Last updated:
CISA preparation guide
CISA study resources: where to start and what to review
Start with the official CISA exam outline, use a baseline to find gaps, then combine concept study with scenario review. Choose resources for the question you need to answer: what is tested, what you misunderstand, or whether you can apply it without hints.
A large reading list is not a study plan. If you already understand a control but keep selecting an action outside the auditor’s role, another definition may not resolve the mistake. Compare the alternatives and explain the decision in your own words.
These guides organize independent CertArc teaching material around that review process. Use ISACA for authoritative exam and certification requirements. Use practice results as evidence about your preparation, not as an official score forecast.
Start CISA baselineChoose a resource by the gap you need to close
| Your question | Start here | What to take away |
|---|---|---|
| What is on the exam? | Exam domains | A checklist of all five domains, not only your strongest subjects |
| Where should I start? | Free diagnostic | An initial view of answers, confidence and time |
| Why was my answer weaker? | Practice questions and auditor mindset | The role, evidence or sequence that changed the decision |
| How should I use my available time? | Study plan | A schedule with time reserved for reviewing mistakes |
Original teaching example
You have read about access reviews twice, but still choose to remove an account when the question asks how an auditor should establish whether a review control operates.
The next useful resource is a worked review of audit evidence, not another list of access-control terms. Explain what records would demonstrate the review, then identify who is responsible for acting on exceptions.
Keep official facts and teaching advice separate
Check ISACA’s current outline before setting your coverage checklist. CertArc’s study suggestions are not ISACA requirements, and completing a practice program does not grant certification.
Build a small review loop
After a practice session, choose one recurring issue, revisit the relevant concept, and test it on a different scenario. A useful note describes why an option was unsuitable; recording only the correct letter will not help when the context changes.
Frequently asked questions
Are these official ISACA resources?
No. These are independent CertArc guides. Official exam facts link to ISACA, and the teaching examples are original illustrations.
Which guide should I read first?
Start with exam domains if the scope is unfamiliar. If you already know the outline, take the baseline and use its results to choose a review topic.
Can I read the guides without an account?
Yes. These public guides are readable without signing in. The practice program uses its separate onboarding and account flow.
Do I need to read every guide before practicing?
No. Read what helps with your current gap, then use practice to check whether you can apply it. Return to the outline regularly so other domains are not neglected.
Where are the CISA access plans?
Choose CISA on the pricing page. Monthly and 90-day access cover the selected program; 24-month all-program access covers released certifications during the access period.
Sources and limits
Exam scope and weights: ISACA CISA exam content outline. Certification eligibility: ISACA certification requirements. Checked September 9, 2026.
Study methods and examples are independent CertArc teaching guidance. Practice results do not convert to an official score or guarantee a pass. CertArc is not affiliated with or endorsed by ISACA.