CISA Study Guide — 2026 Edition cover

CISA — Certified Information Systems Auditor · 2026 Edition

CISA Study Guide — 2026 Edition

All five ISACA domains at their published weights, 250 original practice questions with worked explanations, and a 150-question full-length practice exam.

  • Every CISA domain across 8 chapters, as one PDF + EPUB you keep
  • All 60 sections of ISACA's CISA Exam Content Outline, each taught under its own heading
  • 250 original questions with worked explanations: a quiz closing each of the 8 chapters, plus a full-length practice exam composed to ISACA's domain weights

PDF + EPUB · English · 216 pages · $19.99 one-time

This book is written in English.

Instant download after payment — no account needed, no subscription.

14-day money-back guarantee: not satisfied for any reason? Email support@preppass.org within 14 days of purchase for a full refund. Refund policy

Read a free sample chapter first

Look inside the book

Three real pages, rendered straight from the PDF you download — a reference page, a teaching page, and a worked question, always in that order. Nothing here was redrawn to look better.

  • Quick reference
    Chapter 1 — The IS audit process — planning · PDF page 17

    A page you can turn back to: the numbers, deadlines or terms gathered in one place.

  • How it's taught
    Chapter 6 — Business resilience · PDF page 87

    An explanation page: the material taught in prose, in the order the exam tests it.

  • A question, worked
    Chapter 3 — Governance and management of IT · PDF page 48

    A practice question with its answer and the reasoning behind it — not just a key.

About the CISA exam

IS auditors and control, assurance and information security professionals preparing for ISACA's CISA exam. This book teaches all five domains of the August 2024 outline, with a quiz after every chapter and a full-length practice exam, every answer explained. It is an independent study guide, not an ISACA product, and has no online question bank.

Certified Information Systems Auditor — exam facts
Awarding bodyISACA
Questions150 multiple-choice questions
Time limit240 minutes (4 hours)
Passing ruleA score of 450 or higher on ISACA's 200 to 800 reporting scale
FeesExam registration US$575 (ISACA member) or US$760 (non-member), nonrefundable and nontransferable; US$50 application processing fee after passing; annual maintenance fee US$45 (member) or US$85 (non-member)
DeliveryComputer-based, at authorized PSI testing centers globally or as a remotely proctored exam
EligibilityAnyone may sit the exam. Certification requires a minimum of five years of professional information systems auditing, control or security work experience gained within the 10 years before applying; candidates have five years from the passing date to apply
RetakesFour attempts within a rolling 12-month period; wait 30 days after the first attempt and 90 days before each of the third and fourth; the registration fee is paid in full for each attempt
LanguagesEnglish, Spanish, Chinese Simplified, French, German, Korean, Japanese
Content outlineCISA Examination Content Outline, Effective August 2024 — effective August 2024
Domains and weights
  • Information System Auditing Process — 18%
  • Governance and Management of IT — 18%
  • Information Systems Acquisition, Development, and Implementation — 12%
  • Information Systems Operations and Business Resilience — 26%
  • Protection of Information Assets — 26%

Questions buyers ask

How many questions are on the CISA exam, and how long is it?
The CISA exam has 150 multiple-choice questions and you have 4 hours (240 minutes) to complete it. There is no penalty for a wrong answer, so ISACA advises answering every question.
What score do you need to pass the CISA exam?
You need a score of 450 or higher on ISACA's 200 to 800 scale. It is a scaled score, not a percentage, and the domain-level results in your report do not decide the pass.
What are the CISA domains and their weights?
There are five domains: Information System Auditing Process 18%, Governance and Management of IT 18%, Information Systems Acquisition, Development, and Implementation 12%, Information Systems Operations and Business Resilience 26%, and Protection of Information Assets 26%.
Which CISA content outline is current, and what changed?
The current outline is the CISA Examination Content Outline effective August 2024. The ISACA documents this book is built from do not publish a summary of what changed from the previous outline.
Who can take the CISA exam?
Anyone can take it; there is no experience requirement to sit the exam. To become certified you then need at least five years of IS audit, control or security experience gained within the 10 years before you apply, and you must apply within five years of passing.
How much does the CISA exam cost, and can I retake it?
Registration costs US$575 for ISACA members and US$760 for non-members, plus a US$50 application fee after you pass. You get four attempts in a rolling 12 months, waiting 30 days before the second and 90 days before the third and fourth, paying in full each time.
How is this book organized?
The book has eight chapters that follow the five ISACA domains, each ending with a quiz, then a 150-question practice exam weighted like the real exam. It contains 250 questions in all, every one with an explained answer, and costs $19.99.
Is passing the CISA exam the same as being CISA certified?
No. Passing is the first step. You must also pay the US$50 application fee, submit an application showing the required experience, and agree to follow ISACA's Code of Professional Ethics and its Continuing Professional Education Policy.
Is a study guide enough for the CISA — Certified Information Systems Auditor exam, or do I need a course?
Check eligibility first — per ISACA: anyone may sit the exam. Certification requires a minimum of five years of professional information systems auditing, control or security work experience gained within the 10 years before applying; candidates have five years from the passing date to apply. A book does not replace those requirements. For the exam content itself, this 216-page guide teaches the material chapter by chapter with 250 practice questions and explanations inside. A prep course adds live instruction and a set schedule; whether you need one beyond any required education is your call.
Does the CISA — Certified Information Systems Auditor study guide come as a PDF?
Yes — CISA Study Guide — 2026 Edition downloads as PDF and EPUB, 216 pages. The download link is emailed the moment payment clears and does not expire.
How much does the CISA — Certified Information Systems Auditor study guide cost?
$19.99, once. There is no subscription and no account to create; the PDF and EPUB files are yours to keep.
Can I read part of the CISA — Certified Information Systems Auditor study guide before buying?
Yes. A full chapter is free to read on this page — not a summary of one, the chapter itself.
Is this the official CISA — Certified Information Systems Auditor study guide?
No. This is an independent study guide and is not affiliated with or endorsed by the exam's awarding body. It is written from ISACA's published CISA Exam Content Outline (effective August 2024) and Certification Exam Candidate Guide. Always confirm current requirements with the body that issues your licence.

What's included — and what isn't

Included

  • All 5 CISA domains at ISACA's published weights
  • Every section of the August 2024 Exam Content Outline
  • A quiz closing each of the 8 chapters, with worked explanations
  • A 150-question full-length practice exam at the real domain weights
  • 250 original questions, each explained and cited to ISACA or NIST
  • Quick-reference appendices — PDF + EPUB

Not included

  • No printed copy is shipped — this is a file you download and can print yourself
  • No video course, instructor, tutoring or online question bank comes with the book — everything is in the file
  • Not your exam registration or the testing centre's fee, which you still pay to the official body

Contents

See 13 sections and the page each one starts on
  1. Chapter 1 — The IS audit process — planningp. 7
  2. Chapter 2 — The IS audit process — execution and reportingp. 19
  3. Chapter 3 — Governance and management of ITp. 33
  4. Chapter 4 — Acquisition, development and implementationp. 53
  5. Chapter 5 — Information systems operationsp. 69
  6. Chapter 6 — Business resiliencep. 85
  7. Chapter 7 — Information asset security and controlp. 101
  8. Chapter 8 — Security event managementp. 119
  9. Practice exam — answer key & explanations (Domain 1)p. 141
  10. Practice exam — answer key & explanations (Domain 4)p. 179
  11. Appendix A — The CISA exam at a glancep. 205
  12. Appendix B — ISACA terms an IS auditor is expected to use preciselyp. 208
  13. Appendix C — Audit evidence, sampling and testing at a glancep. 211

Taken from the PDF you download, with the page each one starts on — not typed here.

Read a chapter free, in full

One complete chapter, exactly as it ships in the eBook. Scroll the window to read it right here; no download, no email.

Read chapter 1 here, without leaving the page
FREE SAMPLE — READ IT RIGHT HERE
Chapter 1 · 18% of the exam · ≈9 min read
The IS audit process — planning
scroll ↓

Domain 1 is the auditor's own craft: how an IS audit is planned, executed, and reported. Under the CISA content outline effective August 2024, it carries 18% of the exam, and this chapter covers its planning half — the part of every engagement that succeeds or fails before fieldwork begins. The four sections below follow the order in which a real engagement unfolds: the standards and ethics that authorize and constrain the auditor, the kinds of engagements an IS auditor performs, the risk-based plan that aims effort where it matters most, and the control types that the plan is built to test. Chapter 2 continues with execution: managing the audit project, testing and sampling, collecting evidence, applying data analytics, reporting results, and quality assurance. The domain's logic is sequential, and the exam rewards candidates who think in that order — nothing in Chapter 2 works unless the planning in this chapter was done properly, and candidates who master planning answer execution questions better too, because every testing decision traces back to a planning decision made here.

1A1 IS Audit Standards, Guidelines, and Codes of Ethics

Every CISA begins here, because the credential itself rests on this material: adhering to ISACA's Code of Professional Ethics is one of the steps to certification, and the Code is the only part of the CISA body of knowledge for which ISACA publishes the controlling text free of charge. The Code opens by stating its purpose — to guide the professional and personal conduct of members and certification holders — and then sets out seven tenets, in ISACA's words:

  1. Support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective governance and management of enterprise information systems and technology, including audit, control, security and risk management.
  2. Perform their duties with objectivity, due diligence and professional care, in accordance with professional standards.
  3. Serve in the interest of stakeholders in a lawful manner, while maintaining high standards of conduct and character, and not discrediting their profession or the Association.
  4. Maintain the privacy and confidentiality of information obtained in the course of their activities unless disclosure is required by legal authority. Such information shall not be used for personal benefit or released to inappropriate parties.
  5. Maintain competency in their respective fields and agree to undertake only those activities they can reasonably expect to complete with the necessary skills, knowledge and competence.
  6. Inform appropriate parties of the results of work performed, including the disclosure of all significant facts known to them that, if not disclosed, may distort the reporting of the results.
  7. Support the professional education of stakeholders in enhancing their understanding of the governance and management of enterprise information systems and technology, including audit, control, security and risk management.

Three of these tenets do the heaviest work on the exam. Objectivity and professional care (tenet 2) are operationalized through two supporting concepts. Independence, in ISACA's glossary, is freedom from conflict of interest and undue influence — the auditor must be free to make decisions uninfluenced by the managers and employees being audited. Due professional care is the diligence that a person with special skill would exercise under the circumstances: the standard is not perfection, but the care a competent professional would take. Confidentiality (tenet 4) is near-absolute — client information is never used for personal benefit and never released to inappropriate parties, no matter how informally the request arrives; only disclosure required by legal authority overrides it. Competency (tenet 5) is a continuing obligation rather than a one-time credential, which is why retaining certification requires 20 hours of continuing professional education each year and 120 hours over each three-year reporting period. It is also a per-engagement test: the auditor who lacks the skills for an assignment must say so and obtain qualified help rather than improvise on a live client system.

Beyond the Code, ISACA publishes IS audit standards and guidelines that define how engagements are conducted. The CISA task statements expect the auditor to conduct audits in accordance with IS audit standards and a risk-based IS audit strategy — standards supply the "how an audit is done," and the risk-based strategy, covered in 1A3, supplies the "where the effort goes." An auditor who performs thorough procedures but cannot show the engagement followed professional standards has missed what the exam tests: the process must be defensible, not merely diligent. And the Code's tenets are enforceable rules, not aspirations — failure to comply can lead to investigation of the member's or certification holder's conduct and, ultimately, disciplinary measures.

1A2 Types of Audits, Assessments, and Reviews

Not every assurance engagement is an audit, and the exam expects precision about the differences. An audit provides the highest level of assurance: systematic and evidence-based, performed against stated criteria, and ending in an opinion or conclusion. An assessment is broader and typically lighter — an evaluation of controls or posture against a framework, producing findings and recommendations without a formal opinion. A review is narrower still, applying limited procedures to provide limited assurance. The engagement letter, the formal document defining the IS auditor's responsibility, authority and accountability for the assignment, should make clear which of these the client is getting, because the procedures performed, the evidence bar, and the reporting all differ.

Within audits, several types recur across the exam. Internal audits are performed by or on behalf of the enterprise itself, serving management and those charged with governance. External audits are performed by independent third parties, often driven by regulatory or contractual requirements. Compliance audits test conformity with laws, regulations, policies or contracts. Operational audits examine efficiency and effectiveness — whether resources are well used, not merely whether rules were followed. Financial audits focus on the reliability of financial reporting, where the IS auditor's interest lies in the IT controls those numbers depend on. Integrated audits combine these lenses, for instance testing financial-reporting controls and operational efficiency within a single engagement.

For the IS auditor specifically, two scopes matter most. General-controls audits examine the IT environment as a whole — access management, change control, operations — the foundation on which every application depends. Application-controls audits go deeper into a single system, testing the input, processing and output controls of, say, a payroll or claims application. A recurring exam trap is the relationship between the two: weak general controls undermine reliance on application controls, because an application cannot be more trustworthy than the environment running it. Planning therefore sequences general-controls work before deep application testing whenever the auditor intends to rely on those application controls.

1A3 Risk-Based Audit Planning

The first CISA task statement defines the mission: plan an audit to determine whether information systems are protected, controlled, and provide value to the organization. "Risk-based" is the method. No budget or calendar permits testing everything, so planning allocates effort in proportion to risk, and the audit plan documents the result. ISACA's glossary defines the audit plan as containing the nature, timing and extent of audit procedures to be performed in order to obtain sufficient appropriate evidence for an opinion, and its scope notes spell out what the plan carries: the areas to be audited, the type of work planned, the high-level objectives and scope of the work — plus budget, resource allocation, schedule dates, the type of report and its intended audience.

Planning proceeds in a fixed logical order, and the exam tests the order. First, the auditor builds or refreshes the audit universe: the inventory of auditable entities — systems, processes, locations, projects. Second, a risk assessment ranks that universe by asking where things could go wrong, how badly, and how likely it is. This is where risk vocabulary must be exact. A threat is any circumstance or event with the potential to adversely impact organizational operations and assets — through unauthorized access, destruction, disclosure or modification of information, or denial of service. A threat source is what causes threat events, characterized by the intent and method aimed at exploiting a vulnerability, or by a situation and method that may exploit one accidentally. Likelihood and impact are then judged for each threat, producing the risk ranking that drives the plan.

Third, the auditor sets materiality: an item's importance judged by its impact or effect on the functioning of the entity being audited, its significance in the context of the enterprise as a whole. Materiality keeps a risk-based plan honest — a high-likelihood finding in a trivial process must not outrank a moderate risk in a system the business cannot live without. Fourth, the plan assigns procedures, people and time, explicitly considering audit risk: the risk of reaching an incorrect conclusion based on audit findings. Its three components discipline the planning. Inherent risk is the susceptibility of the area to error or fraud before any controls are considered. Control risk is the chance that the client's controls fail to prevent or detect it. Detection risk is the chance that the auditor's own procedures miss what remains. Where inherent and control risk are high, the plan must drive detection risk down through more extensive, better-designed, or more experienced testing.

Two cross-cutting points complete the picture. Project management is not a separate discipline the auditor borrows for the occasion; it is embedded in the plan itself. The budget, resource allocation and schedule dates the glossary's scope notes require are project management applied to the audit process, and the CISA tasks expect the auditor to apply project management methodologies to keep the engagement on scope, on time and on budget. And the planning sequence has a non-negotiable first step the exam returns to again and again: before designing procedures, the auditor gathers information to understand the process, its risks and its controls. Procedures designed around an unexamined process test the auditor's assumptions, not the client's reality.

1A4 Types of Controls and Considerations

The plan from 1A3 exists to test controls, so the auditor must classify them correctly. ISACA's glossary gives three functional types. Preventive controls are used to avoid undesirable events, errors and other occurrences the enterprise has determined could have a negative material effect — the locked server room, the input validation that rejects malformed data, the segregation of duties that makes fraud require collusion. Detective controls are designed to detect and report when errors, omissions and unauthorized uses or entries occur — the log review, the bank reconciliation, the exception report. Corrective controls are designed to correct errors, omissions, unauthorized uses and intrusions once they are detected — the rollback procedure, the reissued transaction, the incident response playbook. The exam's favorite trap is the control that both notices and stops: classify by primary purpose. A control that blocks an attack in real time is preventive even though it also noticed the attack; a control that merely reports it is detective.

Control considerations shape which controls the auditor expects to find and how much reliance each earns. Cost matters: a control should not cost more than the risk it mitigates, and the auditor evaluates whether the control set is proportionate, not merely present. Compensating controls matter more: where a preferred control is impractical, an alternative achieving the same objective can earn reliance — the auditor tests the compensation, not the absence. And the control environment matters most: the identical technical control earns different reliance in a disciplined environment than in a chaotic one.

Finally, the auditor must evaluate the role and impact of automatization and decision-making systems — the CISA tasks name this explicitly, and it now pervades every control type. Automated controls execute consistently but fail consistently: a misconfigured automated preventive control denies every legitimate transaction, or permits every fraudulent one, at machine speed. Decision-making systems, from rules engines to machine-learning models, introduce risks the plan must capture: biased or stale training data, logic the business cannot explain, and over-reliance by staff who stop exercising judgment. The auditor's job is not to bless automation but to evaluate it — testing whether automated controls are designed correctly, operate consistently, and remain subject to human oversight where the decision affects the enterprise's risk posture. An audit plan that treats "the system handles it" as an answer has confused a control with an excuse.

Open the free chapter →

Before you buy

How do I get it?
Pay, and the download appears on this page straight away. The links are also emailed to you. No account is required.
What if it isn't for me?
Email us within 14 days for a full refund, no questions asked.
Is there online practice for this exam too?
No. PrepPass has no online question bank for this exam; the book is self-contained. Its chapter quizzes and full-length practice exam, each question with a worked explanation, are all in the PDF and EPUB.
Can I read it on my phone?
Yes — the EPUB is for phones and e-readers, the PDF is for printing and tabbing. You get both.

Full refund policy

The details

All five ISACA domains at their published weights, 250 original practice questions with worked explanations, and a 150-question full-length practice exam.

PrepPass team · Verified against ISACA's published CISA Exam Content Outline (effective August 2024) and Certification Exam Candidate Guide · How we review
  • Format: PDF + EPUB download · 216 pages
  • 250 practice questions in the book, with a full answer key
  • $19.99 one-time — no subscription
  • 14-day money-back guarantee · refund policy
  • Cross-referenced against: ISACA's published CISA Exam Content Outline (effective August 2024) and Certification Exam Candidate Guide
  • Last updated: September 2026
  • Verified from the official source(ISACA's published CISA Exam Content Outline (effective August 2024) and Certification Exam Candidate Guide)
  • Instant download, yours for life
Same exam, a fraction of the price
$795–$3,799→$19.99

A CISA review course or boot camp runs $795–$3,799. This book teaches the same exam — same rules, verified to current standards — for a one-time $19.99 you keep for life.

What the book gives you

PrepPass has no online question bank for this exam, so the $19.99 book is complete in itself: the material taught in order, a quiz closing each chapter and a full-length practice exam, in a file you own.

  • Systematic teaching — every exam section explained chapter by chapter, start to finish, not just questions
  • Print it & tab it — a paper-ready PDF you can highlight, mark up, and bring to your study table
  • Study anywhere, offline — EPUB on your phone or e-reader; no wifi, no browser tabs
  • Everything in one place — the chapters and the practice questions in one file
  • Yours for life — one-time $19.99, instant download, no subscription

And it's risk-free: 14-day money-back guarantee — not satisfied? Email us for a full refund, no questions asked. See the refund policy.

Get the eBook — $19.99 (PDF + EPUB) ↑

14-day money-back guarantee · full refund, no questions asked.

One-time purchase, lifetime access to the download. The eBook is the full CISA — Certified Information Systems Auditor study guide in PDF and EPUB. Educational summary, not professional or legal advice — always confirm the current rules with the official source. Last updated: September 2026.

Report