Certified Information Systems Auditor

Why Trust Techopedia

What Does Certified Information Systems Auditor Mean?

Certified Information Systems Auditor (CISA) is a certification issued by ISACA that validates an auditor’s ability to assess risk, institute information technology access and management controls, execute security audits and report on compliance.

Advertisements

The exam for this certification covers the following topics in regards to information and communication (ICT) systems:

Acquisition, development, testing and implementation
This part of the exam tests the candidate’s knowledge of feasibility studies, business cases, total cost of ownership (TCO), return on investment (ROI) and software development project management.

Operations, maintenance & service management
This part of the exam tests the candidate’s knowledge of service management best practices, enterprise architecture, systems resiliency, information lifecycle management (ILM), IT controls and performance monitoring.

IT Governance
This part of the exam tests the candidate’s knowledge of enterprise risk management (ERM), specific IT governance frameworks, quality assurance (QA), performance scorecards and other topics related to business continuity and disaster recovery (BCDR).

Asset protection
This part of the exam tests the candidate’s knowledge of privacy laws and regulations, risk management, digital forensics, data handling and best practices for physical and environmental security controls including digital signatures and encryption.

Auditing
This part of the exam tests the candidate’s knowledge of auditing tools and best practices, as well as the candidate’s knowledge of laws and regulations that pertain to an organization’s business processes.

Techopedia Explains Certified Information Systems Auditor

CISA is an advanced certification from ISACA that is intended for information technology professionals who are interested in advancing their career as an internal or consulting IT auditor. This certification fulfills the United States Department of Defense’s Information Assurance Technical Level III and Cyber Security Service Provider (CSSP) Auditor requirements.

Like ISACA’s exams for CISSP and CISM, CISA exams are four hours long and consists of 150 multiple-choice questions. A score of 450 or higher (scored on a scale of 200 to 800) is required to pass the exam. Successful candidates must agree to adhere to ISACA’s Information Systems Auditing Standards, Continuing Professional Education (CPE) Policy and Code of Professional Ethics.

Advertisements

Related Terms

Margaret Rouse
Technology expert
Margaret Rouse
Technology expert

Margaret is an award-winning writer and educator known for her ability to explain complex technical topics to a non-technical business audience. Over the past twenty years, her IT definitions have been published by Que in an encyclopedia of technology terms and cited in articles in the New York Times, Time Magazine, USA Today, ZDNet, PC Magazine, and Discovery Magazine. She joined Techopedia in 2011. Margaret’s idea of ​​a fun day is to help IT and business professionals to learn to speak each other’s highly specialized languages.