Home/Certifications/ISACA

7 titles • 2026 to 2027 editions

The ISACA certification series

ISACA study guides,
simply explained.

Seven credentials, from CISA and CISM through to the new AI audit and AI security certifications. Every domain mapped to the official job practice areas in plain English.

One scale: 200 to 800, pass at 450Scenario questions that test the professional's judgment, not the engineer's fix
27 domains across 7 titlesMapped to the official ISACA outlines
2,392 practice questionsPrinted in the book with the answer key

Choose your path

7 guides, one series

ISACA writes exams for roles rather than tools: the auditor, the security manager, the risk professional, the governance lead. Start from the seat you hold or want.

600 questions ISACA CISA study guide, 2026 edition Audit • 5 years
ISACA · CISA

Certified Information Systems Auditor

The IS auditor's credential. The audit life cycle, IS controls, governance and business resilience, tested through the auditor's judgment.

  • 5 domains
  • 4 h
  • 513 pages

Official weights · current outline

Most popular ISACA CISM study guide, 2026 edition Management • 5 years
ISACA · CISM

Certified Information Security Manager

For the security manager: governance, risk, program development and incident management from the manager's seat, not the analyst's.

  • 4 domains
  • 4 h
  • 443 pages

Official weights · current outline

ISACA CGEIT study guide, 2026 edition Governance • 5 years
ISACA · CGEIT

Certified in the Governance of Enterprise IT

Enterprise governance of IT at board and executive level: value delivery, resource optimisation and benefits realisation.

  • 4 domains
  • 216 pages

Official weights · current outline

ISACA CDPSE study guide, 2026 edition Privacy • 3 years
ISACA · CDPSE

Certified Data Privacy Solutions Engineer

The technical privacy credential: privacy architecture, data lifecycle and privacy by design, implemented rather than recited.

  • 4 domains
  • 3.5 h
  • 263 pages

Official weights · outline 2 June 2025

ISACA AAIA study guide, 2026 edition AI audit • holds CISA or equivalent
ISACA · AAIA

Advanced in AI Audit

Extends the auditor's toolkit to AI systems: AI governance, risk and controls, and auditing AI itself.

  • 3 domains
  • 2.5 h
  • 225 pages

Official weights · current outline

ISACA AAISM study guide, 2026 edition AI security • holds CISM or equivalent
ISACA · AAISM

Advanced in AI Security Management

AI security management for people who already hold a security credential: threats, governance and program design for AI.

  • 3 domains
  • 249 pages

Official weights · current outline

What is included

Every ISACA guide is built the same way

The books differ in length and in how practice is arranged, because the exams differ. Everything else is the same in all 7.

01

A section per objective

Chapters follow the certifying body's own outline, and each area gets its own section with a scoping paragraph, the explanation and Key Takeaways.

CISA 5 · CISM 4 · CRISC 4 · CGEIT 4 · CDPSE 4
02

Tips and pitfalls

Callouts sit beside the concept they belong to, flagging the distinctions the exam tests and the answers that look right under time pressure.

Throughout every chapter
03?

Practice in the book

Questions are printed with the answer key in the same volume, written in the exam's own style and tagged to the domain they came from.

2,392 questions across 7 titles
04

An exam overview

Delivery, scoring and the published domain weights, then a domain-weighted study plan for where the remaining hours should go.

Front matter, every title

Look inside

A real page, and how it works

This is page 109 of the CGEIT guide. Every section in every ISACA title is built from the same parts. Select a marker to see what each one does.

Page 109 of the Simply Certified CGEIT study guide, showing an Exam Tip, a Common Pitfall and Key Takeaways
CGEIT Study Guide, 2026 to 2027 edition · page 109

Marker 1 · The section heading

Every section opens the same way

The heading on this page is Benefits Realization Versus Benefits Forecasting. Sections follow the certifying body's own outline, so the table of contents doubles as the exam blueprint, and each one is self-contained enough to study alone.

Straight out of the book

One real question from each title

Printed here exactly as they appear in the practice sets. Nothing has been simplified for the website.

ISACA CISAInformation Systems Acquisition, Development and Implementat practice-exams-final

An organization is establishing a steering committee to oversee the implementation of a new enterprise resource planning (ERP) system using an agile project management methodology. What is the MOST important criterion for selecting steering committee members?

  1. The members hold senior management positions within the organization.
  2. The members have the capacity to meet the time commitment that the agile approach requires.
  3. The members have prior experience with agile project management methodologies.
  4. The members have prior experience with ERP system implementations.
Show the answer

Correct answer: C

Agile project management involves iterative delivery cycles, frequent sprint reviews, continuous backlog refinement, and adaptive planning, all of which require active and informed steering committee engagement at each iteration. If committee members lack agile experience, they may apply waterfall-oriented oversight expectations that conflict with agile principles, undermining project governance. Agile methodology experience is therefore the most critical criterion for the committee's composition when agile is the chosen approach.

  • ASenior management representation is important for decision-making authority but does not ensure that members understand the governance demands of an agile delivery model.
  • BAvailability to meet the time commitment is a prerequisite for any committee member but is a general requirement rather than a distinguishing criterion specific to the agile context of this project.
  • DERP implementation experience is valuable but secondary; members who understand ERP but not agile may impose inappropriate oversight structures that undermine the project's chosen methodology.

The CISA guide explains every answer.

Side by side

The ISACA exams, compared

Exam facts come from each book's own exam overview. Book facts come from the printed interior. A dash means the book does not state it.

ComparisonCISACISMCRISCCGEITCDPSEAAIAAAISM
FocusAuditManagementRiskGovernancePrivacy engineeringAI auditAI security
Experience5 years5 years3 years5 years3 yearsHolds CISA or equivalentHolds CISM or equivalent
Domains5444433
Questions1501501501501209090
Time limit4 h4 h4 h3.5 h2.5 h
Pass mark450450450450450Scaled; ISACA does
Practice in the book600 in 4 mocks444 in 3 mocks600 in 4 mocks150 in 1 mock238 in 2 mocks180 in 2 mocks180 in 2 mocks
Pages513443471216263225249
Price$20.99$20.99$20.99$20.99$20.99$20.99$20.99

Why Simply Certified

Simply Certified is a study guide series for working professionals who need to certify efficiently, without a two-thousand-page reference. Chapters and practice questions are both mapped to the certifying body's published exam objectives, so your practice results point directly to the domains that need more work.

Questions

Before you choose

Which ISACA certification should I start with?
Match the credential to the seat. CISA is the auditor's certification, CISM the security manager's, CRISC the risk professional's, CGEIT the governance lead's, and CDPSE the privacy engineer's. AAIA and AAISM are advanced credentials that extend an existing audit or security qualification into AI. All seven expect professional experience; check ISACA's current requirements for your credential.
How are ISACA exams scored?
Every ISACA exam here reports a scaled score from 200 to 800 with a pass mark of 450. The scale is not a percentage: the raw number of correct answers needed varies slightly across exam forms. Questions are scenario-based and lean on BEST, MOST and FIRST framing, where more than one answer is defensible and the keyed answer is the one the professional in that seat would choose first.
Are these official ISACA study guides?
No. Simply Certified is an independent publisher. These are independent study materials written to the certifying body's published exam outlines. They are not affiliated with, endorsed by, or sponsored by ISACA.
Do the books include practice questions, or is that a separate purchase?
Practice is printed in the same volume, with the answer key. There is no separate question pack and no online access code.
What do the printed books look like?
All 7 are 8.5 by 11 inch paperbacks, perfect bound, printed black and white on white paper by Aced It Publications.