Information systems auditing, control assessment and assurance
Certified Information Systems Auditor (CISA) is a professional-level credential from ISACA, examined as follows: A proctored exam of multiple-choice items across the CISA domains covering IS audit process, governance, risk, control and information asset protection. The areas it covers are Information Systems Auditing Process, Governance and Risk Management, Information Asset Protection and IS Acquisition, Development and Maintenance. This page sets out what ISACA publishes about the exam and what Koshish does not yet have questions for.
ISACA
CISA Overview
Exam Format & Timing
A proctored exam of multiple-choice items across the CISA domains covering IS audit process, governance, risk, control and information asset protection.
Penalty Rule
Set by the issuer — most vendor exams apply none
Recertification Cycle
CISA renews annually through a continuing-education programme with a required CPE reporting and annual maintenance fee.
Published Domains
4 Domain Areas
Prerequisites & Eligibility
ISACA requires experience in the audit, control or security areas with waivers for education or certifications; the current waiver conditions are published by ISACA.
ISACA publishes the exam content, timing and delivery rules for this professional-level credential. Restated here without the volatile specifics that change between versions.
A proctored exam of multiple-choice items across the CISA domains covering IS audit process, governance, risk, control and information asset protection.
Level: Professional certification
Issued by: ISACA
The 4 areas ISACA examines for CISA, as published by the issuer.
Information Systems Auditing Process
Governance and Risk Management
Information Asset Protection
IS Acquisition, Development and Maintenance
Stated explicitly so nothing on this page reads as a promise the product cannot keep.
No verified CISA question bank exists yet, so no practice sessions or mock exams are published across its 4 published domains. The syllabus and exam information above are published now; the bank appears here once it is verified. "Verified" here means a question has passed our review pipeline and can be served in the app right now; anything shown as verified is counted from that servable set.
ISACA sets the exam content, timing and policy for CISA. Those details are restated from the issuer's published material and can change between versions — treat the issuer's own page as the authority for your attempt.
Case-study and scenario essay practice, lab environments and hands-on performance exams are outside written-MCQ practice and are not claimed here.
Certifications
| Section | Questions | Marks per question | Section marks | Negative marking |
|---|---|---|---|---|
| Information Systems Auditing Process | Not published | Not published | Not published | Not published |
| Governance and Risk Management | Not published | Not published | Not published | Not published |
| Information Asset Protection | Not published | Not published | Not published | Not published |
| IS Acquisition, Development and Maintenance | Not published | Not published | Not published | Not published |
Official source: www.isaca.org
Score calculator
The official marks scheme for CISA is not published in our data yet, so there is no calculator we can stand behind. Check the notification below.
Practice is live today for 124 verified questions across 4 subjects. The same bank drives the adaptive review queue, so what you miss comes back at the spacing that fixes it.
Information Systems Auditing Process
35 verified questions
Information Asset Protection
34 verified questions
IS Acquisition, Development and Maintenance
29 verified questions
Questions
Not yet. The CISA question bank does not exist today, so we are not advertising practice sessions that would open onto an empty screen. The cybersecurity syllabus, exam pattern and eligibility are published here now, and the bank will be listed as soon as its questions pass verification.
Certified Information Systems Auditor (CISA) is examined across these areas: Information Systems Auditing Process, Governance and Risk Management, Information Asset Protection and IS Acquisition, Development and Maintenance. A proctored exam of multiple-choice items across the CISA domains covering IS audit process, governance, risk, control and information asset protection.
ISACA requires experience in the audit, control or security areas with waivers for education or certifications; the current waiver conditions are published by ISACA. ISACA is the authority for the criteria that apply to your attempt.
CISA renews annually through a continuing-education programme with a required CPE reporting and annual maintenance fee.
Every factual claim on this page traces to the official documents listed below. Each is published by the certifying or examining body, not by Koshish; follow a link to read the current version, because these details can change between cycles.
Content last updated 10 October 2026
Related certifications