, reinforces an important distinction: passing the knowledge exam and meeting certification-experience requirements are separate milestones. Candidates can build audit credibility through the exam while continuing to accumulate practical experience.

Use the domain weights as study guidance, not as permission to ignore smaller areas. A 12% development question can still be decisive, and audit-process principles from Domain 1 influence how you answer operational or security scenarios throughout the exam.

Within the broader ISACA certification portfolio, CISA remains centered on audit, control, and assurance. The strongest preparation combines technical literacy with audit judgment and business context.