← CISA overviewCertified Information Systems Auditor / STUDY TOOLS
Exam coverage map
This path follows the outline effective August 2024 and published as current by ISACA at review time. Passing the exam does not alone satisfy certification experience, ethics and application requirements.
Published objectives
| Objective |
Revision topic |
| 1A · Audit planning |
01 Risk-Based Audit Planning and Independence |
| 1B · Audit execution |
01 Risk-Based Audit Planning and Independence, 02 Evidence, Sampling, Findings and Follow-Up |
| 2A · IT governance |
03 Security Leadership, Ethics and Business Risk, 07 Governance, Data Ownership and Enterprise Architecture |
| 2B · IT management |
04 Security Programs, Suppliers and Useful Metrics, 07 Governance, Data Ownership and Enterprise Architecture |
| 3A · Acquisition and development |
05 Secure Software Lifecycle and Supply Chains, 08 Development, Conversion and Implementation Assurance |
| 3B · Implementation |
08 Development, Conversion and Implementation Assurance |
| 4A · Operations |
06 Incident Leadership, Continuity and Recovery Decisions, 09 Operational Controls, Databases and Resilience |
| 4B · Business resilience |
06 Incident Leadership, Continuity and Recovery Decisions, 09 Operational Controls, Databases and Resilience |
| 5A · Asset security |
03 Security Leadership, Ethics and Business Risk, 10 Cryptography, Certificates and Keys, 11 Secure Architecture and Network Defences |
| 5B · Security events |
02 Evidence, Sampling, Findings and Follow-Up, 06 Incident Leadership, Continuity and Recovery Decisions, 11 Secure Architecture and Network Defences |