CISA: audit IT, controls, and resilience
Prepare for CISA through practical auditing of governance, projects, production, resilience, and information protection.
Objectives and progression
Eight lessons, 50 regular questions, and eight original cases with an internal 32-decision assessment in 50 minutes. First pass through five CISA domains of the outline effective August 1, 2024. Fictional banking and APS examples connect independence, evidence, migration, batches, suppliers, recovery, and access. Includes public ITAF 5 guidance and NIST methodology without reproducing official questions or claiming full coverage of normative ITAF text.
Audience: IT auditors, technical managers, APS teams, and risk and control professionals.
Prerequisites: IT, security, and operations fundamentals. CISA certification normally requires five years of relevant experience, subject to eligible waiver rules, plus the exam and other ISACA conditions. The exam may be taken before meeting experience requirements; confirm individual requirements with the provider. dr.pt does not award CISA.
290 estimated study minutes
- Define objectives and boundaries for an independent assessment guided by risk.
- Produce conclusions respecting the population, period, and method used.
- Assess alignment, accountability, and quality of IT reporting.
- Trace requirements and evidence to delivered artifacts and data.
- Distinguish technical indicators from business-process fulfillment.
- Assess objectives, dependencies, and tests against the event the service must withstand.
- Assess the actual reach of access and cryptographic controls.
- Form security conclusions with authorization, traceability, and clear limits.
Modules
- Audit mandate, independence, and planning
- Evidence, samples, and conclusions
- Governance, resources, and suppliers
- Delivery, migration, and acceptance
- Audit operations, batches, and interfaces
- Resilience and recovery evidence
- Identity, data, and protection boundaries
- Detection, testing, and incident evidence
Continue learning
- CISM — Certified Information Security Manager
- CISSP — Certified Information Systems Security Professional
- Technical Project Manager
- Production Support L3
References and version
CISA outline effective August 1, 2024
- CISA Exam Content Outline · 2026-09-29
- ISACA Exam Candidate Guide · 2026-09-29
- Earn a CISA Certification · 2026-09-29
- CISA exam update announcement · 2026-09-29
- Code of Professional Ethics · 2026-09-29
- Frameworks, Standards and Models · 2026-09-29
- Why ITAF 5 Matters · 2026-09-29
- Assessing Security and Privacy Controls · 2026-09-29
- Assessing Security and Privacy Controls · 2026-09-29
- Cybersecurity Framework 2.0 · 2026-09-29
- Guide for Conducting Risk Assessments · 2026-09-29
- Contingency Planning Guide · 2026-09-29
- Technical Guide to Security Testing and Assessment · 2026-09-29
- Incident Response Recommendations and Considerations · 2026-09-29
- Secure Software Development Framework 1.1 · 2026-09-29
- Authentication and Authenticator Management · 2026-09-29
- Shared Responsibility Model · 2026-09-29
- Guidelines for Media Sanitization · 2026-09-29
- Engineering Trustworthy Secure Systems · 2026-09-29
- Recommendation for Key Management · 2026-09-29
- AI Risk Management Framework 1.0 · 2026-09-29
- TLS 1.3 · 2026-09-29
What you will explore
0 / 8Audit mandate, independence, and planning
Define objectives and boundaries for an independent assessment guided by risk.
Evidence, samples, and conclusions
Produce conclusions respecting the population, period, and method used.
Governance, resources, and suppliers
Assess alignment, accountability, and quality of IT reporting.
Delivery, migration, and acceptance
Trace requirements and evidence to delivered artifacts and data.
Audit operations, batches, and interfaces
Distinguish technical indicators from business-process fulfillment.
Resilience and recovery evidence
Assess objectives, dependencies, and tests against the event the service must withstand.
Identity, data, and protection boundaries
Assess the actual reach of access and cryptographic controls.
Detection, testing, and incident evidence
Form security conclusions with authorization, traceability, and clear limits.