Information System Auditing Process
Risk-based audit planning, standards, evidence, sampling, reporting and follow-up.
Choose CISA for audit, CISM for security management, CRISC for technology risk, CDPSE for privacy engineering, or CGEIT for enterprise IT governance. Each path connects official guidance, eight focused units, a free 30-question original diagnostic and transparent booking information.
CISA develops audit judgement. CISM develops security-management judgement. CRISC develops technology-risk judgement. CDPSE develops privacy-engineering judgement. CGEIT develops enterprise-governance judgement. Every pathway uses official ISACA guidance, original learning scenarios and transparent booking information.
Risk-based audit planning, standards, evidence, sampling, reporting and follow-up.
Strategy alignment, policies, enterprise architecture, performance, people and third-party governance.
Business cases, requirements, project governance, testing, migration and post-implementation review.
Service operations, change, incident and problem management, capacity, backup, continuity and recovery.
Identity, access, network and endpoint controls, encryption, privacy, monitoring and incident response.
ISACA keeps the same four CISM domains. The left weight applies through 2 November 2026; the right weight applies from 3 November 2026.
Enterprise governance, legal and regulatory context, security strategy, architecture, business cases, roles and executive reporting.
Threat and vulnerability analysis, risk assessment, ownership, treatment, monitoring and decision-ready reporting.
Resources, asset classification, policies, control design and testing, awareness, suppliers, metrics and program communication.
Readiness, business impact, continuity and recovery alignment, classification, investigation, containment, communication and lessons learned.
Verify ISACA's 3 November 2026 CISM update →
Organizational strategy, roles, culture, policy, resilience, enterprise risk management, risk appetite, frameworks and obligations.
Threats, vulnerabilities, scenarios, business impact, risk registers, analysis methods, and inherent and residual risk.
Treatment, ownership, third-party risk, control design and testing, action plans, KRIs, KCIs, KPIs and stakeholder reporting.
Architecture, operations, SDLC, data lifecycle, resilience, emerging technology, security principles, privacy and risk awareness.
Verify the current CRISC outline with ISACA →
Personal information, privacy principles and obligations, policies, roles, vendor oversight, incidents and data-subject rights.
Privacy risk processes, PIAs, awareness, threats, response, frameworks, evidence, monitoring and metrics.
Inventory, flows, classification, quality, use limitation, analytics, minimization, disclosure, retention and destruction.
Technology stacks, secure development, APIs, cloud, identity, encryption, logging, consent, de-identification, PETs and AI considerations.
Verify the current CDPSE outline with ISACA →
Governance frameworks, structures, strategy alignment, stakeholder engagement, enterprise architecture, policies and information governance.
Sourcing, capacity, acquisition, asset lifecycles, workforce capability and accountable management of contracted services.
Performance oversight, change, monitoring, reporting, quality, business cases, investment governance, metrics and benefit evaluation.
Risk strategy, appetite, tolerance, enterprise risk alignment, assessment, response, monitoring and governance of IT-enabled exposure.
Open a course to review its overview, full curriculum, instructor guidance, FAQs and enquiry options.
Structured ISACA certification training with guided concepts, practical review and exam-readiness support.
Structured ISACA certification training with guided concepts, practical review and exam-readiness support.
Structured ISACA certification training with guided concepts, practical review and exam-readiness support.
Structured ISACA certification training with guided concepts, practical review and exam-readiness support.
Structured ISACA certification training with guided concepts, practical review and exam-readiness support.
Structured ISACA certification training with guided concepts, practical review and exam-readiness support.
Structured ISACA certification training with guided concepts, practical review and exam-readiness support.
Structured ISACA certification training with guided concepts, practical review and exam-readiness support.
Choose CISA for information-systems audit and assurance, CISM for enterprise security management, CRISC for technology risk and controls, CDPSE for engineered privacy solutions, or CGEIT for enterprise IT governance, resources, benefits and risk oversight.
CISM keeps four domains. ISACA changes the weighting from 17/20/33/30 to 18/20/33/29 and refreshes coverage including security strategy, program development and architecture. Use the outline tied to your appointment date.
Yes. ISACA permits candidates to take CISA, CISM, CRISC, CDPSE and CGEIT before completing the applicable certification experience requirements. Certification is a separate step with experience, ethics, application and maintenance requirements.
ISACA currently lists US$575 for members and US$760 for non-members for CISA, CISM, CRISC, CDPSE and CGEIT. Confirm membership, taxes, regional checkout and the final amount directly with ISACA.
No. Each is a free 30-question, 45-minute diagnostic with original learning scenarios and explanations. CDPSE is a focused preview of the 120-question official pattern; the others are focused previews of their current patterns.
No. ISACA controls registration, delivery, experience review, certification and maintenance. ITCertPath provides independent courses, original practice and booking guidance.