ISACA study plan
CISA study plan
A step-by-step CISA study plan: the exact order to study in, how long to spend on each stage, and when to start practice questions. Follow it top to bottom.
The real CISA is 150 questions in 240 minutes, pass mark 450 / 800. For the full domain-by-domain breakdown behind each stage, read the CISA study guide.
Your step-by-step plan
Map the blueprint and book a date
Day 1Read the official ISACA exam content outline and the five domains with their weights. Book a provisional date now: a fixed date converts open-ended study into a plan and is the strongest predictor of actually sitting. Note that Operations and Business Resilience (26 percent) and Protection of Information Assets (26 percent) are just over half the exam between them.
Adopt the auditor's mindset
Week 1Before any content, drill the one habit the exam is built around: answer as an auditor who evaluates and reports, never as the engineer who fixes. Practise reading a scenario and asking what an independent auditor would do FIRST, and watch for the qualifier (BEST, MOST, PRIMARY). If you cannot say why the fix-it option is wrong, you are not yet thinking the way CISA scores.
Lock the audit process (Domain 1)
Weeks 1 to 2Get the audit lifecycle, the standards hierarchy, the evidence hierarchy, and compliance versus substantive testing exact, because every other domain assumes them. Use the recall checks in this guide: cover the summary, answer from memory, then reveal. If you cannot state a concept in one sentence, you do not own it yet.
Go deep on the two heavy domains (Domains 4 and 5)
Weeks 2 to 4Operations and Resilience and Protection of Information Assets are just over half the exam, so they get the most time. Anchor resilience to RTO and RPO and the BIA, and study every security control for its objective and how you would audit it, not how you would configure it. Practise on scenario questions and read the worked explanation on every one, including the ones you got right.
Cover governance and the build lifecycle (Domains 2 and 3)
Weeks 4 to 5Governance rewards the governance-versus-management split and the outsource-the-activity-not-the-accountability rule; the acquisition domain rewards knowing where application controls live and why building them in early beats retrofitting. Both are learnable, reliable marks once you stop reading them as technology.
Drill weak domains, then space the review
Week 5Use your per-domain accuracy to attack the two domains dragging you down, not to re-read what you already know. Then space it: revisit each domain's recall prompts after a few days and again a week later. Spacing roughly doubles what sticks compared with cramming.
Sit a timed mock and calibrate
Weeks 6 to 7Take at least one full 240-minute, 150-question mock under exam conditions to rehearse pacing and the flag-and-return habit. Treat the score as a per-domain readiness signal, not a single number, and review every missed question, checking that you missed it on knowledge and not on forgetting to answer as an auditor.
Ready to start stage one?
Free CISA questions with worked explanations. No sign-up.
Frequently asked questions
How long does this CISA study plan take?
It is 7 stages, paced by how much time you can give it each week - most candidates work through it in 2 to 6 weeks. Each stage below has a suggested duration; slow down on any stage where the recall checks in the study guide are not landing before moving on.
What order should I study CISA in?
Follow the stages in order below. They are sequenced deliberately: foundational material first, then the domains weighted heaviest on the exam, then timed practice, with review passes built in rather than left to the end.
Do I need practice questions as part of this plan?
Yes. Reading alone does not surface what you have not actually learned. This plan builds in graded practice, and the full 293-question bank is free to use as you work through each stage.
Is this plan enough on its own, or do I need the full study guide too?
This page is the plan: what to do and in what order. The study guide adds the domain-by-domain breakdown, easy-to-confuse traps, and worked examples behind each stage - read it alongside this plan, not instead of it.
Examworthy is not affiliated with or endorsed by ISACA. This study plan is original material based on the public exam blueprint. We never reproduce live exam items. CISA and related marks belong to their respective owners.