Topic Deep Dives
Detailed guides on the most important CISA exam topics across all five domains.
Audit Standards and Frameworks
ITAF, ISACA standards, guidelines, and the IS audit process.
Risk-Based Audit Planning
How to prioritize audits using risk assessment and the audit universe.
COBIT Framework
Governance and management objectives, enablers, and the cascade principle.
IT Risk Management
Risk identification, assessment, response, and monitoring in IT environments.
Vendor Management Lifecycle
Due diligence, SLAs, contract management, and third-party risk.
SDLC Methodologies
Waterfall, agile, spiral, prototyping, and their audit implications.
Change Management Controls
Change control boards, emergency changes, and configuration management.
Testing Strategies
Unit, integration, system, UAT, regression, and performance testing.
BCP/DRP Planning
Business impact analysis, recovery strategies, and plan testing methods.
Incident Management
Detection, triage, containment, eradication, recovery, and lessons learned.
Backup and Recovery
Backup types, rotation schemes, RTO, RPO, and restoration testing.
Identity and Access Management
Authentication methods, RBAC, SSO, MFA, and privileged access management.
Encryption and PKI
Symmetric and asymmetric encryption, digital signatures, certificates, and key management.
Network Security
Firewalls, IDS/IPS, VPNs, network segmentation, and zero trust architecture.
Cloud Security
Shared responsibility model, SaaS/PaaS/IaaS security, and cloud audit challenges.