Information systems auditing, control assessment and assurance
CISA is the audit-side credential: information systems auditing, governance and control, risk management, and the IS audit process end to end. It is the most widely held IS audit certification and the one auditors and assurance teams screen for when moving into or up in audit roles.
ISACA
CISA Overview
Exam Format & Timing
A proctored exam of multiple-choice items across the CISA domains covering IS audit process, governance, risk, control and information asset protection.
Penalty Rule
Set by the issuer — most vendor exams apply none
Recertification Cycle
CISA renews annually through a continuing-education programme with a required CPE reporting and annual maintenance fee.
Published Domains
4 Domain Areas
Prerequisites & Eligibility
ISACA requires experience in the audit, control or security areas with waivers for education or certifications; the current waiver conditions are published by ISACA.
Certifications
Information Systems Auditing Process
Audit planning
Audit execution and reporting
Source: www.isaca.org
IS Acquisition, Development and Maintenance
Business continuity
Incident management
Source: www.isaca.org
Certifications
| Section | Questions | Marks per question | Section marks | Negative marking |
|---|---|---|---|---|
| Information Systems Auditing Process | Not published | Not published | Not published | Not published |
| Governance and Risk Management | Not published | Not published | Not published | Not published |
| Information Asset Protection | Not published | Not published | Not published | Not published |
| IS Acquisition, Development and Maintenance | Not published | Not published | Not published | Not published |
Official source: www.isaca.org
Score calculator
The official marks scheme for CISA is not published in our data yet, so there is no calculator we can stand behind. Check the notification below.
Certifications
2 topics · 35 questions
Practise Information Systems Auditing Process →2 topics · 29 questions
Practise IS Acquisition, Development and Maintenance →Tick each item as you finish revising it, then print the sheet with your browser's print option.
Official source: www.isaca.org
A proctored exam of multiple-choice items across the CISA domains covering IS audit process, governance, risk, control and information asset protection.
ISACA requires experience in the audit, control or security areas with waivers for education or certifications; the current waiver conditions are published by ISACA.
Eligibility as set by ISACA. A certification sets no age band or attempt cap; the prerequisite below is the only gate.
Prerequisites
ISACA requires experience in the audit, control or security areas with waivers for education or certifications; the current waiver conditions are published by ISACA.
Official source: www.isaca.org
Interactive Score Simulator
This issuer does not publish a numeric passing score, so there is no cutoff to simulate. Use this to estimate your practice accuracy; confirm the pass rule on the issuer's own page.
Penalty rule:
Most vendor exams do not deduct marks for incorrect answers — but the penalty rule is the issuer's to set. Confirm it in the issuer's exam policy before relying on it.
Projected accuracy
%
Subject- and topic-filtered practice across the Cybersecurity domains this certification covers
A daily plan that blends new practice with spaced revision of what you have already attempted
Per-topic mastery estimates that surface your weakest domains first
A rationale on every attempt, reactive to the specific mistake you made
Certifications
PMP
Project Management Professional (PMP)
PMI-ACP
Agile Certified Practitioner (PMI-ACP)
PRINCE2 Practitioner
PRINCE2 Project Management (Practitioner Level)
PMI-RMP
Risk Management Professional (PMI-RMP)
AWS SAA
AWS Certified Solutions Architect – Associate
AWS SAP
AWS Certified Solutions Architect – Professional
Azure AZ-104
Microsoft Certified: Azure Administrator Associate (AZ-104)
Azure AZ-305
Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
Questions
Not yet. No verified CISA question bank is available on Koshish yet, so no practice session is advertised — an empty screen is worse than an honest wait. The syllabus, exam pattern and eligibility are published here now, and the bank is listed as soon as it is verified.
Certified Information Systems Auditor (CISA) is examined across these areas: Information Systems Auditing Process; Governance and Risk Management; Information Asset Protection; IS Acquisition, Development and Maintenance. A proctored exam of multiple-choice items across the CISA domains covering IS audit process, governance, risk, control and information asset protection.
ISACA sets it, and it changes between policy versions. ISACA requires experience in the audit, control or security areas with waivers for education or certifications; the current waiver conditions are published by ISACA.
Every factual claim on this page traces to the official documents listed below. Each is published by the certifying or examining body, not by Koshish; follow a link to read the current version, because these details can change between cycles.