Exampractice
Cybersecurity

CISA Study Plan for Beginners

A week-by-week CISA study plan built for first-timers with no audit background — what to cover each week across all five domains, and how to know you're ready.

Alexander Novak · 7 min read
Twelve-week study planner with colour-coded blocks for the five CISA domains ending at an exam-day flag

Here is the plan in one line: twelve weeks, five domains in a deliberate order — audit process first, then governance, then the three technical domains — with practice questions from week one and two full mock exams before test day. The rest of this article turns that line into a week-by-week schedule you can start on Monday, written for people preparing for the Certified Information Systems Auditor (CISA) exam without an audit background.

Two ground rules before the calendar. First, the CISA exam — set by ISACA — is 150 multiple-choice questions in four hours, scored on a 200–800 scale with 450 needed to pass, and you can sit it with zero professional experience (experience is only required for certification afterwards, and you get five years post-pass to earn it). Beginners are not gate-crashing; the exam is built to be sat before or during your qualifying years. Second, this article gives you the schedule — if you first want to calibrate how many total weeks suit your background and free hours, How Long Does CISA Preparation Take? handles that question, and if you're studying around a demanding full-time job, the study schedule for working professionals adapts this structure to tighter evenings.

Why this plan orders the domains the way it does

The 2024 CISA exam content outline weights the five domains like this:

DomainTitleWeight
1Information Systems Auditing Process18%
2Governance and Management of IT18%
3Information Systems Acquisition, Development and Implementation12%
4Information Systems Operations and Business Resilience26%
5Protection of Information Assets26%

A naive plan would start with the heaviest domains. This one deliberately does not, for a reason specific to beginners: Domains 4 and 5 are worth the most marks, but Domain 1 teaches you how an auditor thinks — evidence, risk-based planning, control testing — and every other domain's questions are asked from that mindset. Candidates without audit experience who skip ahead find themselves knowing facts but picking wrong answers, because CISA questions reward the auditor's response, not the technician's. So: mindset first, marks second. (A fuller tour of what each domain contains lives in CISA Exam Domains Explained — one click if you want the syllabus detail this plan compresses.)

The plan assumes roughly 10–12 hours of study per week. ISACA publishes no official study-hours requirement, so treat that as working guidance, not a guarantee — stretch any week that refuses to be finished.

The 12-week schedule

Phase 1 — Learn to think like an auditor (weeks 1–3)

Week 1 — Orientation and Domain 1, part one. Register your intent properly: read ISACA's official exam content outline (free on isaca.org) end to end, set up your study materials, and begin Domain 1 — audit standards, risk-based audit planning, and types of controls. Finish the week by attempting 20–30 practice questions on what you covered, open-book if needed. From day one, questions are how you study, not how you finish.

Week 2 — Domain 1, part two. Evidence collection, sampling, control testing, communicating findings and follow-up. As a beginner, build yourself a one-page "auditor's reflexes" sheet this week: management owns risk decisions; auditors recommend rather than implement; evidence beats assertion; independence is non-negotiable. A surprising share of exam questions are settled by those four reflexes alone.

Week 3 — Domain 2. Governance and management of IT: strategy, policies, organisational structures, resource and vendor management, performance monitoring. This domain is wordy but intuitive — it is about who decides what in an organisation. Close the phase with a 50-question timed quiz mixing Domains 1 and 2, and log every wrong answer in an error journal with one line on why the credited answer wins.

Phase 2 — The technical core (weeks 4–8)

Week 4 — Domain 3. Systems acquisition, development and implementation: project governance, development methodologies, testing and go-live controls. At 12% it is the lightest domain — one focused week is proportionate. Beginners from non-IT backgrounds should slow down on testing types and change control; these recur in Domain 4 questions too.

Weeks 5–6 — Domain 4, in two halves. Operations first (IT service management, job scheduling, incident and problem management, end-user computing), then resilience (backups, disaster recovery, business continuity, recovery objectives). This is one of the two heavyweight domains at 26%, and it rewards concrete mental models — sketch a data centre's day in your notebook and attach controls to it. End week 6 with a 75-question timed set across Domains 1–4.

Weeks 7–8 — Domain 5, in two halves. The other 26% domain: information asset security. Week 7 covers frameworks, identity and access management, and physical/environmental controls; week 8 covers network security, encryption, security testing and incident response. Non-security beginners should expect this fortnight to be the steepest of the plan — protect it fiercely and borrow hours from lighter weeks if needed.

End of week 8 — checkpoint. You have now seen all five domains once. Take stock against this readiness checklist before entering the final phase:

  • [ ] Error journal running, with wrong answers explained in your own words
  • [ ] Scoring comfortably above half on mixed timed sets (an internal yardstick only — the real exam is scaled, and no percentage converts officially to the 450 pass mark)
  • [ ] Auditor's-reflexes sheet internalised — you can predict the "ISACA answer" even when you'd personally act differently
  • [ ] Exam booked, or booking date in the diary

On that last point: ISACA registration is continuous year-round, you get a six-month eligibility window from registration, and appointments (at PSI test centres or via remote proctoring) can be booked up to 90 days ahead. Booking around week 8 for a date four weeks out converts your plan's deadline from theoretical to real. The fee — US$575 for ISACA members, US$760 for non-members, as of 2026 — is non-refundable, so confirm current terms on isaca.org when you book.

Phase 3 — Integration and rehearsal (weeks 9–12)

Week 9 — First full mock. Sit a complete 150-question, four-hour practice exam under real conditions: one sitting, timed, no notes. The score matters less than the diagnosis — sort your errors by domain and by cause (knowledge gap vs misread question vs technician-brain answer). Spend the rest of the week reworking your two weakest domains from the error journal outwards. If you want a deeper method for sequencing and scoring these rehearsals, the CISA practice test strategy article is the specialist resource.

Week 10 — Targeted repair. No new material. Revisit the topics your mock exposed, redo the questions you got wrong two weeks ago (cold, not from memory of the answer letter), and drill your weakest domain with fresh question sets. This is the week ExamPractice fits naturally into the plan: the free CISA practice questions let you sample per-domain sets, and subscribers can run the timed simulation mode for full rehearsals.

Week 11 — Second full mock, plus pacing work. Another 150-question sitting. This time, watch the clock discipline: four hours for 150 questions allows about 96 seconds each, and beginners' most common mock failure is burning five minutes on scenario questions early. Practise the flag-and-return habit — answer, flag if unsure, keep moving. Between mock and review, skim every domain's summary notes once.

Week 12 — Taper. Light review only: error journal, reflexes sheet, domain summaries. No new question sets after midweek — late cramming trades calm for marginal facts, and calm is worth more in a four-hour exam. Confirm your appointment details and ID; the practical run-through of check-in rules, permitted breaks and test-centre logistics is covered in the CISA exam day checklist, which is your assigned reading for the final weekend. You'll see a preliminary pass/fail on screen at the end, with the official score following within ten working days.

Three beginner mistakes this plan is designed to prevent

  1. Reading before questioning. Beginners often plan "finish the manual, then start questions". By then, weeks of misunderstanding have set like concrete. This plan puts questions in every week precisely so errors surface while they are cheap.
  2. Studying the technology instead of the audit of it. Domain 5 does not want you to configure a firewall; it wants you to evaluate whether firewall management is controlled. Whenever a study session drifts into how-to depth, pull back to what would I check, and what evidence would satisfy me?
  3. Treating the weights as a study-time formula. 12% Domain 3 does not mean 12% effort for someone who has never seen a development lifecycle. Weights set the exam's priorities; your unfamiliarity sets yours. The plan's fixed order with flexible hours is the compromise that works.

Adapting the plan when life doesn't cooperate

Running behind by week 5? Extend to fourteen or sixteen weeks by giving Domains 4 and 5 a full fortnight-and-a-half each rather than compressing Phase 3 — the mock-and-repair weeks are the plan's engine and should be cut last. Ahead of schedule? Do not shorten the taper; add a third mock in week 11 instead. And if you fall seriously behind after booking, ISACA lets you reschedule free of charge within your eligibility period provided you do it at least 48 hours before the appointment — a better move than sitting underprepared, since retakes cost the full fee again.

Your first study session

Plans fail at the first session, not the twelfth week — so make the opening move small and concrete. Today: download the official CISA exam content outline from isaca.org, block your 10–12 weekly hours in your calendar as recurring appointments, and attempt ten practice questions cold to feel the question style you are training for. Twelve weeks from that unglamorous half-hour, you walk into a four-hour exam knowing exactly why every week of this plan was shaped the way it was.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like