CISA®Certified Information Systems Auditor
Level: Expert
Course Overview
Course Overview
The CISA® (Certified Information Systems Auditor) certification is one of the world's most respected and recognised qualifications for information systems auditing, governance, risk management and assurance. Awarded by ISACA, CISA demonstrates a professional's ability to assess vulnerabilities, implement controls, manage risk and ensure regulatory compliance across modern IT environments. This four-day CISA training course is designed to help learners prepare for the latest CISA certification examination while developing the practical knowledge required to perform effective information systems audits. The course provides a comprehensive understanding of IT audit processes, governance frameworks, risk management principles and information systems controls. Throughout the course, delegates will explore the five CISA domains, learning how to plan, conduct, and report on IT audits; evaluate information systems operations; assess governance and management practices; and identify opportunities to improve organisational controls. Real-world examples and exam-focused content help learners build both professional competence and examination readiness.
Target Audience
- IT auditors and internal auditors
- Information security and cybersecurity professionals
- Risk, governance and compliance specialists
- IT managers and technology leaders
- Professionals responsible for information systems controls and assurance
- Individuals preparing for the ISACA CISA certification examination
By the End of This Course, You Will Be Able To:
- Understand the role and responsibilities of an Information Systems Auditor
- Plan, conduct and report on information systems audits
- Evaluate governance frameworks and IT management practices
- Assess information systems acquisition, development and implementation processes
- Review IT operations, resilience and service management controls
- Identify and evaluate information security risks and controls
- Assess compliance with policies, regulations and standards
- Recommend improvements to governance, risk and control processes
- Apply industry-recognised audit methodologies and best practices
- Prepare confidently for the CISA certification examination
The CISA® (Certified Information Systems Auditor) certification is one of the world's most respected and recognised qualifications for information systems auditing, governance, risk management and assurance. Awarded by ISACA, CISA demonstrates a professional's ability to assess vulnerabilities, implement controls, manage risk and ensure regulatory compliance across modern IT environments. This four-day CISA training course is designed to help learners prepare for the latest CISA certification examination while developing the practical knowledge required to perform effective information systems audits. The course provides a comprehensive understanding of IT audit processes, governance frameworks, risk management principles and information systems controls. Throughout the course, delegates will explore the five CISA domains, learning how to plan, conduct, and report on IT audits; evaluate information systems operations; assess governance and management practices; and identify opportunities to improve organisational controls. Real-world examples and exam-focused content help learners build both professional competence and examination readiness.
Target Audience
- IT auditors and internal auditors
- Information security and cybersecurity professionals
- Risk, governance and compliance specialists
- IT managers and technology leaders
- Professionals responsible for information systems controls and assurance
- Individuals preparing for the ISACA CISA certification examination
By the End of This Course, You Will Be Able To:
- Understand the role and responsibilities of an Information Systems Auditor
- Plan, conduct and report on information systems audits
- Evaluate governance frameworks and IT management practices
- Assess information systems acquisition, development and implementation processes
- Review IT operations, resilience and service management controls
- Identify and evaluate information security risks and controls
- Assess compliance with policies, regulations and standards
- Recommend improvements to governance, risk and control processes
- Apply industry-recognised audit methodologies and best practices
- Prepare confidently for the CISA certification examination
CISA Certified Information Security Auditor
Domain 1 – Information System Auditing Process
- IS Audit Standards, Guidelines, Functions, and Codes of Ethics
- Types of Audits, Assessments, and Reviews
- Risk-based Audit Planning
- Types of Controls and Considerations
- Audit Project Management
- Audit Testing and Sampling Methodology
- Audit Evidence Collection Techniques
- Audit Data Analytics
- Reporting and Communication Techniques
- Quality Assurance and Improvement of Audit Process
Domain 2 – Governance and Management of IT
- Laws, Regulations, and Industry Standards
- Organisational Structure, IT Governance, and IT Strategy
- IT Policies, Standards, Procedures, and Guidelines
- Enterprise Architecture and Considerations
- Enterprise Risk Management (ERM)
- Privacy Program and Principles
- Data Governance and Classification
- IT Resource Management
- IT Vendor Management
- IT Performance Monitoring and Reporting
- Quality Assurance and Quality Management of IT
Domain 3 – Information Systems Acquisition, Development, and Implementation
- Project Governance and Management
- Business Case and Feasibility Analysis
- System Development Methodologies
- Control Identification and Design
- System Readiness and Implementation Testing
- Implementation Configuration and Release Management
- System Migration, Infrastructure Deployment, and Data Conversion
- Post-Implementation Review
Domain 4 – Information Systems Operations and Business Resilience
- IT Components
- IT Asset Management
- Job Scheduling and Production Process Automation
- System Interfaces
- End-user Computing and Shadow IT
- Systems Availability and Capacity Management
- Problem and Incident Management
- IT Change, Configuration, and Patch Management
- Operational Log Management
- IT Service Level Management
- Database Management
- Business Impact Analysis
- System and Operational Resilience
- Data Backup, Storage, and Restoration
- Business Continuity Plan
- Disaster Recovery Plans
Domain 5 – Protection of Information Assets
- Information Asset Security Policies, Frameworks, Standards, and Guidelines
- Physical and Environmental Controls
- Identity and Access Management
- Network and End-Point Security
- Data Loss Prevention
- Data Encryption
- Public Key Infrastructure (PKI)
- Cloud and Virtualised Environments
- Mobile, Wireless, and Internet-of-Things Devices
- Security Awareness Training and Programs
- Information System Attack Methods and Techniques
- Security Testing Tools and Techniques
- Security Monitoring Logs, Tools, and Techniques
- Security Incident Response Management
- Evidence Collection and Forensics
CISA Exam Preparation
- CISA Exam Rules
- Exam Tips
- Day of the Exam
- CISA Certification Steps
CISA Certified Information Security Auditor
Domain 1 – Information System Auditing Process
- IS Audit Standards, Guidelines, Functions, and Codes of Ethics
- Types of Audits, Assessments, and Reviews
- Risk-based Audit Planning
- Types of Controls and Considerations
- Audit Project Management
- Audit Testing and Sampling Methodology
- Audit Evidence Collection Techniques
- Audit Data Analytics
- Reporting and Communication Techniques
- Quality Assurance and Improvement of Audit Process
Domain 2 – Governance and Management of IT
- Laws, Regulations, and Industry Standards
- Organisational Structure, IT Governance, and IT Strategy
- IT Policies, Standards, Procedures, and Guidelines
- Enterprise Architecture and Considerations
- Enterprise Risk Management (ERM)
- Privacy Program and Principles
- Data Governance and Classification
- IT Resource Management
- IT Vendor Management
- IT Performance Monitoring and Reporting
- Quality Assurance and Quality Management of IT
Domain 3 – Information Systems Acquisition, Development, and Implementation
- Project Governance and Management
- Business Case and Feasibility Analysis
- System Development Methodologies
- Control Identification and Design
- System Readiness and Implementation Testing
- Implementation Configuration and Release Management
- System Migration, Infrastructure Deployment, and Data Conversion
- Post-Implementation Review
Domain 4 – Information Systems Operations and Business Resilience
- IT Components
- IT Asset Management
- Job Scheduling and Production Process Automation
- System Interfaces
- End-user Computing and Shadow IT
- Systems Availability and Capacity Management
- Problem and Incident Management
- IT Change, Configuration, and Patch Management
- Operational Log Management
- IT Service Level Management
- Database Management
- Business Impact Analysis
- System and Operational Resilience
- Data Backup, Storage, and Restoration
- Business Continuity Plan
- Disaster Recovery Plans
Domain 5 – Protection of Information Assets
- Information Asset Security Policies, Frameworks, Standards, and Guidelines
- Physical and Environmental Controls
- Identity and Access Management
- Network and End-Point Security
- Data Loss Prevention
- Data Encryption
- Public Key Infrastructure (PKI)
- Cloud and Virtualised Environments
- Mobile, Wireless, and Internet-of-Things Devices
- Security Awareness Training and Programs
- Information System Attack Methods and Techniques
- Security Testing Tools and Techniques
- Security Monitoring Logs, Tools, and Techniques
- Security Incident Response Management
- Evidence Collection and Forensics
CISA Exam Preparation
- CISA Exam Rules
- Exam Tips
- Day of the Exam
- CISA Certification Steps
- Exam duration: 4 hours (240 minutes)
- 150 multiple-choice questions
- The examination is scored using ISACA’s scaled scoring system. A scaled score of 450 or higher is required to pass.
- Closed-book examination – no reference materials are permitted during the exam
- In addition to passing the examination, candidates must satisfy ISACA’s professional experience and certification requirements before the full CISA certification can be awarded.
- Further information on certification requirements is available from ISACA
Please note: The CISA examination voucher is not included with this course.
- Exam duration: 4 hours (240 minutes)
- 150 multiple-choice questions
- The examination is scored using ISACA’s scaled scoring system. A scaled score of 450 or higher is required to pass.
- Closed-book examination – no reference materials are permitted during the exam
- In addition to passing the examination, candidates must satisfy ISACA’s professional experience and certification requirements before the full CISA certification can be awarded.
- Further information on certification requirements is available from ISACA
Please note: The CISA examination voucher is not included with this course.
- Four days of instructor-led training and exam preparation delivered by an accredited CISA trainer
- Comprehensive course notes, presentation slides and supporting learning materials
- Practical exam preparation covering the latest CISA examination objectives
- NILC course completion certificate
- Four days of instructor-led training and exam preparation delivered by an accredited CISA trainer
- Comprehensive course notes, presentation slides and supporting learning materials
- Practical exam preparation covering the latest CISA examination objectives
- NILC course completion certificate
There are no formal prerequisites for attending this course. However, as CISA is an advanced-level certification, learners will benefit from prior experience in IT, information systems, cybersecurity, risk management, governance, compliance or auditing functions. Please note that while anyone can sit the CISA examination, ISACA requires candidates to meet specific professional experience requirements before it can award full CISA certification.
There are no formal prerequisites for attending this course. However, as CISA is an advanced-level certification, learners will benefit from prior experience in IT, information systems, cybersecurity, risk management, governance, compliance or auditing functions. Please note that while anyone can sit the CISA examination, ISACA requires candidates to meet specific professional experience requirements before it can award full CISA certification.
Who is the CISA course suitable for?
The CISA course is designed for professionals involved in auditing, assessing or managing information systems and technology risks. It is particularly suitable for IT auditors, internal auditors, cybersecurity professionals, risk and compliance specialists, IT managers and professionals responsible for information systems controls and assurance.
Is CISA suitable for beginners?
CISA is an Expert-level certification and is primarily aimed at experienced professionals. There are no formal prerequisites for attending the training, but previous experience in IT, cybersecurity, auditing, risk management, governance or compliance will help you get the most from the course.
Do I need auditing experience before attending?
Previous auditing experience is beneficial but not required to attend the course. The training covers the information systems auditing process in detail, including audit planning, risk assessment, testing, evidence collection, reporting and quality assurance.
Who is the CISA course suitable for?
The CISA course is designed for professionals involved in auditing, assessing or managing information systems and technology risks. It is particularly suitable for IT auditors, internal auditors, cybersecurity professionals, risk and compliance specialists, IT managers and professionals responsible for information systems controls and assurance.
Is CISA suitable for beginners?
CISA is an Expert-level certification and is primarily aimed at experienced professionals. There are no formal prerequisites for attending the training, but previous experience in IT, cybersecurity, auditing, risk management, governance or compliance will help you get the most from the course.
Do I need auditing experience before attending?
Previous auditing experience is beneficial but not required to attend the course. The training covers the information systems auditing process in detail, including audit planning, risk assessment, testing, evidence collection, reporting and quality assurance.
Dates & Prices
Live Instructor-Led Virtual
Live Instructor-Led Virtual
Can't find the course dates, location or delivery type you are looking for?
Fill out the request dates form above and we'll try our best to accommodate or contact us directly.
"*" indicates required fields
How we deliver our courses
Virtual
Our virtual courses allow you to access live instructor-led training from the same expert instructors that deliver our classroom courses, without leaving the comfort of your home or office. All virtual courses are fully interactive, and learners can communicate with their trainer and peers at any time.
Many of our virtual courses are also recorded, so you can recap over the content you learnt as many time as you wish.
Classroom
Our classroom courses allow you to learn and interact face-to-face with our expert instructors in a comfortable and modern training environment. All of our classroom based courses take place at NILC centers, or high quality training facilities, and include all required IT and physical equipment.
We also limit our class sizes to help promote better discussions and to ensure your learning experience is comfortable as possible.
Onsite
Save time and hassle by arranging for one of our expert instructors to come to you. Our onsite courses allow you to learn in a location of your choosing, and you can train as many or as few people as you want – from a single person or team to whole departments. We can also fully customize the course content to the specific requirements of your business or project.
We offer onsite courses throughout the UK and it can be a great team building opportunity for colleagues to come together, bond and discuss.
Online
Our Online Self Paced courses allow you to learn new skills from our expert instructors, in your own time and at your own pace. Our flexible online learning platform allows you to access content on your computer, tablet or mobile device, whether you’re on the move or at home. All our online courses come with immediate access and you can start learning straight away, from any internet enabled compatible device.
We also offer online email support from our expert instructors, so they’re always on hand and happy to help you with any questions which may arise.
Why choose NILC for your training?
Award-Winning Training with Industry-Leading Customer Satisfaction
Trusted Training Partner by Colleges, Government Organisations and Businesses
UK-Based Trainers with Real-World Industry Experience
Family-Run Business with Customer Service at Its Core
Rated Excellent on Trustpilot with 950+ Customer Reviews
Our learners rate us 'Excellent' on Trustpilot
Frequently Asked Questions
The CISA course is designed for professionals involved in auditing, assessing or managing information systems and technology risks. It is particularly suitable for IT auditors, internal auditors, cybersecurity professionals, risk and compliance specialists, IT managers and professionals responsible for information systems controls and assurance.
CISA is an Expert-level certification and is primarily aimed at experienced professionals. There are no formal prerequisites for attending the training, but previous experience in IT, cybersecurity, auditing, risk management, governance or compliance will help you get the most from the course.
Previous auditing experience is beneficial but not required to attend the course. The training covers the information systems auditing process in detail, including audit planning, risk assessment, testing, evidence collection, reporting and quality assurance.
Yes. You can take the CISA examination before meeting the full professional experience requirements. However, passing the exam alone does not automatically award the full CISA certification. You must also satisfy ISACA’s professional experience and certification requirements.
The course covers all five CISA domains: Information Systems Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development and Implementation; Information Systems Operations and Business Resilience; and Protection of Information Assets.
CISA covers key technical areas, including network security, identity and access management, encryption, cloud environments, incident response, and security monitoring. However, its primary focus is on auditing, governance, risk, controls and assurance rather than hands-on cybersecurity engineering.
Yes. Governance, risk and compliance are major areas within CISA. You will explore IT governance, enterprise risk management, policies and standards, regulatory requirements, privacy, data governance and methods for assessing organisational controls.
Yes. The course is specifically designed to prepare you for the CISA examination. It covers the latest CISA examination objectives, exam-focused content, exam rules, preparation guidance, and practical exam tips.
No. The CISA examination voucher is not included in the course price. The course includes four days of instructor-led training and exam preparation, but you must purchase the exam separately.
The CISA examination consists of 150 multiple-choice questions and lasts up to four hours. It is a closed-book examination, and ISACA uses a scaled scoring system, with a score of 450 or higher required to pass.
Frequently Asked Questions
The CISA course is designed for professionals involved in auditing, assessing or managing information systems and technology risks. It is particularly suitable for IT auditors, internal auditors, cybersecurity professionals, risk and compliance specialists, IT managers and professionals responsible for information systems controls and assurance.
CISA is an Expert-level certification and is primarily aimed at experienced professionals. There are no formal prerequisites for attending the training, but previous experience in IT, cybersecurity, auditing, risk management, governance or compliance will help you get the most from the course.
Previous auditing experience is beneficial but not required to attend the course. The training covers the information systems auditing process in detail, including audit planning, risk assessment, testing, evidence collection, reporting and quality assurance.
Yes. You can take the CISA examination before meeting the full professional experience requirements. However, passing the exam alone does not automatically award the full CISA certification. You must also satisfy ISACA’s professional experience and certification requirements.
The course covers all five CISA domains: Information Systems Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development and Implementation; Information Systems Operations and Business Resilience; and Protection of Information Assets.
CISA covers key technical areas, including network security, identity and access management, encryption, cloud environments, incident response, and security monitoring. However, its primary focus is on auditing, governance, risk, controls and assurance rather than hands-on cybersecurity engineering.
Yes. Governance, risk and compliance are major areas within CISA. You will explore IT governance, enterprise risk management, policies and standards, regulatory requirements, privacy, data governance and methods for assessing organisational controls.
Yes. The course is specifically designed to prepare you for the CISA examination. It covers the latest CISA examination objectives, exam-focused content, exam rules, preparation guidance, and practical exam tips.
No. The CISA examination voucher is not included in the course price. The course includes four days of instructor-led training and exam preparation, but you must purchase the exam separately.
The CISA examination consists of 150 multiple-choice questions and lasts up to four hours. It is a closed-book examination, and ISACA uses a scaled scoring system, with a score of 450 or higher required to pass.
Trusted By