I am trying to build a study plan but I am struggling to find a clear breakdown of the CISA syllabus. Does anyone have a summarized list of the five domains? I want to make sure I am focusing my time on the right areas according to the latest weightings.
The CISA exam covers five core domains weighted as Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development, and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%).
12 answers
When preparing for the CISA, precision is not a suggestion, it is a requirement. You must align your study plan with the ISACA Examination Candidate Information Guide. Deviating from these official weightings is a professional oversight I see far too often in junior auditors. Ensure your allocation of study hours mirrors the official percentages exactly.
The five domains are structured as follows:
- Domain 1: Information Systems Auditing Process (18%)
- Domain 2: Governance and Management of IT (18%)
- Domain 3: Information Systems Acquisition, Development, and Implementation (12%)
- Domain 4: Information Systems Operations and Business Resilience (26%)
- Domain 5: Protection of Information Assets (26%)
Focus your efforts heavily on Domains 4 and 5 as they command over half of your total exam weight. If you are not familiar with the technical nuances of business continuity and data protection, your audit proficiency will not save you. Review the official ISACA job practice areas and verify that your internal documentation aligns with these controls.
If you are attempting to build a study plan, you must first consult the official ISACA CISA Job Practice areas. Relying on summarized lists from third parties introduces the risk of misinformation regarding the current weightings. Per the latest documentation, the five domains are weighted as follows:
- Domain 1: Information Systems Auditing Process (18 percent)
- Domain 2: Governance and Management of IT (18 percent)
- Domain 3: Information Systems Acquisition, Development, and Implementation (12 percent)
- Domain 4: Information Systems Operations and Business Resilience (26 percent)
- Domain 5: Protection of Information Assets (26 percent)
It is statistically significant to note that Domains 4 and 5 represent over half of the examination. Meticulous study of these sections is empirically required to achieve a passing score. Do not neglect the audit standards, as they form the theoretical backbone of the entire syllabus. Precision in your mapping of these domains to your study hours is the only logical path toward certification.
If you cannot find the weightings, you are looking in the wrong place. ISACA publishes these on their site. It is basic due diligence.
- D1: Auditing Process (18%)
- D2: Governance (18%)
- D3: SDLC (12%)
- D4: Ops/Resilience (26%)
- D5: Asset Protection (26%)
Audit is about process evidence. Don't overthink the definitions; focus on the control objectives. If you don't understand how to test a control, you will fail the exam. Prioritize D4 and D5. Everything else is secondary to operational security.
Standardization is the cornerstone of our profession. I suggest you consult the ISACA official CISA Job Practice for the most up-to-date breakdown. Any other source is subject to obsolescence.
The curriculum is defined by these five specific domains:
- Domain 1: Information Systems Auditing Process (18%)
- Domain 2: Governance and Management of IT (18%)
- Domain 3: Information Systems Acquisition, Development, and Implementation (12%)
- Domain 4: Information Systems Operations and Business Resilience (26%)
- Domain 5: Protection of Information Assets (26%)
It is vital to prioritize your study time according to these weights. Allocating equal time to all domains is a flawed strategy. Focus your analytical capabilities on the high-weight domains, as they represent over 50 percent of the examination content. Ensure your study habits include active practice of question-based scenarios, as the exam is less about rote memorization and more about critical evaluation of audit scenarios.
Look, keep it simple. If you are doing incident response, you probably know how things break, but auditors care about how things are documented. The syllabus is public record. Stop searching for shortcuts and go to the source documentation.
The weightings are clear:
- Audit Process (18%)
- Governance (18%)
- Acquisition/Development (12%)
- Operations/Resilience (26%)
- Protection (26%)
If you don't know the difference between an administrative control and a technical control, you're toast. Most candidates fail the operational resilience domain because they assume it's just about backups. It isn't. It's about business processes. Start with the ISACA manual and read it twice. Don't look for secondary sources until you understand the primary one. It is a dry read, but necessary for the certification.
I have watched enough auditors struggle with this. People get bogged down in theory while the exam is practically testing how you apply ISACA’s mindset to real-world scenarios. Don't just memorize the list of domains; understand the logic behind the audit procedures.
The current syllabus is split across these areas:
- Auditing Process (18%)
- IT Governance and Management (18%)
- Acquisition, Development, and Implementation (12%)
- Operations and Resilience (26%)
- Protection of Information Assets (26%)
Take note: Domain 4 and 5 are where the heavy lifting happens. If you treat these like a glossary of terms, you will be disappointed. You need to understand the intent of the control, not just the definition. Most people fail because they try to apply their own company's internal policies to the questions instead of the standardized ISACA framework. Strip your internal biases away, or you will consistently choose the wrong answer.
Effective study requires a framework-centric approach. Do not attempt the CISA without mapping your preparation directly to the ISACA Job Practice. The exam is designed to test your ability to think like an IS auditor, which requires a specific, rigorous mindset.
You are looking at these core domains:
- Information Systems Auditing Process: 18%
- Governance and Management of IT: 18%
- Information Systems Acquisition, Development, and Implementation: 12%
- Information Systems Operations and Business Resilience: 26%
- Protection of Information Assets: 26%
My advice is to document your progress against these weightings weekly. If you find your mock exam scores lagging in Domain 4, adjust your study schedule immediately. The exam is not about knowing everything; it is about knowing what the auditor is expected to verify at each stage of the lifecycle. Maintain focus on the higher-weighted domains to ensure your passing score.
Honestly? If you cannot find the syllabus on the ISACA website, you are already behind. It is literally their business to keep that documentation front and center. I see people spending months on theory while ignoring the reality that this exam is about thinking like an auditor, not a sysadmin.
You want the breakdown? Here it is:
- Audit Process: 18 percent.
- IT Governance: 18 percent.
- Acquisition and Implementation: 12 percent.
- Operations and Resilience: 26 percent.
- Asset Protection: 26 percent.
Stop overthinking the planning and start doing the practice questions. The weightings are a hint: focus on the back end of the syllabus because that is where the bulk of the points are. If you treat this like a technical exam, you will fail. Treat it like a compliance check. Good luck.
The CISA is a test of mindset, not just a memorization of domains. Most candidates fail because they look for facts instead of analyzing the control framework. The weightings provided by ISACA are fixed for the current cycle, and you would be remiss to treat them as suggestions. The exam prioritizes the following:
- Audit Process (18 percent)
- Governance (18 percent)
- SDLC/Acquisition (12 percent)
- Operations (26 percent)
- Protection of Assets (26 percent)
Note the heavy concentration on the latter two domains. If you are weak in operational resilience or security controls, you will not pass regardless of how well you know the audit process. Approach your studies with a focus on risk-based decision making. Every scenario is a vulnerability assessment in disguise. Identify the risk, apply the control, and justify the audit finding. That is the entire exercise.
For an efficient study plan, align your time expenditure directly with the percentage weightings provided by ISACA. The exam evaluates proficiency across five distinct domains. To maximize your success rate, prioritize the domains with the highest weighting, which currently constitute over 50 percent of the total content.
Core Syllabus Domains:
- Information Systems Auditing Process: 18 percent.
- Governance and Management of IT: 18 percent.
- Information Systems Acquisition, Development, and Implementation: 12 percent.
- Information Systems Operations and Business Resilience: 26 percent.
- Protection of Information Assets: 26 percent.
It is advisable to view these domains not as isolated subjects but as a tiered hierarchy of risk management. Ensure your study habits reflect this proportional distribution.
Look, keep it simple. You have 150 questions to get through, and they are designed to trip up people who rely on intuition rather than standard audit practices. The weightings are exactly what they say they are, and you ignore the 26 percent heavy hitters at your own peril.
The Breakdown:
- Audit Process (18 percent): Understand the standards.
- Governance (18 percent): Understand the boardroom perspective.
- SDLC (12 percent): Don't get lost in the weeds here; it's a smaller slice.
- Operations (26 percent): This is your bread and butter for real-world impact.
- Protection (26 percent): This covers the security controls you should already know if you are in this field.
Stop looking for a magic bullet and start pounding the QAE (Questions, Answers, and Explanations) database. That is the only resource that actually matters. The syllabus is just the map; the QAE is the terrain.
Building a methodical study plan requires mapping your time against the official ISACA weightings. It is important to emphasize that while the audit process is foundational, the operational and protection domains command a significant majority of the scoring. Based on the current exam blueprint, please note the following structure:
- Domain 1: Information Systems Auditing Process (18 percent)
- Domain 2: Governance and Management of IT (18 percent)
- Domain 3: Information Systems Acquisition, Development, and Implementation (12 percent)
- Domain 4: Information Systems Operations and Business Resilience (26 percent)
- Domain 5: Protection of Information Assets (26 percent)
When you allocate your study time, I recommend assigning roughly 52 percent of your effort to domains 4 and 5. The remaining effort should be split among the first three. Please remember to review the official ISACA candidate guide for the most granular level of sub-topics within these five categories, as the exam is comprehensive and expects a high level of technical rigor.