The 5 CISA Domains Explained (With Official Weights)

The 5 CISA domains and their official exam weights: 18, 18, 12, 26, and 26 percent

The CISA exam has five domains. In weight order: Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development, and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%). Those weights come from the ISACA Exam Content Outline effective August 2024, which is the current version and is expected to stay stable for several years.

The number that should shape your study plan: Domains 4 and 5 are 26% each, 52% of the exam combined. Domain 3 is the smallest at 12%. Over a 150-question exam, Domain 3 is worth about 18 questions while Domains 4 and 5 are worth about 78 between them. This post walks through what each domain actually covers, what the exam rewards in each one, and where your hours are best spent.

What are the CISA domain weights?

Domain Name Weight
1 Information Systems Auditing Process 18%
2 Governance and Management of IT 18%
3 Information Systems Acquisition, Development, and Implementation 12%
4 Information Systems Operations and Business Resilience 26%
5 Protection of Information Assets 26%

The exam itself is 150 multiple-choice questions in 4 hours, scored on a scale of 200 to 800 with 450 to pass. If you want the full picture of format, fees, and eligibility, start with what the CISA exam is and come back.

One framing point before the domain-by-domain tour. CISA is a technical exam tested from the auditor's seat. You are never the person who builds the firewall or writes the recovery plan. You are the person who evaluates whether those things exist, work, and can be evidenced. That lens decides more answers than any single fact.

Domain 1: Information Systems Auditing Process (18%)

Domain 1 is the craft of auditing itself, in two halves. The planning half (sub-area 1A) covers IS audit standards, guidelines, and the code of ethics, the types of audits and reviews, risk-based audit planning, and the taxonomy of controls: preventive, detective, corrective, general versus application. The execution half (1B) covers audit project management, testing and sampling methodology, evidence collection techniques, data analytics, reporting and communication, and quality assurance of the audit function.

What the exam rewards here is independence and evidence discipline. When a question pits being helpful against staying objective, the auditor preserves independence every time; you cannot advise on a control you will later audit. Questions also test whether you know that an opinion rests on sufficient, appropriate evidence, and that a finding is built from criteria, condition, cause, and effect before anyone proposes a fix.

Study implication: learn the auditor's rules of engagement cold, because Domain 1 thinking leaks into every other domain's questions.

Domain 2: Governance and Management of IT (18%)

Domain 2 asks whether IT is pointed in the right direction and run accountably. The governance side (2A) covers laws, regulations, and standards, organizational structure and IT strategy, the policy hierarchy, enterprise architecture, enterprise risk management, the privacy program, and data governance and classification. The management side (2B) covers IT resource management, vendor management, performance monitoring and reporting, and quality assurance and quality management of IT.

The exam rewards a clean split between governance and management. Governance sets direction and accountability at the board level; management executes at the operational level. A large share of Domain 2 questions are really "who is responsible" questions, and mapping the stem to that split usually settles them. The other trap: a policy existing is not the control. The auditor tests whether it is communicated, implemented, and enforced.

Study implication: memorize the governance-versus-management split and the three lines model, then practice "who is responsible" stems until the mapping is automatic.

Domain 3: Information Systems Acquisition, Development, and Implementation (12%)

Domain 3 is the system life cycle. The acquisition and development half (3A) covers project governance and management, the business case and feasibility analysis, development methodologies from waterfall to Agile and DevOps, and control identification and design. The implementation half (3B) covers readiness and testing, configuration and release management, migration and data conversion including cutover strategies, and the post-implementation review.

What the exam rewards is knowing where in the life cycle a control belongs and preferring the earliest option. Controls are cheapest and strongest when designed in at requirements, so watch for "earliest stage" qualifiers. Segregation questions show up here too: developers with production access, or live production data used in test without masking, are reliable wrong-environment red flags.

Study implication: this is the smallest weight on the exam, and the worst place to spend your first study week; cover it properly, once, later in your plan.

Domain 4: Information Systems Operations and Business Resilience (26%)

Domain 4 is one of the two heavyweights, and it is really two subjects. The operations half (4A) is the daily running of IT: asset management, job scheduling, system interfaces, shadow IT and end-user computing, availability and capacity, problem and incident management, change, configuration, and patch management, log management, service level management, and database management. The resilience half (4B, plus the business resilience piece of 4A) is what happens when things break: the business impact analysis, data backup, storage, and restoration, the business continuity plan, and the disaster recovery plan.

The exam rewards precise operational definitions. An incident restores service fast; a problem removes the root cause; if the stem stresses preventing recurrence, the answer is problem management. On the resilience side, the BIA drives everything: RTO is how long you can be down, RPO is how much data you can lose, and recovery spending must match those objectives. And a backup job that reported success proves nothing. The only proof is a tested restoration, and auditors look for evidence of restore tests.

Study implication: at 26%, this domain deserves a full quarter of your study time, with the BCP/DRP material drilled until the recovery-objective vocabulary is reflexive.

Domain 5: Protection of Information Assets (26%)

Domain 5 is the security heavyweight, matching Domain 4 at 26%. The security-and-control half (5A) covers security policies and frameworks, physical and environmental controls, identity and access management, network and endpoint security, data loss prevention, encryption, PKI, cloud and virtualized environments, and mobile, wireless, and IoT devices. The event-management half (5B) covers security awareness training, attack methods, security testing, security monitoring, incident response, and evidence collection and forensics.

The exam rewards evaluating protection, never engineering it. Authentication proves who you are; authorization decides what you may do; access reviews and prompt deprovisioning are the controls organizations run weakest, so they are frequent answers. Encryption is only as good as its key management. And in incident response, containment comes before eradication, with evidence preserved before you remediate when forensics may matter.

Study implication: give this domain the other full quarter of your time, and study it as an assessor of controls, not a builder of them, even if security engineering is your day job.

Which CISA domains should you study most?

Follow the weights. Domains 4 and 5 are 52% of the exam between them, so about half your preparation should live there. Domains 1 and 2 share the next 36%, and Domain 3 gets what remains. Spending equal time per domain is the most common self-inflicted wound in CISA prep, because it quietly overweights the 12% domain and starves the two 26% ones.

Weights also compound with difficulty. Domains 4 and 5 carry the most technical detail tested through the auditor's lens, which is an awkward combination if you come from either a pure audit or a pure engineering background. One group knows the lens but not the technology; the other knows the technology but answers like a builder. Both need the most reps where the exam puts the most questions. A week-by-week CISA study plan can allocate those hours for you, and if you are gauging the overall challenge first, see how hard the CISA exam is.

This post is the map, not the territory. A deep-dive on each of the five domains is coming next in this series. For everything in one place now, the ISACA CISA Study Guide teaches all five domains in plain English with chapter space allocated to the same 18/18/12/26/26 weights the exam uses.

Do the CISA domain weights change?

Not often. The current Exam Content Outline took effect in August 2024, kept the five-domain structure, and has no announced change; ISACA refreshes its job practices roughly every three to five years. If you are studying in 2026, the 18/18/12/26/26 weights are the ones you will see. Always confirm the current outline on ISACA's site before booking, since the outline is the exam's contract with you.

FAQ

How many CISA domains are there?

Five: Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development, and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. The weights are 18%, 18%, 12%, 26%, and 26% under the outline effective August 2024.

Which CISA domain is the hardest?

It depends on your background, but Domains 4 and 5 give most candidates the most trouble. They carry the deepest technical content, and the exam tests it from the auditor's evaluation seat rather than the engineer's build seat. They are also the heaviest weighted, so weakness there costs the most.

Which CISA domain has the fewest questions?

Domain 3, at 12% of the exam. On a 150-question exam that works out to the smallest share of items, roughly half the count of Domain 4 or Domain 5.

Are the domain weights the same in every CISA exam?

Yes. Every form of the exam is built to the same content outline, so the 18/18/12/26/26 distribution holds regardless of when or where you test. Individual questions differ between forms; the blueprint does not.

Do I need to pass each domain separately?

No. CISA is scored as a single scaled result from 200 to 800, and 450 passes. There is no per-domain minimum, which is exactly why weighting your study toward the 26% domains is rational: points are points, wherever they come from.


Looking for a plain-English CISA guide? ISACA CISA: Certified Information Systems Auditor Study Guide covers all five domains with four full-length practice exams, every answer explained.

Simply Certified is an independent publisher. CISA and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.