CISA cheat sheet
A one-page reference for the ISACA CISA — Certified Information Systems Auditor exam: the format, how the domains are weighted, and the glossary terms for this exam.
Exam at a glance
Vendor
ISACA
Level
Advanced
Questions
100
Time
180 min
Mock pass mark
70%
Domains
5
Practice Qs
148
Code
CISA
Domain weightings
How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.
Key terms
- IS Audit
- IS Audit is the formal, independent examination of information systems, controls, and processes to assess whether they safeguard assets, maintain integrity, and meet objectives. CISA is built entirely around performing IS audits competently.
- Audit Evidence
- Audit Evidence is the information an auditor gathers — through inspection, observation, inquiry, and reperformance — to support audit conclusions. CISA stresses that conclusions must be based on sufficient, reliable, and relevant evidence.
- Sampling
- Sampling is testing a subset of a population to draw conclusions about the whole, using statistical or judgmental methods. CISA covers choosing an appropriate sampling method and interpreting the risk of sampling error.
- Control Self-Assessment
- Control Self-Assessment (CSA) is a process in which business process owners themselves evaluate the effectiveness of their controls. CISA covers CSA as a way to broaden control coverage beyond the audit function.
- Internal Control
- An Internal Control is a policy, procedure, or mechanism that reduces risk and provides reasonable assurance that objectives are met. CISA classifies controls as preventive, detective, or corrective and tests their design and operating effectiveness.
- IT Governance
- IT Governance is the framework of leadership, structures, and processes that ensures IT sustains and extends the organization's strategy and objectives. CISA Domain 2 evaluates governance frameworks, policies, and strategic alignment.
- Segregation of Duties
- Segregation of Duties (SoD) divides critical tasks among different people so no single individual can both perpetrate and conceal an error or fraud. CISA treats SoD as a fundamental preventive control and a common audit finding.
- SDLC
- The System Development Life Cycle (SDLC) is the structured process for acquiring, developing, and implementing information systems. CISA Domain 3 audits SDLC controls, project governance, and post-implementation reviews.
- Change Management
- Change Management is the controlled process for requesting, approving, testing, and deploying changes to systems. CISA audits it to confirm that changes are authorized, tested, and traceable, preventing unauthorized production changes.
- Post-Implementation Review
- A Post-Implementation Review evaluates a completed system against its objectives, budget, and expected benefits after go-live. CISA covers it as the final control checkpoint in the acquisition and implementation domain.
- BIA
- A Business Impact Analysis (BIA) identifies critical processes and the impact of their disruption to prioritize recovery. CISA uses the BIA to derive recovery objectives such as RTO and RPO for resilience planning.
- RTO and RPO
- RTO and RPO are recovery objectives: Recovery Time Objective is the target time to restore a process, and Recovery Point Objective is the maximum tolerable data loss measured in time. CISA derives both from the business impact analysis.
- Disaster Recovery
- Disaster Recovery is the set of plans and capabilities for restoring IT systems and data after a disruptive event. CISA Domain 4 audits DR plans, backups, and testing against defined recovery objectives.
- Identity and Access Management
- Identity and Access Management (IAM) governs how identities are provisioned and what resources they may access, enforcing least privilege. CISA Domain 5 audits IAM controls as a core safeguard for information assets.
- Encryption
- Encryption transforms readable data into ciphertext reversible only with a key, protecting confidentiality in storage and transit. CISA audits encryption and key management as controls for protecting information assets.