Scroll to top
CISA

The 5 CISA Domains Explained

What the five domains cover.

ISACA
Training delivered by Virtual Infrastructure Services LLC — an accredited ISACA Training Organization.

The CISA exam is built around five domains that together cover the full IS audit lifecycle — from planning an engagement to protecting the assets under review. Here's what each one covers.

Domain 1 — Information Systems Auditing Process

The core of the credential: planning and executing audits. Covers IS audit standards, guidelines and codes of ethics, risk-based audit planning, types of audits and assessments, audit project management, sampling methodology, evidence collection, data analytics, reporting, and quality assurance of the audit process.

Domain 2 — Governance and Management of IT

How IT is governed and run: IT-related frameworks, standards, policies and procedures, organizational structure, enterprise architecture, enterprise risk management, maturity models, and the laws, regulations and industry standards affecting the organization — plus IT resource, service-provider and performance management.

Domain 3 — Information Systems Acquisition, Development and Implementation

Building and deploying systems: project governance, business case and feasibility analysis, system development methodologies, control identification and design, testing methodologies, configuration and release management, system migration and data conversion, and post-implementation review.

Domain 4 — Information Systems Operations and Business Resilience

Running systems reliably: technology components, IT asset management, job scheduling, system interfaces, end-user computing, data governance, performance, problem and incident management, change and patch management, and database management — plus business impact analysis, backups, business continuity and disaster recovery.

Domain 5 — Protection of Information Assets

Securing the assets: privacy principles, physical and environmental controls, identity and access management, network and endpoint security, data classification, encryption and PKI, security awareness, attack methods, security testing and monitoring, incident response, and evidence collection and forensics.

Ready to go deeper? See the CISA exam guide for format and study plan, or explore CISA exam-prep training.

Get certified

Start foundational prep today and join our next monthly live-virtual cohort.

Next cohort: August 31, 2026 (monthly)

Live virtual, instructor-led

Pricing: from $1,195

RegisterRequest a Quote
CISA — Certified Information Systems Auditor