Domain 1: Information Systems Auditing Process
Standards, planning, evidence, sampling and reporting. The domain that decides how you approach every other one.
Start here
How CISA Questions Are Written
- 1How CISA Questions Are WrittenEvery option can be true and only one can be best. The reading technique that separates candidates who know the material from candidates who pass.9 min · 3 questions · video
- 2Standards, Ethics and the Audit CharterWhat gives an IS auditor the authority to demand evidence, and what obliges them to hand back work they are not competent to perform.8 min · 3 questions · video
- 3Independence and ObjectivityWhy the most helpful thing an auditor can do is often the one thing they must refuse, and how the exam ranks independence against every practical consideration.8 min · 3 questions · video
- 4Risk-Based Audit PlanningHow the annual audit plan is built from a risk assessment rather than from last year's plan, and why coverage is not the objective.9 min · 3 questions · video
- 5Materiality in an IS AuditFinancial audit measures materiality in currency. IS audit often cannot, and the exam expects you to know what replaces it.7 min · 3 questions · video
- 6Audit Types and Engagement ObjectivesCompliance, substantive, operational and integrated engagements ask different questions. Choosing the wrong one produces a technically correct answer to something nobody asked.7 min · 3 questions · video
- 7Design Effectiveness and Operating EffectivenessTwo questions that sound alike and are not. Testing the second when you have not established the first produces findings that do not hold up.8 min · 3 questions · video
- 8Choosing a Sampling ApproachStatistical or judgemental, attribute or variable. The choice determines what you are allowed to say about the population when you are finished.8 min · 3 questions · video
- 9Sample Size and Evaluating ExceptionsWhat actually moves sample size, and what to do with the exception you found, which is a harder question than most auditors treat it as.8 min · 3 questions · video
- 10Evidence: Sufficiency and ReliabilitySufficient is about quantity, appropriate is about quality, and the hierarchy of reliability is the part candidates guess at.8 min · 3 questions · video
- 11Test Methods and CAATsInquiry, observation, inspection and reperformance carry very different evidential weight, and computer assisted techniques let you stop sampling altogether.9 min · 3 questions · video
- 12Findings, Reporting and Follow-UpA finding without a cause is an observation. The four elements, who owns the risk acceptance decision, and why follow-up is where audit functions quietly fail.9 min · 3 questions · video
Before you start, optional
A short primer on IT general controls, written for practitioners rather than exam candidates. Useful background if ITGC is not your day-to-day, and not part of the Domain 1 sequence.
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Domain structure reflects the published exam content outline and is not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
