Cheat Sheet · Cybersecurity

CISA Cheat Sheet: Domains, Audit & Control Terms

advanced

A free CISA cheat sheet: the five domains and official weights, audit and control terms, and business-resilience essentials for final pre-exam revision.

By The Exam Atlas Editorial Team · Verified 2026-06-06

A final-revision summary for CISA. Study aid only - no notes are allowed in the proctored exam.

The five domains and weights

DomainOfficial weight
Information Systems Auditing Process18%
Governance and Management of IT18%
IS Acquisition, Development and Implementation12%
IS Operations and Business Resilience26%
Protection of Information Assets26%

CISA vs CISM in one line

CISACISM
SeatAuditor - examines controls from the outsideManager - runs the security programme from the inside
VerbAssess, verify, reportPlan, build, operate
If a question tempts you to……gather evidence / report a finding…implement or fix a control

If a CISA option has you fixing or operating a control, it is usually the wrong (CISM-style) answer.

Audit-process essentials

TermIdea
Independence / objectivityThe auditor must not audit work they performed or own
Sufficient, appropriate evidenceEnough, and relevant + reliable, to support the conclusion
Risk-based auditingScope and effort follow where control failure hurts most
SamplingStatistical vs judgemental selection of items to test
MaterialityWhether a finding is significant enough to matter

Control types

TermIdea
PreventiveStops an event (e.g., access control)
DetectiveSpots an event after it happens (e.g., log review)
CorrectiveFixes or restores after an event
CompensatingCovers a gap when the primary control is impractical

Business-resilience essentials

The chain to remember: BIA → RTO/RPO → BCP/DRP - and the auditor checks the plans match the BIA and are actually tested.

TermMeaning
BIABusiness Impact Analysis
RTO / RPORecovery Time / Recovery Point Objective
BCP / DRPBusiness Continuity Plan / Disaster Recovery Plan
SoDSegregation of Duties
Change managementControlled approval of changes to systems

FAQ

Can I bring notes to the CISA exam?
No. CISA is a proctored exam. Use this for final revision before exam day only.

Sources