ISACA Certified Information Systems Auditor (CISA) Cert Prep
7h 5mIntermediate2026-06-04
Authors

Cybrary
Course details
The Certified Information Systems Auditor (CISA) certification from ISACA validates expertise in auditing, monitoring, and assessing IT and business systems. Whether you're an auditor moving into IT or an IT professional transitioning into auditing, this prep course covers the core concepts and essential skills you need to know to pass the exam. Explore each of the five CISA domains: Information Systems Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development, and Implementation; Information Systems Operations and Business Resilience; and Protection of Information Assets. Discover a risk-based approach to audit engagements, testing and assurance practices, and emerging technology considerations. Along the way, real-world examples, frameworks, and case studies help you connect the material to your everyday work in IT auditing.
Concepts
Introduction
- Instructor overview and welcome to CISA
- CISA overview
Information System Auditing Process
- IS audit standards
- Types of audits
- Risk-based audit planning
- Types of controls and control considerations for auditing
- Audit execution and audit program project management
- Audit testing, sampling, and evidence collection
- Audit data analytics
- Audit reporting and quality improvement
Governance and Management of IT
- Auditing IT governance
- Governance, risk, and compliance (GRC) of IT
- IT organizational structure
- External factors of IT governance
- Policies, standards, and procedures
- Key enterprise governance of IT programs and auditing
- Key IT management programs and auditing
- Performance monitoring and reporting
Information Systems Acquisition, Development, and Implementation
- IT project management
- System development methodologies and tools
- Software development methodologies
- Infrastructure development and acquisition
- Hardware, software, and system software acquisition
- Application controls and output controls
- System readiness and implementation testing
- Configuration and release management
- System migration, deployment, and data conversion
- Post-implementation review
Information Systems Operations and Business Resilience
- IT components overview
- IT components deepdive - Networking
- IT components deepdive - Hardware and maintenance
- IT components deep dive - Back-end devices and other technologies
- IT asset management
- Job scheduling
- System interfaces
- End-user computing
- Systems availability and capacity management
- Problem and incident management
- IT change, configuration, and patch management
- IT operations and operational log management
- IT service level management
- Database management
- Business resilience and business impact assessments (BIAs)
- Backup and recovery methods
- Business continuity planning, testing, and auditing
- Disaster recovery
Protection of Information Assets
- Identity and access management
- Network and endpoint security
- Data loss prevention
- Data encryption
- Public key infrastructure
- Cloud and virtualized environment
- Mobile and wireless
- Security awareness and training
- Information system attack methods
- Security testing tools and techniques
- Security monitoring logs, tools, and techniques
- Security incident response management
- Evidence collection and forensics
- Course wrap-up
- Information asset security governance documents
- Physical and environmental controls
- Identity and access management basics