CISA Exam Blueprint: Five Domains and Readiness Checks
Map the five CISA domains to concrete audit tasks and use a readiness checklist alongside official exam and certification requirements.
ISACA’s current CISA outline has five domains. Use the official outline as the scope authority and the table below as a preparation map, not as a substitute for its detailed tasks. ISACA CISA exam content outline .
| Domain | Weight | Questions in our 150-item practice set |
|---|---|---|
| Information Systems Auditing Process | 18% | 27 |
| Governance and Management of IT | 18% | 27 |
| Information Systems Acquisition, Development and Implementation | 12% | 18 |
| Information Systems Operations and Business Resilience | 26% | 39 |
| Protection of Information Assets | 26% | 39 |
The practice allocation applies the published percentages to our independent set. It does not disclose an official exam form or imply that a real question cannot connect several domains.
Test your readiness with observable tasks
Audit process
Given a mandate, a population and a control assertion, identify an appropriate procedure and the limit of the conclusion. Explain why a current screenshot, a selected sample and evidence covering a whole period support different claims. Draft a finding that separates criteria, observed condition and business impact.
Self-check: could a different population filter reverse your conclusion? Identify how you would validate the extraction before relying on it.
Governance and management
Read a risk report or policy exception and identify decision authority, business priorities and unresolved exposure. Evaluate whether performance measures say something meaningful about the intended outcome rather than merely counting activity.
Self-check: distinguish a manager’s acknowledgment from risk acceptance under the organization’s delegated authority. State what the auditor should verify and communicate.
Acquisition and implementation
Follow a business requirement into design, testing, conversion and release. Determine whether the evidence demonstrates the required behavior, whether data relationships survived migration and whether operational responsibility is ready for handover.
Self-check: a deployment completed and record counts match. Name an important business or data assertion that those facts still do not establish.
Operations and resilience
Connect service measurements to the agreed measurement window and exclusions. Assess whether a recovery exercise restores the business service, including its dependencies and usable data, rather than just starting infrastructure.
Self-check: on a disruption timeline, compute the recovery duration and data-loss window separately. Explain which event starts each measurement.
Information asset protection
Evaluate whether identity, access, physical safeguards, data protection and monitoring address the stated exposure. Connect records to users and time periods, examine responsibility boundaries, and distinguish an implemented mechanism from evidence that it operates reliably.
Self-check: encryption is enabled, but an application account can read decrypted records. Explain which threats are reduced and which remain relevant.
Format, scoring and certification are different questions
The official CISA exam has 150 multiple-choice questions and a four-hour allowance. Use ISACA’s candidate-guide entry point for current administration details. Our static set uses one best answer per question and manual raw scoring; its result is not an official scaled score or pass prediction.
A passing exam result does not by itself award CISA certification. Check ISACA’s certification application requirements for qualifying experience, permitted substitutions, application timing and continuing professional obligations. Verify your own eligibility directly with ISACA rather than inferring it from practice performance.
Choose the next preparation action
If the task is unfamiliar, start with the cheat sheet . If you recognize the terms but choose the wrong procedure, use the scenario guide . If your knowledge is uneven across domains, use the study plan before taking the free practice exam .