
Master information system auditing from scratch, prep for the CSA exam on the first attempt, and gain real life experience in planning, conducting, and reporting, including internal and external audits.
Explore the value, prerequisites, renewal, exam process, and domain coverage for the certified information system auditor. Check isaka.org for details on the certification, eligibility, application, and computer-based testing.
Examine the CISA exam structure, including hours, 150 questions, domain distribution, and member versus non-member pricing, to map questions to domains for focused study.
Explore CISA course outline across domains: auditing process, IT governance and management, information system acquisition, development and implementation, operation and business resilience, and security, with templates, documents, and step-by-step guides.
Explore audit overview fundamentals, including purpose, scope, and documentation, and learn how ISMS and ISO 27001 audits are conducted with real reports and structured findings.
Define governance, risk, and compliance within the GRC framework, showing how IT investments support business objectives and how risk, threat, and vulnerability drive audits via COBIT, ITIL, CMMI, and FAIR.
Explore how governance, risk, and compliance translate into realistic workflows, contrast manual vs automated GRC practices, and preview tools like Archer from RCA, SAP, ACL, and SAI.
Learn the IT audit framework ITAF by Isaca, outlining general, performance, and reporting parts, with emphasis on proper audit processes, independence, risk assessment, evidence, and free download.
Follow a scenario-based audit of a software house providing mobile apps, mapping findings to departments—HR with finance, sales with marketing, IT with network and development—using applicable frameworks and regulations.
Learn to align audit findings with ISO 27001 and ISO 2000 standards by mapping controls to domains, validating readiness, and using attached control lists for real audits.
Learn the crucial definitions of tasks and knowledge statements for information systems auditing, and how to validate logs, data centers, and databases, plus the mapping between knowledge statements and tasks.
Senior management drives business success by defining goals, understanding requirements and risk, and providing strategy, sponsorship, and budget, with policy, standards, guidelines, and procedures to support governments, risk, and compliance.
Senior management translates governance, risk, and compliance into policy, standards, guidelines, and procedures, then implements controls, audits, and dashboards to assess residual risk and confirm management success.
Understand the four-layer ISACA organization structure: senior management sets governance and policy; steering and committee approve projects and policies; audit checks controls; program management runs projects; IT supports the business.
Learn to conduct an information system audit using a risk-based strategy, craft an audit plan, perform the audit, and report findings with executive and detailed reports.
Review an IS audit report sample to see how observations, non-conformities, and evidence are documented. Learn how internal and external auditors use these reports.
Learn to use the information asset register to inventory information assets, including documents, software, hardware, and people, and assess ownership, custody, and the confidentiality, integrity, and availability ratings for auditing.
Explore IT risk assessment, risk analysis, and risk-based audit to map threats to business objectives and information assets using probability and impact, and apply mitigation and other risk management techniques.
Master audit planning and management guided by PMI standards. Identify audit subject, objective, and scope; plan resources; gather and evaluate information; apply PMI’s five project phases from initiation to closing.
Audit document control in information systems by verifying document id, owner, writer, approver, issue dates, last saved dates, version history, and annual reviews.
Map the business process to IT by first understanding what the organization does, its external factors, strategy, objectives, and performance measures, then assess how IT supports critical functions.
Explore how law and regulation shape information system audits, noting country-specific policies, log retention, backup, audit frequency, and reporting requirements, with HEPA and SOX as examples.
Learn to collect reliable, objective evidence from independent, qualified sources using interviews, documentation review, data gathering, and sampling. Validate evidence with witnessed collection and signed minutes.
Explore how sampling relates to evidence and compliance, examine statistical and judgment sampling in auditing, and validate controls before sampling with population size, precision, and risk.
Validate control functionality through compliance checks before sampling, then apply statistical or judgment sampling based on population, precision, and risk. Prepare for exam-style questions on sampling and terminology.
Empower your organization with targeted security awareness and training that educates employees on threats, phishing, and social engineering, aligns with GDPR and HIPAA, and reinforces resilient on the job practices.
Establish and apply IT audit standards and guidelines to plan, assess risks, collect evidence, report findings, and follow up, aligning audits with COBIT, ITIL, ISO, and organizational governance.
Apply the risk management framework with six steps—categorize, select, implement, assess, authorize, and monitor information systems—to align security with risks, policies, contingency planning, ISO 27,001, and business continuity objectives.
Study professional ethics as a cornerstone of information security, guiding trust, accountability, and protecting society and infrastructure. Learn how a code of ethics, canon principles, ethical decision making shape practice.
Security documentation provides the blueprint for defining protocols, responsibilities, and expectations, guiding governance, ensuring regulatory compliance, and unifying efforts through policies, standards, and procedures.
Identify and assess cybersecurity risks using asset-based and service-based methodologies, calculate risk by impact and likelihood, and prioritize actions with risk registers and heat maps.
Identify assets, threats, vulnerabilities, and risks, then mitigate them through structured threat modeling using stride and other frameworks to build proactive, compliant security.
Explore how to build a resilient organization with a BCP and BIA, defining scope, policy and authority, roles, testing, and disaster recovery integration, plus metrics like RPO, RTO, and MTD.
Explore how a robust information security policy underpins an organization's security framework, detailing objectives, types, documents, components, and a practical template to guide implementation.
Align IT with business strategy to deliver secure, reliable information, manage risk, and support strategic objectives with accountability.
Master governance and management of IT and learn how to audit IT governance in any organization, covering 11 tasks and 16 knowledge statements to prepare for the exam.
Align information security governance with business strategy to ensure regulatory compliance, protect client information, and manage risk through policies, culture, and KPIs.
Explore information system strategy driven by a streaming committee and strategic planning, aligning projects and change requests with the strategic plan, mission, and business plan, plus IT state assessment.
Define an effective IT organization by clarifying roles and responsibilities, establishing a governance committee and PMO, applying a RACI chart, and implementing a change management process.
Explore the maintenance of policy and procedures, including policy, procedures, standards, guidelines, and baseline, and how auditors verify awareness, accessibility, and annual validation of security and acceptable user policies.
Build a comprehensive information security documentation framework for the ISMS by studying policy, standards, guidelines, and procedures, and by using templates from sans.org to implement management-approved, high-level policies and baselines.
Explore legal compliance in outsourcing, assess cross-border data exposure, and apply segregation of duties and controls, with compensating controls for secure, auditable transactions.
Audit the quality management system by evaluating quality assurance versus quality control, ensuring measurable process compliance and improvements, and understanding ISO 9001 certification and internal audits.
Explore three maturity models—CMMI, IDEAL, and PAM—and learn how they help avoid reinventing the wheel, enable process measurement, and reduce business costs.
Understand process optimization in IT auditing by defining it as improving performance without raising costs and evaluating it with tools like KPI, PDCA, CSF, Six Sigma, and benchmarking.
Audit IT investment for value for money, spend in the right places, and apply value optimization and ISACA COVID framework considerations.
Audit the IT supplier selection process from make-or-buy decisions to fair supplier evaluation, using a waiting system beyond price, and verify contracts, NDAs, ongoing status reports, and proper contract closure.
Apply make or buy analysis to decide renting or buying project resources, and master plan procurement management, procurement statements of work, and source selection criteria using a weighting system.
Assess risk across the organization by identifying risks, ranking them by likelihood and impact, and applying qualitative and quantitative methods to build a risk register and heat map.
Explore how to conduct a business impact analysis to identify and prioritize critical functions, determine recovery time objectives, and build a plan using templates and standards for availability.
Explore information systems acquisition, development, and implementation through core project management practices, from validating the business case to post-implementation review, and compare PMP, PRINCE2, and Agile frameworks.
Learn project governance, align IT projects with the company portfolio, and understand portfolio, project, and PMO concepts, plus organizational structures for functional and projectized setups for auditing.
Explore functional, matrix (weak, balanced, strong), and projectized organizations and how they shape project management through resource allocation and both vertical and horizontal communication.
Explore the five process groups and ten knowledge areas that define PMI project management. Learn how initiation, planning, execution, monitoring, and closing drive 47 processes, charters, stakeholders, and planning outputs.
Audit the IT architecture through its life cycle—from analysis to implementation—by reviewing the current data center, planning with vendor evaluation and a proof of concept, and assessing hardware and software.
Explore planned procurement management by defining procurement terminology, creating a request for proposal (RFP), detailing the statement of work, and auditing contract types to assess vendor selection.
Learn planned procurement management and make or buy analysis to decide buy or rent options, define the procurement statement of work, and apply a source selection weighting system.
This lecture outlines information system operations as the domain of daily audit activities, covering 11 tasks from service level and third-party management to backup, disaster recovery, and incident handling.
Explore service management within ITSM, including SLA, KEDB, and SIP, and distinguish support services from delivery services such as service desk, incident, problem, configuration, change, release, capacity, and availability management.
Audit hardware, software, and network by examining organization-specific risks across mainframe, client-server, and cloud setups; address shoulder surfing, insecure printing, usb data handling, and virus and patching practices.
Audit software license inventory to prevent unlicensed software; verify license evidence and copies, understand licensing types including open source and Microsoft asset management guidance, and report unlicensed installations immediately.
Align current and future capacity planning across processing, storage, memory, and network with business needs. Maintain an annual, cost-effective capacity plan that is continuously tuned to business growth and constraints.
Define incident versus problem, and map the incident management lifecycle from capture and categorization to priority, resolution, and closure, including root-cause analysis using the fishbone diagram.
Explore incident management and incident reports, detailing what should be inside, including root cause, corrective and preventive actions, and document control, with sample templates.
Explore backup concepts for availability, including media options such as tape drives, remote storage, remote journaling backups, and electronic vaulting, plus full, differential, and incremental backups and restoration.
Explore disaster recovery plans as the technical arm of business continuity, detailing risk, cost-benefit, and short-, mid-, and long-term priorities, with backup types like mirroring and full, incremental, differential backups.
Learn about alternative sites for business continuity, including hot site mirroring, warm, cold, portable sites, and mutual aid agreements, plus recovery and salvage teams restoring operations after a disaster.
Audit protection of information assets by examining information security policy, security awareness, data classification, incident handling, physical access, environmental controls, and data storage and backup aligned with the CIA triad.
Learn how access control integrates identification, authentication, authorization, logging, and accounting across technical, physical, and administrative security, with models like discretionary and mandatory access control, and role-based and time-based approaches.
Explore network architecture from hubs to switches, ARP vulnerabilities, and MAC address tables, then learn how routers use routing tables and dynamic protocols like rip and ospf.
Practice cryptography basics with Cryptool, explore the Caesar cipher through substitution and transposition, and understand that encryption provides confidentiality and integrity—but not availability, with public protocols and secret keys.
Explore physical security implementation, focusing on fences, doors, lighting, and access control. Learn exam-relevant details on deterrence fences, guards, intrusion detection, logs, and alarms.
Identify information assets and build an asset register with owner and custodian, apply classification levels and labeling (public, confidential, restricted) under policy and privacy laws.
Explore how law, regulation, and frameworks drive information security through policies and documentation. Learn to implement security policies, templates, and a policy framework in real-world organizations.
Are you preparing for the CISA exam and looking for a structured, exam-focused course that covers every domain?
The Certified Information Systems Auditor (CISA) is one of the most recognized credentials in IT auditing, governance, and security. Earning it can open doors to senior roles in audit, compliance, and information security — and this course is designed to help you get there.
What you will get:
Complete coverage of all 5 CISA exam domains
Real-world audit scenarios that reinforce every concept
Domain-by-domain practice questions for self-assessment
Content covering all CISA exam topics, updated for 2026
No prior experience required — structured from the ground up
This is an independent preparation course, not affiliated with or endorsed by ISACA.
Domain 1 – Information System Auditing Process
Audit planning, risk-based audit execution, evidence collection, sampling techniques, IT audit standards, professional ethics, and audit reporting.
Domain 2 – Governance and Management of IT
IT governance frameworks, strategic alignment, legal and regulatory compliance, business impact analysis, maturity models, and IT investment management.
Domain 3 – Information Systems Acquisition, Development and Implementation
Project governance, procurement management, SDLC, system architecture, and make-or-buy decisions.
Domain 4 – Information Systems Operations and Business Resilience
Incident and service level management, hardware and software operations, backup strategies, disaster recovery planning, and alternative site strategies.
Domain 5 – Protection of Information Assets
Access control frameworks, network security, cryptography, physical security controls, and data classification practices.
Who this course is for:
IT professionals transitioning into auditing, compliance, or GRC roles
Aspiring IT auditors preparing for the CISA exam
Security professionals looking to formalize their audit knowledge
Compliance officers seeking a structured understanding of IS auditing
Enroll now and take the next step toward your CISA certification.