5-Month CISA Study Schedule Template
A comprehensive 5-month CISA study plan designed for working professionals who prefer a steady, manageable preparation pace.
Why Choose a 5-Month Timeline?
A five-month study schedule is well-suited for working professionals who want to prepare thoroughly without overwhelming their daily routines. This plan requires approximately 7 to 10 hours of study per week, making it sustainable alongside full-time employment and personal commitments. The extended timeline allows deeper exploration of each domain and more opportunities for spaced repetition.
Month 1: Domain 1, Information Systems Auditing Process
Spend the entire first month on the audit process domain. This foundational knowledge informs how you approach every other domain on the exam. Cover audit planning, execution, reporting, and follow-up activities in detail.
- Week 1: Audit standards, guidelines, and codes of ethics
- Week 2: Risk-based audit planning and audit objectives
- Week 3: Audit execution, evidence gathering, and sampling
- Week 4: Audit reporting, follow-up, and quality assurance
Month 2: Domain 2, Governance and Management of IT
Dedicate the second month to IT governance. Study organizational structures, policies, and the alignment of IT strategy with business objectives. Understand how governance frameworks guide decision-making and resource allocation within IT departments.
- Week 5: IT governance frameworks and structures
- Week 6: IT strategy and alignment with business goals
- Week 7: IT resource and portfolio management
- Week 8: Risk management and monitoring practices
Month 3: Domains 3 and 4
Weeks 9 and 10: Information Systems Acquisition, Development, and Implementation
Cover the SDLC, project governance, requirements analysis, testing, and implementation. Focus on understanding the controls that should be present at each stage of system development and acquisition.
Weeks 11 and 12: Information Systems Operations and Business Resilience
Study IT service management, operations monitoring, incident response, BCP, and DRP. These topics frequently appear on the exam, so ensure you understand recovery strategies and testing approaches thoroughly.
Month 4: Domain 5, Protection of Information Assets
Allocate a full month to information asset protection given its breadth and exam weight. Cover security governance, access controls, cryptography, network security, and physical/environmental controls in depth.
- Week 13: Security policies, standards, and awareness programs
- Week 14: Logical access controls and identity management
- Week 15: Network and endpoint security
- Week 16: Data classification, encryption, and physical security
Month 5: Review and Practice Exams
The final month is entirely devoted to review and exam simulation. Take at least three full-length practice exams, analyze your results, and focus remediation efforts on your weakest domains. Create condensed review notes for last-minute study, and practice managing your time across 150 questions in four hours. By the end of this month, you should consistently score above 75% on practice exams before sitting for the real test.