← Back to catalogue
Certification preparation

CISA: audit IT, controls, and resilience

Prepare for CISA through practical auditing of governance, projects, production, resilience, and information protection.

ISACAAvailable
ISACACISA8 lessons
Outline effective August1,2024, weights18/18/12/26/26%. Exam of150questions in240minutes, passing450 on the200–800 scale without percentage equivalence. Portuguese is not listed among official guide languages. ITAF5 identified from current public guidance without claiming access to full normative text. The November CISM update is not presented as a CISA change. Certification requires experience and other ISACA conditions in addition to passing the exam.

Objectives and progression

Eight lessons, 50 regular questions, and eight original cases with an internal 32-decision assessment in 50 minutes. First pass through five CISA domains of the outline effective August 1, 2024. Fictional banking and APS examples connect independence, evidence, migration, batches, suppliers, recovery, and access. Includes public ITAF 5 guidance and NIST methodology without reproducing official questions or claiming full coverage of normative ITAF text.

Audience: IT auditors, technical managers, APS teams, and risk and control professionals.

Prerequisites: IT, security, and operations fundamentals. CISA certification normally requires five years of relevant experience, subject to eligible waiver rules, plus the exam and other ISACA conditions. The exam may be taken before meeting experience requirements; confirm individual requirements with the provider. dr.pt does not award CISA.

290 estimated study minutes

  • Define objectives and boundaries for an independent assessment guided by risk.
  • Produce conclusions respecting the population, period, and method used.
  • Assess alignment, accountability, and quality of IT reporting.
  • Trace requirements and evidence to delivered artifacts and data.
  • Distinguish technical indicators from business-process fulfillment.
  • Assess objectives, dependencies, and tests against the event the service must withstand.
  • Assess the actual reach of access and cryptographic controls.
  • Form security conclusions with authorization, traceability, and clear limits.

Modules

  1. Audit mandate, independence, and planning
  2. Evidence, samples, and conclusions
  3. Governance, resources, and suppliers
  4. Delivery, migration, and acceptance
  5. Audit operations, batches, and interfaces
  6. Resilience and recovery evidence
  7. Identity, data, and protection boundaries
  8. Detection, testing, and incident evidence

Continue learning

Cybersecurity

References and version

CISA outline effective August 1, 2024

What you will explore

0 / 8

Learning is also trying.

Original explained questions, flashcards, and scenarios to apply the concepts.

Practice
This module covers foundations. It is not a complete certification course or a full simulation of the official exam.

Exam domains

Information Systems Auditing Process18%
Governance and Management of IT18%
Information Systems Acquisition, Development and Implementation12%
Information Systems Operations and Business Resilience26%
Protection of Information Assets26%