Syllabus · Cybersecurity

CISA Domains Explained (The 5 CISA Domains & Weights)

advanced

The five CISA domains (auditing process, IT governance, development, operations and protecting assets) explained in plain English with official weights.

By The Exam Atlas Editorial Team · Verified 2026-06-06

CISA is organised into five domains, all viewed from an auditor’s perspective: you assess and report on controls, you do not build or run them. The weightings below are ISACA’s official figures; ISACA’s content outline is authoritative.

#DomainOfficial weight
1Information Systems Auditing Process18%
2Governance and Management of IT18%
3Information Systems Acquisition, Development and Implementation12%
4Information Systems Operations and Business Resilience26%
5Protection of Information Assets26%

Domain 1 - Information Systems Auditing Process (18%)

The practice of auditing: risk-based planning, executing against ISACA’s audit standards, gathering sufficient and appropriate evidence, sampling, and reporting findings. Independence and objectivity underpin the whole domain.

Domain 2 - Governance and Management of IT (18%)

Auditing how IT is directed and controlled: governance frameworks, IT strategy and business alignment, policies and structures, roles, and IT-related risk management.

Domain 3 - Information Systems Acquisition, Development and Implementation (12%)

The smallest domain. Auditing how systems are acquired, built and deployed: business cases, project governance, the SDLC and its controls, testing, migration, and the post-implementation review.

Domain 4 - Information Systems Operations and Business Resilience (26%)

Joint-largest. Auditing IT operations (change, problem and incident management, scheduling, backups) and resilience: business continuity and disaster recovery, anchored in the BIA and its RTO/RPO targets.

Domain 5 - Protection of Information Assets (26%)

Joint-largest. Auditing the controls that protect data and systems: logical and physical access, network and endpoint security, encryption and key management, data classification, and incident response.

FAQ

How many domains does CISA have?
Five: Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets.
Which CISA domains are largest?
Two tie at 26% each: Information Systems Operations and Business Resilience, and Protection of Information Assets. Together they are over half the exam.

Sources