Skip to main content

CISA Certified Information Systems Auditor.

CISA is the reference IT-audit credential, awarded by ISACA since 1978. Five domains covering the audit process, governance, acquisition, operations and asset protection. The credential Big Four engagements default to. Recognised globally; mandatory for many internal-audit and compliance roles in regulated industries.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyCertifications & credentialsAll entries

The Cyber Academy take

CISA is the reference IT-audit credential, awarded by ISACA since 1978. Five domains covering the audit process, governance, acquisition, operations and asset protection. The credential Big Four engagements default to. Recognised globally; mandatory for many internal-audit and compliance roles in regulated industries.

What CISA actually certifies

CISA is the credential that signals you can audit an information system and defend the opinion you reach. It is awarded by ISACA and has been the reference IT-audit qualification for decades, which is why it is the default expectation on Big Four engagements and the requirement many regulated employers write into internal-audit and compliance job descriptions. The certification is not about running IT or securing it. It is about independently assessing whether controls exist, whether they work, and whether the evidence supports that conclusion.

The practitioner distinction worth holding onto is that CISA is an assurance credential, not an implementation one. A CISM holder runs a security programme. A CISA holder forms an independent opinion on whether that programme, and the wider IT environment around it, is controlled. That independence is the whole point: an auditor who built the control cannot credibly assure it. CISA trains the evidence-and-sampling mindset that keeps the opinion defensible.

The five CISA domains

The exam and the body of knowledge are organised into five domains. They move from how you audit, through how IT is governed, to the three lifecycle areas an auditor has to be able to assess:

  • Information systems auditing process. Planning, risk-based scoping, evidence gathering, sampling, and reporting. The discipline that makes every other domain auditable.
  • Governance and management of IT. Strategy, policies, organisational structure, and how the enterprise steers and oversees its IT.
  • Information systems acquisition, development and implementation. Whether projects, change, and new systems are controlled from business case through go-live.
  • Information systems operations and business resilience. Day-to-day operations, service management, backup, continuity, and disaster recovery.
  • Protection of information assets. Logical and physical security, identity and access, encryption, and data protection controls.

Where CISA sits next to neighbouring credentials

CISA does not stand alone in the ISACA catalogue, and practitioners routinely stack it. The most common moves are sideways into risk with CRISC, or up into security leadership with CISM. Against the ISO world, CISA and the PECB Lead Auditor credential both certify audit competence but in different lanes: CISA is a broad IT-audit qualification tied to ISACA domains, while Lead Auditor is built on ISO 19011 and aimed at auditing a specific management system such as an ISO 27001 ISMS, often as the route to becoming an accredited certification-body auditor.

CISA compared to neighbouring credentials
CredentialBodyPrimary focus
CISAISACABroad IT-audit assurance across five domains
CISMISACAManaging and governing an information security programme
CRISCISACAIT-risk identification, assessment and response
Lead AuditorPECBAuditing a specific management system on ISO 19011

Earning the credential is more than passing the exam. ISACA requires verified professional IT-audit experience, adherence to a code of professional ethics, and ongoing continuing professional education to keep the certification active. That experience requirement is why CISA carries weight: it confirms the holder has actually done the work, not just studied it.

Frequently asked questions

01What is the difference between CISA and CISM?

CISA certifies that you can independently audit and assure an IT environment. CISM certifies that you can design and manage an information security programme. CISA is the assurance side, CISM is the management side, and many practitioners hold both.

02Is work experience required to get CISA?

Yes. ISACA requires verified professional experience in information systems auditing, control, or security in addition to passing the exam. There are limited substitutions, but the experience requirement is central to the credential.

03How is the CISA exam structured?

The exam is built around the five CISA domains and is scenario-based. Questions test audit judgement and risk prioritisation, such as what an auditor should do first in a given situation, rather than rote recall of control names.

04CISA or PECB Lead Auditor, which should I choose?

CISA is a broad IT-audit credential tied to ISACA domains and is the default in IT-audit and Big Four roles. PECB Lead Auditor is built on ISO 19011 to audit a specific management system, such as ISO 27001, and is the path toward accredited certification-body auditing. They serve different career routes and are not mutually exclusive.

05Do you have to renew CISA?

Yes. CISA holders maintain the credential through ISACA's continuing professional education programme and adherence to its code of professional ethics. Without ongoing CPE the certification lapses.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.