The Cyber Academy take
CISA is the reference IT-audit credential, awarded by ISACA since 1978. Five domains covering the audit process, governance, acquisition, operations and asset protection. The credential Big Four engagements default to. Recognised globally; mandatory for many internal-audit and compliance roles in regulated industries.
What CISA actually certifies
CISA is the credential that signals you can audit an information system and defend the opinion you reach. It is awarded by ISACA and has been the reference IT-audit qualification for decades, which is why it is the default expectation on Big Four engagements and the requirement many regulated employers write into internal-audit and compliance job descriptions. The certification is not about running IT or securing it. It is about independently assessing whether controls exist, whether they work, and whether the evidence supports that conclusion.
The practitioner distinction worth holding onto is that CISA is an assurance credential, not an implementation one. A CISM holder runs a security programme. A CISA holder forms an independent opinion on whether that programme, and the wider IT environment around it, is controlled. That independence is the whole point: an auditor who built the control cannot credibly assure it. CISA trains the evidence-and-sampling mindset that keeps the opinion defensible.
The five CISA domains
The exam and the body of knowledge are organised into five domains. They move from how you audit, through how IT is governed, to the three lifecycle areas an auditor has to be able to assess:
- Information systems auditing process. Planning, risk-based scoping, evidence gathering, sampling, and reporting. The discipline that makes every other domain auditable.
- Governance and management of IT. Strategy, policies, organisational structure, and how the enterprise steers and oversees its IT.
- Information systems acquisition, development and implementation. Whether projects, change, and new systems are controlled from business case through go-live.
- Information systems operations and business resilience. Day-to-day operations, service management, backup, continuity, and disaster recovery.
- Protection of information assets. Logical and physical security, identity and access, encryption, and data protection controls.
Where CISA sits next to neighbouring credentials
CISA does not stand alone in the ISACA catalogue, and practitioners routinely stack it. The most common moves are sideways into risk with CRISC, or up into security leadership with CISM. Against the ISO world, CISA and the PECB Lead Auditor credential both certify audit competence but in different lanes: CISA is a broad IT-audit qualification tied to ISACA domains, while Lead Auditor is built on ISO 19011 and aimed at auditing a specific management system such as an ISO 27001 ISMS, often as the route to becoming an accredited certification-body auditor.
| Credential | Body | Primary focus |
|---|---|---|
| CISA | ISACA | Broad IT-audit assurance across five domains |
| CISM | ISACA | Managing and governing an information security programme |
| CRISC | ISACA | IT-risk identification, assessment and response |
| Lead Auditor | PECB | Auditing a specific management system on ISO 19011 |
Earning the credential is more than passing the exam. ISACA requires verified professional IT-audit experience, adherence to a code of professional ethics, and ongoing continuing professional education to keep the certification active. That experience requirement is why CISA carries weight: it confirms the holder has actually done the work, not just studied it.
Frequently asked questions
01What is the difference between CISA and CISM?
CISA certifies that you can independently audit and assure an IT environment. CISM certifies that you can design and manage an information security programme. CISA is the assurance side, CISM is the management side, and many practitioners hold both.
02Is work experience required to get CISA?
Yes. ISACA requires verified professional experience in information systems auditing, control, or security in addition to passing the exam. There are limited substitutions, but the experience requirement is central to the credential.
03How is the CISA exam structured?
The exam is built around the five CISA domains and is scenario-based. Questions test audit judgement and risk prioritisation, such as what an auditor should do first in a given situation, rather than rote recall of control names.
04CISA or PECB Lead Auditor, which should I choose?
CISA is a broad IT-audit credential tied to ISACA domains and is the default in IT-audit and Big Four roles. PECB Lead Auditor is built on ISO 19011 to audit a specific management system, such as ISO 27001, and is the path toward accredited certification-body auditing. They serve different career routes and are not mutually exclusive.
05Do you have to renew CISA?
Yes. CISA holders maintain the credential through ISACA's continuing professional education programme and adherence to its code of professional ethics. Without ongoing CPE the certification lapses.