CISA
Certified Information Systems Auditor
IS audit, governance, control testing, and assurance.
› Quality score
Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.
› Market signals
public, citable inputs to the recognition score› Built for these roles
› Exam format
150 multiple-choice questions over 4 hours, English plus several other languages. Pearson VUE proctored. ISACA membership not required but discounts the AMF.
ISACA charges members $575 / non-members $760. 4 attempts per 12-month rolling window.
› Recertification
120 CPEs over the three-year cycle (avg 40/yr, minimum 20/yr) plus the $45/yr maintenance fee for ISACA members ($85/yr non-members).
› 3-year cost of ownership
Excludes study materials, training, retake risk, and lost-wage opportunity. Use as a floor estimate.
› NICE Framework work roles
The NIST NICE work-role IDs this cert maps to. NICCS lookup.
› Core domains covered
The 1 domain this cert is centrally about. Passing the exam demonstrates working knowledge of each.
› Also touched
Present in the blueprint but not the primary focus — you’ll be introduced but shouldn’t expect depth.
SBOM, vendor risk assessment, software supply chain attacks, dependency management.
Data classification, encryption-at-rest/in-transit, DLP, tokenization, privacy-by-design, plus the regulatory stack (GDPR, CCPA, HIPAA) that sets the bar.
Cyber risk quantification, board communication, security program development, budget & ROI.
› Prerequisites
Five years of IS audit, control, or security experience. Waivers available for other certs and education.
- Audit process and methodology
- Governance and risk management
- IT operations and resilience
› Progression
requiredrecommendedWhere this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.
No vendor-gated prereqs.
No de facto priors typically expected.
No certs require this one.
› Study materials
Curated starting points. Not exhaustive — vet each against your learning style and the current exam version.
- CISA Review Manual, 28th Ed. — ISACA
- CISA Review Questions, Answers & Explanations Database (QAE) — ISACA
- ISACA QAE Database (1000+ questions)
- Hemang Doshi practice tests (Udemy)
› Version & lifecycle
ISACA performs a job-practice analysis every ~5 years. Five domains.
› Salary signal
IT Auditor / SOX auditor / IS audit manager, US, 5+ years.
ISACA Salary Survey + Salary.com 'IT Auditor' aggregations · 2024 · US base only · p25–p75 range
› How it compares
Risk-management emphasis (CRISC) vs CISA's audit-execution and assessment focus.
↔ Compare side-by-sideSingle-standard ISMS lead-auditor focus vs CISA's broader IS-audit framework coverage.
↔ Compare side-by-side› Careers that commonly pursue this cert
Manage risk, ensure regulatory compliance, and build governance frameworks. Where security meets business strategy.
See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.