CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingMap the CISA career path from junior IT auditor to audit leadership, GRC and beyond — the roles, the timelines and the branch points that matter.

The Certified Information Systems Auditor (CISA) career path typically runs from junior IT audit or IT operations work, through qualified IT auditor and senior auditor roles, and then branches: towards audit management, towards governance, risk and compliance (GRC), or sideways into security and risk roles that prize audit literacy. CISA, awarded by ISACA, is the credential that anchors the audit-shaped version of that journey — this article maps each stage, what you actually do in it, and the decision points where careers fork.
One boundary note before we start: this piece is about roles and progression. If you want pay figures for these roles, the CISA Salary Guide owns the numbers, and if you are still deciding whether to pursue the certification at all, Is CISA Worth It? delivers that verdict.
CISA certifies your ability to audit, control and assure information systems — checking that an organisation's technology genuinely does what management, regulators and customers assume it does. That maps to a family of jobs rather than a single title: IT auditor, IS auditor, technology risk analyst, IT compliance analyst, internal auditor with a systems focus, and the consulting equivalents of all of these.
The certification's structure tells you what employers expect a holder to handle. The 2024 CISA exam content outline covers five domains: the information systems auditing process (18%), governance and management of IT (18%), information systems acquisition, development and implementation (12%), information systems operations and business resilience (26%), and protection of information assets (26%). Read that as a job description: a CISA-calibre professional can plan and run an audit, judge whether IT is governed sensibly, assess systems as they are built and as they run, and evaluate how well information is protected. Every role on the path below draws on some blend of those five.
It is worth knowing how the credential itself is earned, because it shapes when the letters appear on your CV. You can sit the 150-question exam with no experience at all, but certification requires a minimum of five years of professional IS/IT audit, control, assurance or security experience (waivers can cover up to three years, and you have five years after passing to apply). In practice, many people pass the exam mid-career-stage and become certified a year or two later — the path below assumes exactly that pattern.
Almost nobody's first job title is "IT auditor with CISA". The pipeline draws from three feeder routes:
At this stage your work is execution: testing access controls, walking through change-management processes, gathering evidence, documenting findings under supervision. This is also when many people pass the CISA exam, banking it while their experience clock runs.
A realistic composite: a systems administrator with two years of experience joins an internal audit team as an IT audit analyst. Her sysadmin background makes her faster than her peers at Domain 4 territory — operations, backups, resilience — while the audit methodology of Domain 1 is what she has to learn on the job. Eighteen months in, she passes the exam; certification follows once her qualifying experience (with waivers for her earlier IT work) adds up.
This is the stage the certification is squarely aimed at. As a certified (or nearly certified) IT auditor you begin to own audits rather than tasks on audits: scoping, planning the testing approach, running client or stakeholder meetings, drafting reports that an audit committee might actually read. You develop specialisms — application controls, cloud environments, ERP systems, IT general controls for financial reporting — and those specialisms start steering which branch you take later.
The market for this stage is broad. ISACA reports more than 151,000 CISA holders worldwide (as of August 2026), and the roles span internal audit functions in banks, insurers, retailers and public bodies; external audit and advisory at professional-services firms; and regulators and audit institutions themselves.
Seniority in audit means judgement and supervision. Senior auditors decide what is material, defend findings when management pushes back, coach juniors, and manage the relationship between the audit plan and the organisation's actual risk picture. Titles at this level include senior IT auditor, IT audit lead, technology audit supervisor and, in consulting, manager.
This is also the classic branch point. Around this stage, most CISA holders choose one of three directions — up, across, or out — covered in the next three sections.
The vertical route continues into IT audit manager, senior audit manager, head of IT audit and, ultimately, chief audit executive (CAE) or audit director. The work becomes portfolio-shaped: setting the audit universe, negotiating resources, reporting to the audit committee, and owning the function's methodology and talent pipeline. At CAE level the "IT" prefix often falls away — you are running assurance for the whole organisation, and your systems-audit background is a differentiator rather than the job itself. Professionals heading this way often pair CISA with a general internal-audit credential such as the IIA's Certified Internal Auditor; if that route interests you, the CIA Part 1 exam overview shows what that qualification tests.
Governance, risk and compliance teams sit on the other side of the table from audit — designing and running the controls auditors test. CISA transfers well because Domains 2 and 4 are essentially the GRC playbook viewed from the assurance angle. Typical titles: GRC analyst, IT risk analyst, IT compliance manager, controls assurance manager, technology risk manager. People often make this move because they want to build rather than inspect, and because second-line roles exist in far more organisations than dedicated IT audit teams do. For those who settle into risk as the career rather than a stop, ISACA's Certified in Risk and Information Systems Control (CRISC) is the natural companion credential — the CRISC Certification Guide explains what it covers.
Plenty of CISA holders migrate into security: security compliance, security assurance, third-party risk, and eventually security management. The audit skill set — evidence, control frameworks, structured scepticism — is genuinely scarce inside security teams. The management end of this branch is where ISACA's Certified Information Security Manager (CISM) lives; the two credentials target different roles rather than forming a sequence, and CISA vs CISM untangles that choice in one sentence more than we will here.
Advisory work — IT audit co-sourcing, controls transformation, pre-audit readiness, due diligence on acquisitions — rewards CISA holders who like variety and client work. Progression follows the consulting ladder (consultant, manager, senior manager, director, partner) rather than the internal-audit one, and tends to move faster for those comfortable with sales and travel.
A newer branch is opening on top of CISA itself. ISACA's Advanced in AI Audit (AAIA) credential, launched in May 2025, is an add-on for which all CISA holders qualify, covering AI governance and risk, AI operations, and AI auditing tools and techniques. The demand signal behind it is loud: in ISACA's 2025 research, 85% of digital trust professionals said they will need to increase their AI skills within two years. For an IT auditor deciding where to specialise next, auditing AI systems is currently the least crowded room.
When you reach the senior-auditor fork, four questions do most of the work:
Yes, in the sense that anyone may sit the exam — no experience is required to test, and you then have five years to accumulate the qualifying experience and apply for certification. The practical entry, though, still runs through a feeder role: internal audit, IT operations or a graduate risk scheme. Passing the exam first signals commitment to hiring managers in those pipelines.
No. The branch routes above — GRC, security assurance, consulting, AI audit — are populated heavily by former auditors, and audit literacy is the transferable asset. Many holders spend three to six years in audit proper and the rest of their careers adjacent to it.
Yes. Regulated industries (banking, insurance, healthcare) hire the most, but any organisation with an internal audit function, significant compliance obligations or external-audit scrutiny of its systems has work for the skill set — including public sector bodies and the technology firms being audited.
Volunteer for the audits nobody understands yet — cloud migrations, AI systems, new ERP implementations. Scarcity of understanding, not tenure, is what pulls people up this particular ladder.
Map yourself onto the stages honestly: feeder, qualified auditor, senior, or branch point. If you are pre-pipeline, your next move is a feeder role plus the exam; if you are at the fork, the decision framework above matters more than any additional credential. And if you are preparing to sit the exam itself, test your readiness against the real domain structure — the free CISA practice questions on ExamPractice let you sample how the five domains are actually examined before you commit study months to the climb.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading