← Home
ISACA · Full exam outline

CISA

Certified Information Systems Auditor

IT audit / assurance leadership
1Information Systems Auditing Process18%
1.1Audit standards, guidelines and ethics
1.2Risk-based audit planning
1.3Audit execution, evidence and sampling
1.4Communication of results and follow-up
2Governance and Management of IT18%
2.1IT governance, strategy and organizational structure
2.2Policies, standards and procedures
2.3Enterprise architecture and resource management
2.4IT risk management and quality assurance
3Information Systems Acquisition, Development and Implementation12%
3.1Project governance and management
3.2Business case and feasibility analysis
3.3System development methodologies
3.4Control identification, testing and readiness
3.5Post-implementation review
4Information Systems Operations and Business Resilience26%
4.1IT service management and operations
4.2End-user computing and data governance
4.3Problem and incident management
4.4Change, configuration and release management
4.5Business impact analysis and disaster recovery plans
5Protection of Information Assets26%
5.1Information asset security frameworks and standards
5.2Physical and environmental controls
5.3Identity and access management
5.4Network and endpoint security
5.5Data classification, encryption and public key infrastructure
5.6Security awareness, incident response and evidence collection
Weights are the certification body’s published values and are checked against each outline revision.