CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingA clear breakdown of the five CISA exam domains, their 2024 weightings, what each one actually tests and how to prioritise them in your revision.

The Certified Information Systems Auditor (CISA) exam, run by ISACA, tests five domains: Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%). Those weightings come from the 2024 job practice, effective 1 August 2024, and they determine how ISACA distributes the exam's 150 multiple-choice questions.
More than half of the exam — 52% — sits in the last two domains. That single fact should shape how you divide your revision time, and it is the thread running through this whole breakdown. Below, you will find what each domain covers, why the weightings shifted in 2024, which domain candidates tend to find hardest, and how to convert the five-domain map into a sensible study order.
| # | Domain | Weight | Approx. share of 150 questions* |
|---|---|---|---|
| 1 | Information Systems Auditing Process | 18% | ~27 |
| 2 | Governance and Management of IT | 18% | ~27 |
| 3 | Information Systems Acquisition, Development and Implementation | 12% | ~18 |
| 4 | Information Systems Operations and Business Resilience | 26% | ~39 |
| 5 | Protection of Information Assets | 26% | ~39 |
*Indicative only — the weightings are ISACA's official percentages; the per-question arithmetic is ours, and ISACA does not publish an exact per-domain question count for any individual exam form.
The exam itself runs for four hours (240 minutes), which works out at a little over 90 seconds per question across all five domains. Every question is multiple choice, and every domain is examined on every sitting — there is no optional content and no way to "drop" a weak domain.
If you are using older study notes, check them against the current outline before trusting them. ISACA updated the CISA exam to the 2024 job practice with effect from 1 August 2024. The five domain names stayed the same as the 2019 version, but the weightings moved:
The practical message of the shift: audit process mechanics lost a little ground, while operations and business resilience gained it. ISACA's aligned materials for the current outline are the CISA Review Manual, 28th Edition, the CISA Online Review Course 2024 and the CISA QAE Database 2024. Pre-2024 editions still cover largely the same subject matter, but their practice-question mix will over-represent Domain 1 and under-represent Domain 4 relative to the live exam.
This is the "how auditors work" domain — the profession's core craft. Expect it to examine how an information systems (IS) audit is planned, executed and reported: setting audit objectives, applying a risk-based approach to decide what gets audited first, gathering and evaluating evidence, sampling, documenting findings and communicating results to stakeholders who need to act on them.
Two things make this domain distinctive. First, it is the lens for the entire exam: even questions that live in other domains are usually framed from an auditor's perspective ("what should the IS auditor do FIRST / recommend / conclude?"). Getting fluent in that framing pays off everywhere, not just in Domain 1's 18%. Second, it rewards judgement over recall. Many questions offer four defensible-sounding actions and ask you to rank them the way audit standards would — report to the audit committee or investigate further? Note the finding or stop the engagement? If you come from a hands-on IT background rather than an audit one, this mindset — independence, evidence, materiality, reporting lines — is usually the biggest adjustment.
What actually matters here: risk-based audit planning, evidence quality and sufficiency, the difference between substantive testing and control testing, and knowing who the auditor reports what to, and when.
Domain 2 steps back from the audit engagement and asks whether the organisation is directing and controlling IT properly in the first place. It covers how IT strategy aligns with business strategy, organisational structures and responsibilities (boards, steering committees, ownership of risk), policies and standards, resource and vendor management, performance monitoring and IT risk management as a governance activity.
Candidates from technical roles often underestimate this domain because little of it is technical. The questions probe whether you can distinguish governance (setting direction, evaluating outcomes — a board-level activity) from management (planning, building, running — an executive activity), and whether you know which body or role should own a given decision. When a question asks who should approve the IT strategy or where accountability for a risk sits, the "doer" answer is often the wrong one and the "accountable owner" answer is right.
What actually matters here: governance versus management, roles and accountability, alignment of IT investment with business objectives, and how an auditor evaluates whether governance structures actually function rather than merely exist on paper.
The smallest domain covers how systems come into being: business cases and feasibility, project governance, development methodologies, control design during development, testing regimes, data migration and conversion, and post-implementation review. The auditor's angle is consistent — at each stage of acquiring or building a system, what controls should exist, and how would you verify them?
At 12%, roughly 18 of 150 questions, this is the domain where over-investment costs you elsewhere. It still deserves proper coverage — its material connects naturally to Domain 4 (what happens after go-live) — but if you are triaging limited study hours, Domain 3 is the one that should absorb the cut, not Domains 4 and 5.
What actually matters here: controls at each project stage, why post-implementation reviews exist, the audit risks in data conversion, and the auditor's role in a project (reviewing controls, not designing the system).
Now the exam's centre of gravity. Domain 4 jumped to 26% in the 2024 update, and it covers the day-to-day running of IT: operations management, IT service and incident processes, change and patch management, job scheduling and monitoring, end-user computing, data management — and then the resilience half: business impact analysis, business continuity planning, disaster recovery, backups and restoration testing.
The 2024 weight increase reflects where the profession has moved — auditors are increasingly asked to give assurance over operational resilience, not just financial-system controls. Expect scenario questions: a change went to production without approval, a restore test failed, a business impact analysis is out of date. The exam wants to know what the finding is, how severe it is, and what the auditor should recommend.
Resilience concepts are a reliable source of questions because they have crisp, testable relationships: the difference between a business continuity plan and a disaster recovery plan, how recovery objectives drive backup strategy, and why an untested plan is treated as an unproven one. Learn the relationships between these concepts, not just their definitions in isolation.
What actually matters here: change management as the classic IT general control, incident versus problem management, the business impact analysis as the foundation of continuity planning, and evidence that recovery arrangements are tested rather than assumed.
The joint-largest domain covers information security through an auditor's eyes: security frameworks, policies and awareness; identity and access management; network security; encryption and public key infrastructure concepts; physical and environmental controls; security event monitoring; and responding to attacks and incidents.
Two cautions. First, breadth: Domain 5 spans everything from door locks to cryptography, so it usually has the longest topic list in any review manual and takes longer to cover than its 26% suggests. Second, altitude: the exam does not want a penetration tester's answer. Questions ask what the auditor should conclude about an access-control weakness or which control best mitigates a described exposure — assurance-level thinking, not configuration-level detail. Security specialists sometimes lose marks here by reaching for the deepest technical answer when the question wanted the strongest control principle, such as least privilege or segregation of duties.
What actually matters here: access control principles (least privilege, need-to-know, segregation of duties), the logic of layered defence, what different security technologies achieve at the level an auditor evaluates them, and how security incidents should be detected, escalated and reviewed.
Short answer: there is no officially "hardest" domain — ISACA publishes neither pass rates nor per-domain performance statistics — but difficulty tracks your background. Auditors typically find Domain 5 heaviest because of its technical breadth; IT and security professionals more often struggle with Domains 1 and 2, where the exam's audit-judgement style is most concentrated.
A useful self-diagnosis: read a handful of practice questions from Domain 1 and a handful from Domain 5. If the Domain 1 questions feel like guesswork between four reasonable options, your gap is the audit mindset, and it will affect your accuracy across all five domains, so fix it first. If Domain 5 reads like a foreign language, your gap is technical vocabulary, which is more mechanical to close. Timed practice questions scored by domain will show you which pattern you fit — a topic covered properly in our CISA practice test strategy guide. For a broader view of what trips candidates up and how the 450/800 scaled pass mark works, see how hard the CISA exam really is.
The weightings are a budget, and the simplest planning move is to spend your hours roughly in proportion to them, with two adjustments:
Note that CISA has no per-domain minimum: your pass mark of 450 on the 200–800 scale is calculated across the whole exam, so a strong showing in the heavyweight domains can offset a mediocre one in Domain 3. ISACA does not publish a percent-correct equivalent of 450, so ignore any source that translates it into a fixed percentage.
If you want this converted into an actual timetable, that is deliberately outside this article's scope: our CISA study schedule for working professionals does the week-by-week planning around a full-time job, the beginner study plan sequences the five domains for first-timers, and how long CISA preparation takes covers time estimates by background.
No. The 2024 job practice, effective 1 August 2024, kept the same five domain names as the 2019 version and changed only the weightings — most notably Domain 1 dropping from 21% to 18% and Domain 4 rising from 23% to 26%.
No. The exam produces a single scaled score from 200 to 800, and 450 or above passes. There is no published per-domain minimum, so overall accuracy is what counts — though your score report's domain feedback is valuable diagnosis if you need a retake.
On ISACA's CISA exam content outline pages at isaca.org. This article interprets what each domain emphasises; the outline is the authoritative list of tasks and supporting knowledge, and it is worth reading once in full before you buy any study materials.
The candidate guide lists CISA in seven languages: English, Spanish, Chinese-Simplified, French, German, Korean and Japanese. Confirm availability for your preferred language and location when booking through ISACA.
The five domains reward different muscles: judgement in Domains 1 and 2, process discipline in Domains 3 and 4, technical breadth in Domain 5. Knowing the map is the easy part; the work is finding out which domains are genuinely weak for you rather than which ones merely feel unfamiliar. A quick, honest benchmark is the fastest way to do that — try a set of free CISA sample questions across all five domains before you plan anything, and let the per-domain results, not guesswork, set your priorities. ExamPractice offers free samples for CISA, with fuller question sets and a timed practice-test simulation available to subscribers when you are further along.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading