All programmes
IT Auditing Professional

Certified Information Systems Auditor (CISA)

Study level Professional
Field IT Auditing

What this programme is about

CISA sits at the intersection of technology, controls and assurance. It is designed for professionals who evaluate whether information systems are governed, protected and operated as intended.

The qualification is widely associated with IT audit, but the scope is broader than checking technical settings. You also need to understand governance, risk, systems acquisition and operational controls.

For someone working in audit, compliance, risk or IT assurance, the certification can provide a structured way to demonstrate knowledge across those areas.

Preparation usually involves learning how to assess evidence, identify control weaknesses and judge whether a process actually reduces risk. The key skill is not memorising controls, but understanding why they exist.

Because CISA is a professional certification, exam preparation and certification eligibility are not the same thing. Training providers may prepare you for the exam, while ISACA sets the official requirements.

Check the latest domains, experience rules and renewal requirements directly with ISACA before committing to a course.

What you'll cover

IT Audit Process IT Governance Risk Management Systems Acquisition Systems Development Controls IT Operations Information Asset Protection Audit Evidence Control Evaluation Audit Reporting

Capabilities you'll strengthen

IT Auditing Control Assessment Risk Analysis Evidence Evaluation Audit Planning Compliance Review Governance Analysis Audit Reporting Process Evaluation Stakeholder Communication

Where this qualification can support you

IT Auditor
Information Systems Auditor
Technology Risk Analyst
IT Compliance Analyst
Internal Auditor
GRC Analyst
Audit Consultant
Information Security Auditor
Risk Consultant
IT Assurance Specialist

What preparing for this qualification is like

Audit-process topics cover planning, evidence, testing and reporting. You learn how to structure an audit so that conclusions are traceable to reliable evidence.

Governance modules examine whether technology decisions support organisational objectives and whether responsibilities are clearly assigned.

Systems acquisition and development introduces controls around new technology projects, including change management and implementation risk.

Operations topics focus on how systems are run, monitored, backed up and supported after deployment.

Information-asset protection brings security into the picture through access controls, data protection and resilience.

Across all these areas, CISA expects professional judgement and independence. You are evaluating whether controls are appropriate and effective, not simply whether they exist.

Is this likely to suit you?

Good fit if you...

  • You work in audit, risk, compliance or IT controls.
  • You enjoy evaluating evidence and processes.
  • You are comfortable working with governance and policy.
  • You want a professional credential recognised in IT assurance.
  • You can communicate findings clearly and objectively.

Think twice if you...

  • You are looking for a hands-on penetration-testing certification.
  • You dislike audit documentation or evidence review.
  • You have little interest in governance and controls.
  • You have not checked the current experience requirements.

Eligibility and requirements

Training-provider requirements vary. The official CISA certification has examination and professional-experience requirements set by ISACA. Experience in IT audit, controls, security, governance or risk is especially relevant. Always verify current eligibility, experience, exam and maintenance requirements directly with ISACA.

Common questions

Is CISA only for auditors?
It is especially relevant to auditors, but professionals in technology risk, compliance and controls also pursue it.
Who awards CISA?
CISA is awarded by ISACA.
Does CISA include cybersecurity?
Yes, but within a broader audit, governance and control framework.
Is work experience required?
The certification has professional-experience requirements. Check ISACA for the latest rules.
What jobs use CISA?
Common roles include IT audit, technology risk, assurance, compliance and GRC.
Still comparing?

Compare related programmes before you decide.

Compare qualifications, subject areas and the institutions offering each programme.

Explore similar programmes

Programme structures, duration and admission requirements can vary by institution and country. Always confirm current details with the institution before applying.