CISA Training Course

Training course

This is a free, self-paced reading course for CISA: Certified Information Systems Auditor, ISACA’s credential for the people who provide assurance. It is written for the shape of the actual exam, which is not a vocabulary test. Nearly every hard CISA question turns on judgment: not what a firewall is, but what the auditor should do FIRST, which finding is the GREATEST concern, what constitutes the BEST evidence. Reading a domain teaches you the controls; reading it the way this course frames it is meant to teach you the auditor’s ordering instinct that those questions are really measuring.

The course is organized as one module per official exam domain, in the order ISACA publishes them, and each module carries the domain’s published weight from the exam content outline in force since August 1, 2024. That weighting is the single most useful thing on this page. Operations and Business Resilience and Protection of Information Assets sit at 26% each, 52% of your scored questions between them, while systems acquisition and development carries 12%. Study hours that follow the blueprint rather than your comfort zone are worth more than extra hours spent anywhere else.

CISA Professional level 5 modules Domain-weighted Self-paced Free account

What the course covers

Information Systems Auditing Process

Module 1 · 18%

The professional core: audit charters, risk-based planning, standards and ethics, evidence and sampling (attribute, variable, discovery, and stop-or-go) CAATs and data analytics, control self-assessment, reporting, follow-up, and quality assurance over the audit function itself. This module teaches the reasoning the rest of the exam expects you to use in every other domain.

Governance and Management of IT

Module 2 · 18%

Whether leadership actually steers IT: governance frameworks and steering committees, policy hierarchies, risk appetite and response, maturity models and balanced scorecards, organizational structure and segregation of duties, HR controls, and the full third-party arc, vendor selection, SLAs, right-to-audit clauses, offshore and fourth-party risk, and data ownership roles.

Information Systems Acquisition, Development and Implementation

Module 3 · 12%

The lightest domain by weight, covering how systems come to exist: feasibility studies and business cases, project governance, SDLC methodologies from waterfall through agile and CI/CD pipelines, requirements traceability, testing tiers and UAT, data migration controls, cutover strategies, post-implementation reviews, and vendor protections such as source-code escrow.

Information Systems Operations and Business Resilience

Module 4 · 26%

One of the two scoring heavyweights. Day-to-day operations, incident, problem, and change management, patching, job scheduling, interfaces, database integrity, end-user computing, capacity, monitoring, virtualization and cloud operations, flowing directly into resilience: the business impact analysis, RPO and RTO, backup schemes and restore testing, alternate-site strategies, and the full ladder of BCP and DRP test types.

Protection of Information Assets

Module 5 · 26%

The security domain, equal in weight to module 4: identity and access management, MFA and biometrics, privileged account controls, physical and environmental protection, network security from firewalls and DMZs to segmentation and IDS/IPS, cryptography and PKI, data classification, DLP, media sanitization, security awareness, vulnerability management and penetration testing, and SIEM-driven monitoring.

How to use it

Read a module, then take the matching portion of the CISA practice exam instead of saving the questions until the end. On CISA that sequence matters more than usual, because the failure mode is not forgetting a control. It is knowing all four options and still picking the third-best one. Only questions surface that. This page is open to everyone; the course lessons themselves open once you are signed in to a free Certifym account.

For exam logistics, the 150 questions, the 240-minute window, the scaled 200 to 800 range with 450 to pass, PSI and remote-proctor delivery, the five-year experience requirement and its waivers, and the 120 CPE hours per three-year cycle, see the CISA certification guide.

CISA Training: Certified Information Systems Auditor

A comprehensive CISA (Certified Information Systems Auditor) training course covering the current ISACA Job Practice Areas. Organized into five modules mirroring the exam domains, this course prepares you to think like an auditor: to evaluate rather than design, to test rather than operate, to gather evidence and report findings. Includes 51 lessons across the audit process, IT governance, systems acquisition and development, operations and business resilience, and protection of information assets.

Module 1: Information Systems Auditing Process 21% of exam

The foundation domain: audit standards (ITAF), planning, evidence, sampling, testing techniques, reporting, and follow-up. What distinguishes an auditor from an operator or a consultant.

  • 1.1 What CISA Is 5 min Free preview
  • 1.2 IS Audit Standards and Guidelines (ITAF) 5 min πŸ”’
  • 1.3 IS Audit Planning and Risk Assessment 5 min πŸ”’
  • 1.4 Audit Program Development 4 min πŸ”’
  • 1.5 Audit Types and Approaches 4 min πŸ”’
  • 1.6 Audit Evidence and Documentation 4 min πŸ”’
  • 1.7 Sampling Methodologies 5 min πŸ”’
  • 1.8 Testing Techniques and Data Analytics 4 min πŸ”’
  • 1.9 Interviewing and Observation 4 min πŸ”’
  • 1.10 Audit Findings and Recommendations 4 min πŸ”’
  • 1.11 Audit Reporting and Follow-Up 4 min πŸ”’

Module 2: Governance and Management of IT 17% of exam

IT governance frameworks, strategy alignment, policies, organizational structure, enterprise risk management, resource management, performance monitoring, quality management, and the laws and regulations that shape IT.

  • 2.1 IT Governance Frameworks 5 min πŸ”’
  • 2.2 IT Strategy and Alignment 4 min πŸ”’
  • 2.3 IT-Related Policies and Standards 4 min πŸ”’
  • 2.4 Organizational Structure and Roles 4 min πŸ”’
  • 2.5 Enterprise Risk Management 4 min πŸ”’
  • 2.6 IT Resource Management 4 min πŸ”’
  • 2.7 Performance Monitoring and Reporting 4 min πŸ”’
  • 2.8 Quality Assurance and Management 4 min πŸ”’
  • 2.9 Laws, Regulations, and Industry Standards 5 min πŸ”’

Module 3: Information Systems Acquisition, Development, and Implementation 12% of exam

How projects are governed, business cases justified, systems developed, controls designed in, testing performed, and implementations executed. The lightest-weighted domain but still core to what auditors evaluate.

  • 3.1 Project Governance and Management 5 min πŸ”’
  • 3.2 Business Case and Feasibility Analysis 4 min πŸ”’
  • 3.3 System Development Methodologies 5 min πŸ”’
  • 3.4 Control Identification and Design 4 min πŸ”’
  • 3.5 Testing Methodologies 4 min πŸ”’
  • 3.6 Implementation and System Migration 4 min πŸ”’

Module 4: Information Systems Operations and Business Resilience 26% of exam

The heaviest domain. IT architecture, asset management, scheduling, interfaces, end-user computing, data governance, performance, incident and problem management, change and release, service levels, databases, and business continuity.

  • 4.1 IT Common Components and Architecture 5 min πŸ”’
  • 4.2 IT Asset Management 4 min πŸ”’
  • 4.3 Job Scheduling and Production Process Automation 4 min πŸ”’
  • 4.4 System Interfaces 4 min πŸ”’
  • 4.5 End-User Computing and Shadow IT 4 min πŸ”’
  • 4.6 Data Governance 4 min πŸ”’
  • 4.7 Systems Performance Management 4 min πŸ”’
  • 4.8 Problem and Incident Management 4 min πŸ”’
  • 4.9 Change, Configuration, Release, and Patch Management 5 min πŸ”’
  • 4.10 IT Service Level Management 4 min πŸ”’
  • 4.11 Database Management 4 min πŸ”’
  • 4.12 Business Impact Analysis 4 min πŸ”’
  • 4.13 Business Continuity Plan and Disaster Recovery Plan 5 min πŸ”’

Module 5: Protection of Information Assets 24% of exam

Security frameworks, privacy, physical and environmental controls, identity and access management, network and endpoint security, encryption, PKI, cloud, mobile and IoT, awareness, attack methods and testing, and incident response and forensics.

  • 5.1 Information Asset Security Frameworks and Standards 4 min πŸ”’
  • 5.2 Privacy Principles and Regulations 4 min πŸ”’
  • 5.3 Physical Access and Environmental Controls 4 min πŸ”’
  • 5.4 Identity and Access Management 5 min πŸ”’
  • 5.5 Network and Endpoint Security 5 min πŸ”’
  • 5.6 Data Classification and Encryption 5 min πŸ”’
  • 5.7 Public Key Infrastructure 4 min πŸ”’
  • 5.8 Cloud and Virtualization Security 5 min πŸ”’
  • 5.9 Mobile, Wireless, and IoT Security 4 min πŸ”’
  • 5.10 Security Awareness and Training 3 min πŸ”’
  • 5.11 Attack Methods, Testing, and Monitoring 5 min πŸ”’
  • 5.12 Incident Response, Forensics, and Evidence 5 min πŸ”’

Frequently asked questions about the CISA training course

Is the CISA training course free?

Yes. The course costs nothing to read. Opening the lessons requires a free Certifym account, and nothing beyond that, no payment, no trial. It is funded by the practice-exam catalogue it sits alongside.

How is the course structured?

One module per official CISA domain, in ISACA’s published order, with each module weighted to the domain’s published percentage. Within each module the material is broken into short lessons, followed by key terms and further reading.

Does this replace ISACA’s official review material?

No. ISACA publishes the exam content outline and sells the CISA Review Manual and its own question database; those are the authoritative sources. This course is an independent study companion, written to be read quickly and to slot alongside practice questions.

Do I need the five years of audit experience before studying?

No, the experience requirement applies to certification rather than to study, and ISACA offers waivers against part of it. What the exam does assume is that you have sat on one side of an audit or the other. If you have not, expect module 1 to take longer than its 18% weight suggests, because everything after it is written in that vocabulary.

What should I do after finishing the course?

Move to the CISA practice exam and read the explanation on every item you got right for the wrong reason, not just the ones you missed. The practice pass line is set at 65% as the working proxy for the scaled 450, but treat that as a floor; aim for the mid-70s before you schedule with PSI.

Is the course current?

The course is built against the exam content outline effective August 1, 2024, five domains weighted 18%, 18%, 12%, 26%, and 26%, as published on the CISA certification guide. If other material you are using still shows the older 21/17/12/23/27 split, it predates the current exam. ISACA can revise the outline at any time; download the current version from isaca.org before you schedule.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISACA. CISA® and ISACA® are registered trademarks of ISACA (Information Systems Audit and Control Association). Use of these marks is solely to identify the certification for which these study materials are intended. The CISA Exam Content Outline and its domain structure are the property of ISACA; candidates should download the official, current exam content outline directly from isaca.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISACA training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, and eligibility criteria are set by ISACA and may change; always verify current details at isaca.org before scheduling your exam.