CISA Exam Guide: Domains, Scoring, Experience and Prep
A clear CISA exam guide: the five ISACA domains, scaled scoring from 200 to 800 with 450 to pass, the experience requirement and how to prepare well.
The Certified Information Systems Auditor (CISA) from ISACA is the best-known credential for IT audit, assurance and control professionals. It is valued by audit firms, internal audit teams, regulators and risk functions. The exam is challenging because it asks you to think like an auditor: independent, evidence-focused and risk-based. This guide walks through the five domains, how scoring works, the experience requirement and a practical way to prepare.
Exam format at a glance
CISA is a computer-based, multiple-choice exam delivered at test centres or through remote proctoring. In recent years it has consisted of 150 questions in four hours. ISACA reviews the job practice periodically and the current outline took effect in 2024, so always check the latest CISA Exam Candidate Information Guide and the published job practice areas before you start studying. Older materials may use previous domain titles or weightings.
The five CISA domains
The CISA job practice is organised into five domains, each with a published weighting:
Domain 1: Information System Auditing Process
Planning and conducting audits in line with ISACA standards: risk-based audit planning, types of audits and controls, evidence collection, sampling, data analytics, reporting and follow-up. This domain sets the mindset for the whole exam.
Domain 2: Governance and Management of IT
IT strategy, governance frameworks, organisational structure, policies, enterprise risk management, IT resource and vendor management, performance monitoring and quality assurance.
Domain 3: Information Systems Acquisition, Development and Implementation
Business cases and project governance, system development methodologies, control design, testing, configuration and release management, and post-implementation review.
Domain 4: Information Systems Operations and Business Resilience
IT operations, asset and problem management, change management, service levels, database management, business impact analysis, backup and recovery, and business continuity and disaster recovery planning.
Domain 5: Protection of Information Assets
Information security frameworks, privacy principles, physical and logical access controls, network and endpoint security, data classification, encryption, security monitoring and incident response.
How CISA scoring works
CISA uses scaled scoring. Your raw result is converted to a score between 200 and 800, and you need 450 or higher to pass. A scaled score of 800 means every question was answered correctly, 200 is the lowest possible score, and 450 represents ISACA's minimum standard of knowledge.
Two points are worth understanding:
- A scaled score is not a percentage. You cannot reliably translate 450 into a fixed number of correct answers, because scaling accounts for differences between exam forms.
- Your score report typically shows performance by domain, which is very useful if you need to resit.
The experience requirement
Passing the exam is only one step. To become certified you must also apply for certification and demonstrate relevant work experience. ISACA's standard requirement is five years of professional experience in information systems audit, control, assurance or security, gained within the ten years before your application or within five years after passing the exam.
ISACA allows certain substitutions and waivers for some of that experience, for example for relevant degrees or other qualifications, up to a published maximum. You also agree to follow ISACA's Code of Professional Ethics and its continuing professional education (CPE) policy once certified. Because these rules can change, read the current requirements on ISACA's website before relying on any waiver.
You can sit the exam before you have the full experience, which many candidates do early in their careers.
How to prepare
- Start with the official job practice. Print the task and knowledge statements and use them as your checklist.
- Use the ISACA Review Manual and question database, or other reputable materials aligned with the current outline.
- Learn to think like an auditor. The best answer is usually the one that is risk-based, preserves independence and relies on evidence. Auditors recommend and report; they do not implement controls themselves.
- Prioritise heavily weighted domains, but do not neglect any domain, because weak areas show up on your score report.
- Practise in timed blocks, then full-length sittings, to build pace for 150 questions.
- Keep an error log. Note the reasoning behind each correct answer, not just the fact.
A typical study period for working professionals is several weeks to a few months, depending on background. Auditors often find Domain 1 familiar, while IT professionals may need more time on audit concepts. If you are weighing CISA against ISACA's security management credential, see our comparison of CISM vs CISA.
Common pitfalls
- Answering as a technician. Choose the audit perspective, not the hands-on fix.
- Overlooking key words such as "first", "best" and "most important".
- Studying outdated materials that do not match the current job practice.
How a personal 1-to-1 assistant can help
The biggest CISA challenge is often adopting the auditor's mindset consistently. A personal study assistant can explain why one answer is "more right" than another, build a schedule around the domain weightings, and analyse your practice results so you spend time where it counts. FoxyCert provides a dedicated 1-to-1 assistant for each exam, available on Telegram, with all services included until you pass. You sit the exam yourself; we help you prepare with focus. To get started, see FoxyCert's 1-to-1 exam prep.
Frequently asked questions
What score do I need to pass CISA?
CISA uses scaled scoring from 200 to 800. You need a scaled score of 450 or higher to pass. A scaled score is not a percentage of correct answers.
Can I take the CISA exam without five years of experience?
Yes. You can sit and pass the exam first, then apply for certification once you meet the experience requirement, which can be gained within five years after passing. Some waivers may apply.
What are the five CISA domains?
Information System Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development and Implementation; Information Systems Operations and Business Resilience; and Protection of Information Assets.