Training course
This is a free, self-paced reading course for CISA: Certified Information Systems Auditor, ISACA’s credential for the people who provide assurance. It is written for the shape of the actual exam, which is not a vocabulary test. Nearly every hard CISA question turns on judgment: not what a firewall is, but what the auditor should do FIRST, which finding is the GREATEST concern, what constitutes the BEST evidence. Reading a domain teaches you the controls; reading it the way this course frames it is meant to teach you the auditor’s ordering instinct that those questions are really measuring.
The course is organized as one module per official exam domain, in the order ISACA publishes them, and each module carries the domain’s published weight from the exam content outline in force since August 1, 2024. That weighting is the single most useful thing on this page. Operations and Business Resilience and Protection of Information Assets sit at 26% each, 52% of your scored questions between them, while systems acquisition and development carries 12%. Study hours that follow the blueprint rather than your comfort zone are worth more than extra hours spent anywhere else.
What the course covers
Information Systems Auditing Process
Module 1 · 18%The professional core: audit charters, risk-based planning, standards and ethics, evidence and sampling (attribute, variable, discovery, and stop-or-go) CAATs and data analytics, control self-assessment, reporting, follow-up, and quality assurance over the audit function itself. This module teaches the reasoning the rest of the exam expects you to use in every other domain.
Governance and Management of IT
Module 2 · 18%Whether leadership actually steers IT: governance frameworks and steering committees, policy hierarchies, risk appetite and response, maturity models and balanced scorecards, organizational structure and segregation of duties, HR controls, and the full third-party arc, vendor selection, SLAs, right-to-audit clauses, offshore and fourth-party risk, and data ownership roles.
Information Systems Acquisition, Development and Implementation
Module 3 · 12%The lightest domain by weight, covering how systems come to exist: feasibility studies and business cases, project governance, SDLC methodologies from waterfall through agile and CI/CD pipelines, requirements traceability, testing tiers and UAT, data migration controls, cutover strategies, post-implementation reviews, and vendor protections such as source-code escrow.
Information Systems Operations and Business Resilience
Module 4 · 26%One of the two scoring heavyweights. Day-to-day operations, incident, problem, and change management, patching, job scheduling, interfaces, database integrity, end-user computing, capacity, monitoring, virtualization and cloud operations, flowing directly into resilience: the business impact analysis, RPO and RTO, backup schemes and restore testing, alternate-site strategies, and the full ladder of BCP and DRP test types.
Protection of Information Assets
Module 5 · 26%The security domain, equal in weight to module 4: identity and access management, MFA and biometrics, privileged account controls, physical and environmental protection, network security from firewalls and DMZs to segmentation and IDS/IPS, cryptography and PKI, data classification, DLP, media sanitization, security awareness, vulnerability management and penetration testing, and SIEM-driven monitoring.
How to use it
Read a module, then take the matching portion of the CISA practice exam instead of saving the questions until the end. On CISA that sequence matters more than usual, because the failure mode is not forgetting a control. It is knowing all four options and still picking the third-best one. Only questions surface that. This page is open to everyone; the course lessons themselves open once you are signed in to a free Certifym account.
For exam logistics, the 150 questions, the 240-minute window, the scaled 200 to 800 range with 450 to pass, PSI and remote-proctor delivery, the five-year experience requirement and its waivers, and the 120 CPE hours per three-year cycle, see the CISA certification guide.
CISA Training: Certified Information Systems Auditor
A comprehensive CISA (Certified Information Systems Auditor) training course covering the current ISACA Job Practice Areas. Organized into five modules mirroring the exam domains, this course prepares you to think like an auditor: to evaluate rather than design, to test rather than operate, to gather evidence and report findings. Includes 51 lessons across the audit process, IT governance, systems acquisition and development, operations and business resilience, and protection of information assets.
Module 1: Information Systems Auditing Process 21% of exam
The foundation domain: audit standards (ITAF), planning, evidence, sampling, testing techniques, reporting, and follow-up. What distinguishes an auditor from an operator or a consultant.
- 1.1 What CISA Is 5 min Free preview
- 1.2 IS Audit Standards and Guidelines (ITAF) 5 min π
- 1.3 IS Audit Planning and Risk Assessment 5 min π
- 1.4 Audit Program Development 4 min π
- 1.5 Audit Types and Approaches 4 min π
- 1.6 Audit Evidence and Documentation 4 min π
- 1.7 Sampling Methodologies 5 min π
- 1.8 Testing Techniques and Data Analytics 4 min π
- 1.9 Interviewing and Observation 4 min π
- 1.10 Audit Findings and Recommendations 4 min π
- 1.11 Audit Reporting and Follow-Up 4 min π
Module 2: Governance and Management of IT 17% of exam
IT governance frameworks, strategy alignment, policies, organizational structure, enterprise risk management, resource management, performance monitoring, quality management, and the laws and regulations that shape IT.
- 2.1 IT Governance Frameworks 5 min π
- 2.2 IT Strategy and Alignment 4 min π
- 2.3 IT-Related Policies and Standards 4 min π
- 2.4 Organizational Structure and Roles 4 min π
- 2.5 Enterprise Risk Management 4 min π
- 2.6 IT Resource Management 4 min π
- 2.7 Performance Monitoring and Reporting 4 min π
- 2.8 Quality Assurance and Management 4 min π
- 2.9 Laws, Regulations, and Industry Standards 5 min π
Module 3: Information Systems Acquisition, Development, and Implementation 12% of exam
How projects are governed, business cases justified, systems developed, controls designed in, testing performed, and implementations executed. The lightest-weighted domain but still core to what auditors evaluate.
- 3.1 Project Governance and Management 5 min π
- 3.2 Business Case and Feasibility Analysis 4 min π
- 3.3 System Development Methodologies 5 min π
- 3.4 Control Identification and Design 4 min π
- 3.5 Testing Methodologies 4 min π
- 3.6 Implementation and System Migration 4 min π
Module 4: Information Systems Operations and Business Resilience 26% of exam
The heaviest domain. IT architecture, asset management, scheduling, interfaces, end-user computing, data governance, performance, incident and problem management, change and release, service levels, databases, and business continuity.
- 4.1 IT Common Components and Architecture 5 min π
- 4.2 IT Asset Management 4 min π
- 4.3 Job Scheduling and Production Process Automation 4 min π
- 4.4 System Interfaces 4 min π
- 4.5 End-User Computing and Shadow IT 4 min π
- 4.6 Data Governance 4 min π
- 4.7 Systems Performance Management 4 min π
- 4.8 Problem and Incident Management 4 min π
- 4.9 Change, Configuration, Release, and Patch Management 5 min π
- 4.10 IT Service Level Management 4 min π
- 4.11 Database Management 4 min π
- 4.12 Business Impact Analysis 4 min π
- 4.13 Business Continuity Plan and Disaster Recovery Plan 5 min π
Module 5: Protection of Information Assets 24% of exam
Security frameworks, privacy, physical and environmental controls, identity and access management, network and endpoint security, encryption, PKI, cloud, mobile and IoT, awareness, attack methods and testing, and incident response and forensics.
- 5.1 Information Asset Security Frameworks and Standards 4 min π
- 5.2 Privacy Principles and Regulations 4 min π
- 5.3 Physical Access and Environmental Controls 4 min π
- 5.4 Identity and Access Management 5 min π
- 5.5 Network and Endpoint Security 5 min π
- 5.6 Data Classification and Encryption 5 min π
- 5.7 Public Key Infrastructure 4 min π
- 5.8 Cloud and Virtualization Security 5 min π
- 5.9 Mobile, Wireless, and IoT Security 4 min π
- 5.10 Security Awareness and Training 3 min π
- 5.11 Attack Methods, Testing, and Monitoring 5 min π
- 5.12 Incident Response, Forensics, and Evidence 5 min π
Frequently asked questions about the CISA training course
Is the CISA training course free?
Yes. The course costs nothing to read. Opening the lessons requires a free Certifym account, and nothing beyond that, no payment, no trial. It is funded by the practice-exam catalogue it sits alongside.
How is the course structured?
One module per official CISA domain, in ISACA’s published order, with each module weighted to the domain’s published percentage. Within each module the material is broken into short lessons, followed by key terms and further reading.
Does this replace ISACA’s official review material?
No. ISACA publishes the exam content outline and sells the CISA Review Manual and its own question database; those are the authoritative sources. This course is an independent study companion, written to be read quickly and to slot alongside practice questions.
Do I need the five years of audit experience before studying?
No, the experience requirement applies to certification rather than to study, and ISACA offers waivers against part of it. What the exam does assume is that you have sat on one side of an audit or the other. If you have not, expect module 1 to take longer than its 18% weight suggests, because everything after it is written in that vocabulary.
What should I do after finishing the course?
Move to the CISA practice exam and read the explanation on every item you got right for the wrong reason, not just the ones you missed. The practice pass line is set at 65% as the working proxy for the scaled 450, but treat that as a floor; aim for the mid-70s before you schedule with PSI.
Is the course current?
The course is built against the exam content outline effective August 1, 2024, five domains weighted 18%, 18%, 12%, 26%, and 26%, as published on the CISA certification guide. If other material you are using still shows the older 21/17/12/23/27 split, it predates the current exam. ISACA can revise the outline at any time; download the current version from isaca.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISACA. CISA® and ISACA® are registered trademarks of ISACA (Information Systems Audit and Control Association). Use of these marks is solely to identify the certification for which these study materials are intended. The CISA Exam Content Outline and its domain structure are the property of ISACA; candidates should download the official, current exam content outline directly from isaca.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISACA training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, and eligibility criteria are set by ISACA and may change; always verify current details at isaca.org before scheduling your exam.
