
Explore information systems auditing and the CISA credential, covering the five domains, the code of ethics, and the exam format plus maintenance requirements for ongoing certification.
Master a five-step, risk-based audit planning method that maps the universe, scores inherent risk, uses heat maps, and plans capacity aligned with risk appetite to prioritize scarce audit hours.
Explore how the audit charter grants authority, uphold independence of mind and appearance, and apply dual reporting to the audit committee for objective audits.
Discover how quality assurance and improvement programs safeguard audit credibility by building a three-layer QAIP, tracking KPIs like cycle time and closure rate, and executing rigorous follow-ups.
Learn to replace vanity metrics with outcome-driven IT KPIs by applying maturity models like COBIT 2019, designing smart KPIs, balancing leading and lagging indicators, and using a six-part KPI canvas.
Reframe software testing as a security and risk discipline by mastering UAT, regression, performance, and security tests, while ensuring safe test data management in pre-production environments.
Explore system migration, cutover strategies, and post-implementation reviews through the TSB bank failure case, contrasting big bang, parallel run, phased, and pilot approaches with ETL checks and MACs.
Explore the difference between business continuity and disaster recovery, learn the continuity lifecycle from BIA to testing, and examine RTO- and RPO-driven cloud and site strategies for resilient operations.
Explore how end-user computing and spreadsheets can trigger the J.P. Morgan London whale losses. Identify how to inventory EUCs, apply six control objectives, and enforce named ranges.
Discover identity and access management as the bedrock of security, covering the JML lifecycle, least privilege, privileged access management, phishing-resistant multi-factor authentication, single sign-on, and zero trust.
Audit cryptography and PKI through a governance-focused framework, verifying controls, threat models, and the key lifecycle from generation to destruction, plus post-quantum readiness using modern algorithms and HSMs.
Explore modern enterprise defense architectures, from layered perimeter controls and micro-segmentation to zero trust access and data loss prevention, showing why firewalls alone aren’t security.
Explore the high-stakes of privacy, data protection, and regulatory compliance, from GDPR accountability and ROPA to cross-border transfers, DPIA, and mandated security frameworks for auditors.
Master the ISACA CISA with an eight-week blueprint featuring domain deep dives. Use Anki, 200 weekly questions, a 150-question final, and aim for a 450 scaled score via QAE.
This course contains the use of artificial intelligence.
Welcome to the most comprehensive and professionally structured preparation course for the ISACA Certified Information Systems Auditor (CISA) certification available online today. Whether you are an aspiring IT auditor targeting your first professional credential, an internal auditor expanding into information systems, a GRC or compliance professional, a security manager preparing for a globally recognised designation, or an experienced practitioner seeking a structured review of all five CISA domains — this course gives you everything you need to pass the ISACA exam and perform at the highest level in real-world IS audit engagements.
The CISA certification is one of the most respected and widely recognised credentials in the technology and audit profession worldwide. With over 168,000 active certified professionals across financial services, healthcare, government, defence, energy, and retail, CISA is the benchmark for information systems auditing competence globally. This course prepares you not just to pass the 150-question, four-hour examination — it prepares you to be the kind of IS auditor that organisations trust with their most consequential assurance work.
Across eight comprehensive modules covering all five CISA domains, you will build complete mastery of the information systems auditing discipline. You begin with the foundational principles — understanding what IS audit is, how the ITAF framework governs professional practice across its General, Performance, and Reporting Standards, and how to plan and execute risk-based audit engagements from universe construction through to audit committee presentation. Audit evidence, sampling methodology, and Computer-Assisted Audit Techniques using IDEA, ACL, Power Query, and Python pandas are all covered in full alongside the five-step engagement lifecycle.
Domain 2 takes you deep into IT governance using COBIT 2019, ISO/IEC 38500, and ITIL 4 — covering IT strategy, policy hierarchies, enterprise architecture, application and project portfolio management, IT performance measurement, maturity models, and outsourcing governance including vendor due diligence, MSA and SLA design, SOC 2 reliance, and cloud shared-responsibility models. Domain 3 covers the full acquisition, development, and implementation lifecycle — from business case construction and feasibility through SDLC, DevSecOps, secure development frameworks, all testing strategies including UAT, regression, performance, and penetration testing, and through to cutover strategy, data migration controls, and post-implementation review.
Domain 4 gives you complete command of IS operations and business resilience — covering ITIL 4 service management practices, database and backup controls including the 3-2-1 and immutable backup rules, Business Continuity Management under ISO 22301 including BIA, RTO and RPO, recovery site categories, DR testing modalities, end-user computing risk, and ITSM auditing including CMDB accuracy assessment. Domain 5 — the most heavily weighted domain at 27% of the exam — covers information security programs mapped to ISO 27001, NIST CSF 2.0, and CIS Controls v8; identity and access management including the JML lifecycle, PAM tools, FIDO2, and zero trust; cryptography and PKI including post-quantum migration; network and endpoint security; SOC operations and MITRE ATT&CK detection coverage; and privacy and data protection under GDPR, HIPAA, PCI DSS, and the EU AI Act.
The exam preparation module gives you ISACA's precise question-attack methodology — mastering trigger words including BEST, FIRST, MOST, MAJOR, and PRIMARY — alongside a proven two-month study plan, Anki spaced-repetition strategy, and score interpretation guidance. Real-world case studies from the TSB Bank IT migration failure in the UK and the Equifax data breach in the US provide the applied context that converts domain knowledge into professional judgement.
About Veloxa Labs: This course is proudly delivered by Veloxa Labs, a specialist IT training and certification provider dedicated to advancing professional education in Networking, Information Technology, Data Security, and preparation for the world's leading IT certifications. Veloxa Labs designs its courses to meet the demands of the modern technology industry, combining rigorous technical content with structured, career-focused learning experiences that prepare professionals for real-world challenges and globally recognised credentials.