A Certified Information Systems Auditor is someone trained to examine how organizations protect their computer systems and data

A Certified Information Systems Auditor (CISA) is a professional who inspects an organization's IT systems, security controls, and data handling practices to find weaknesses and ensure compliance with regulations. Unlike a general IT worker who maintains systems day-to-day, a CISA acts as an independent reviewer — someone brought in to verify that controls are working, risks are being managed, and the organization follows the rules that apply to its industry.

The CISA credential is issued by ISACA, a nonprofit organization that sets standards for IT audit, governance, and security. To earn it, a person must pass an exam, meet work experience requirements, and agree to follow a code of ethics. Organizations hire CISAs to audit their systems before a major change, after a security incident, or to meet regulatory requirements — particularly in banking, healthcare, and government where data protection is legally mandated.

Key Takeaways

  • A CISA examines IT systems and security controls to find gaps and verify compliance with regulations, rather than building or maintaining systems.
  • The CISA exam covers five domains: IT audit processes, governance and management, information systems acquisition and implementation, operations and service delivery, and protection of information assets.
  • CISA certification requires passing the exam plus five years of IT audit or security work experience, though some education can substitute for part of that requirement.
  • Organizations in regulated industries like banking, healthcare, and government often require or strongly prefer CISAs to conduct audits and verify their security posture.
  • A CISA typically earns between $90,000 and $130,000 annually, depending on location, employer size, and years of experience.

What a CISA actually does on the job

A CISA's work varies by employer and industry, but the core task is always the same: assess whether an organization's IT environment is secure, well-managed, and compliant with applicable rules. This might mean reviewing access logs to confirm that only authorized people can reach sensitive data, testing whether backups actually work if the main system fails, or checking that the organization has documented its security policies and trained staff to follow them.

In practice, a CISA might spend weeks inside an organization interviewing IT staff, reviewing documentation, running tests on systems, and observing processes. They produce a report listing what they found — both strengths and gaps — and recommend fixes. They do not usually implement those fixes themselves; instead, they hand the report to management and IT leadership, who decide what to address and how quickly.

Some CISAs work for the organization itself as an internal auditor, conducting regular reviews of their own systems. Others work for audit firms or consulting companies and are hired to audit multiple clients. Government agencies also employ CISAs to oversee contractor systems or verify that federal IT spending is secure and compliant.

The CISA exam and what it covers

The CISA exam is a single test lasting four hours with 150 multiple-choice questions. It covers five domains: IT audit processes, governance and management, information systems acquisition and implementation, operations and service delivery, and protection of information assets. Each domain tests both knowledge and judgment — not just whether you know a definition, but whether you can apply it to a real scenario.

The exam is offered year-round at testing centers and covers topics like how to plan an audit, how to evaluate whether IT governance is working, how to assess risks in new systems, how to verify that operations are running smoothly, and how to confirm that data and systems are protected. Most people study for two to four months before sitting for the exam, using study guides, practice tests, and sometimes instructor-led courses.

You do not have to pass the exam on your first try, and retakes are allowed. The exam costs around $760 for ISACA members and $960 for non-members. Many employers cover the exam fee for staff pursuing the credential.

Experience and education requirements

To hold the CISA credential, you must pass the exam and meet an experience requirement. ISACA requires five years of IT audit, IT security, or IT governance work experience. However, if you hold certain other certifications — such as CISSP or CISM — you can reduce that requirement to four years. If you have a bachelor's degree in a related field, you can reduce it to four years as well.

You do not need a degree to become a CISA, but you do need documented work experience in IT audit or security. This means roles like IT auditor, security analyst, compliance officer, or IT risk manager. General IT support or system administration work typically does not count toward the requirement unless you can show it included audit or security responsibilities.

After you pass the exam, you have three years to submit your experience documentation to ISACA for review. Once approved, you receive the CISA credential and must renew it every three years by earning continuing education credits and paying a renewal fee.

Industries and roles that hire CISAs

Banks and financial institutions are among the largest employers of CISAs because regulators require them to conduct regular audits of their IT systems and security controls. Healthcare organizations hire CISAs to verify compliance with HIPAA, which sets strict rules for protecting patient data. Government agencies at federal, state, and local levels employ CISAs to oversee IT spending and security. Insurance companies, utilities, and large retailers also commonly hire CISAs to manage IT risk and audit their systems.

Within these organizations, CISAs work in audit departments, compliance teams, risk management offices, or as consultants to IT leadership. Some CISAs move into management roles overseeing teams of auditors or directing an organization's entire audit function. Others specialize in specific areas like cloud security auditing or compliance with particular regulations.

How CISA compares to other IT security certifications

The CISA is one of several certifications in the IT security and governance space, and they serve different purposes. The CISSP (Certified Information Systems Security Professional) focuses on designing and building secure systems, while CISA focuses on auditing and verifying that security is working. The CISM (Certified Information Security Manager) is aimed at people managing security programs and teams, whereas CISA is broader and includes audit, governance, and compliance alongside security.

The CompTIA Security+ is an entry-level security certification that covers foundational security concepts and is often a stepping stone before pursuing CISA. The COBIT framework, also from ISACA, is a governance and management standard that CISAs often use as a reference when auditing IT controls, though COBIT itself is not a certification.

If you are early in your IT career and want to move toward audit and governance, CISA is a strong choice. If you want to specialize in building secure systems or managing a security team, CISSP or CISM might be a better fit. Many professionals hold multiple certifications over their careers as their roles evolve.

Salary and job outlook

A CISA typically earns between $90,000 and $130,000 annually in the United States, depending on location, employer size, years of experience, and industry. CISAs in major financial centers or working for large banks tend to earn toward the higher end. Those in smaller organizations or less regulated industries may earn less. Salary also increases with experience — a newly certified CISA often starts lower than someone with ten years in the role.

Demand for CISAs remains steady because regulatory requirements for IT audits and security controls are not going away. As organizations move more systems to the cloud and face growing cybersecurity threats, the need for independent auditors who can verify security and compliance continues to grow. However, the job market is competitive, and most employers expect candidates to have several years of IT audit or security work before pursuing the credential.

Frequently Asked Questions

Do I need IT work experience before taking the CISA exam?

You can take the exam without the required experience, but you cannot use the CISA credential until you have met the experience requirement and submitted documentation to ISACA. Many people take the exam first while still building their work history, then formally apply for the credential once they have the required years.

How long does it take to study for the CISA exam?

Most people study for two to four months, dedicating 10 to 15 hours per week. The timeline depends on your background — someone with IT audit experience may need less time than someone transitioning from a different IT role. Self-study, instructor-led courses, and boot camps are all common approaches.

Can I get a CISA if I work in IT support or system administration?

Not directly, because those roles do not typically count toward the experience requirement. However, you could move into an IT audit, security, or compliance role and then pursue CISA after gaining the required years in that position. Some organizations offer internal audit roles as a path for IT staff to transition into audit work.

Is CISA worth the time and cost?

If you work in or want to move into IT audit, governance, or compliance — especially in regulated industries — CISA significantly increases your marketability and earning potential. If you are happy in a general IT support or system administration role, CISA may not be necessary. The decision depends on your career goals and whether your employer values or requires the credential.

What happens if I fail the CISA exam?

You can retake it as many times as needed. Most people who fail study for another one to three months and pass on the second attempt. ISACA provides feedback on which domains you scored lowest in, which helps you focus your next study effort.