CISA Certification Overview
The mark of excellence for a professional certification program is the value and recognition it bestows on the individual who achieves it. Since 1978, the Certified Information Systems Auditor (CISA) program, sponsored by ISACA®, has been the globally accepted standard of achievement among information systems (IS) audit, control and security professionals.
The technical skills and practices that CISA promotes and evaluates are the building blocks of success in the field. Possessing the CISA designation demonstrates proficiency and is the basis for measurement in the profession. With a growing demand for professionals possessing IS audit, control and security skills, CISA has become a preferred certification program by individuals and organizations around the world. CISA certification signifies commitment to serving an organization and the IS audit, control and security industry with distinction. In addition, it presents a number of professional and personal benefits.
Worldwide Recognition
Although certification may not be mandatory for you at this time, a growing number of organizations are recommending that employees become certified. To help ensure success in the global marketplace, it is vital to select a certification program based on universally accepted technical practices. CISA delivers such a program. CISA is recognized worldwide, by all industries, as the preferred designation for IS audit, control and security professionals.
More than 50,000 professionals have earned the CISA since inception, so clearly many people agree: earning the CISA is a good career move
CISA Exam Information
The CISA exam is offered annually during the months of June and December.
June 2007 Exam Dates
14 February – Early Registration Deadline
11 April – Final Registration Deadline
9 June - Exam
December 2007 Exam Dates
15 August – Early Registration Date
26 September – Final Registration Date
8 December – Exam
Requirements for CISA CertificationThe CISA designation is awarded to those individuals with an interest in Information Systems auditing, control, and security who have met and continue to meet the following requirements regarding:
Successful completion of the CISA examination
Information systems auditing, control or security experience
Adherence to the Code of Professional Ethics
Adherence to the continuing professional education program
Compliance with the Information Systems Auditing Standards
1. Successful Completion of the CISA Examination
The examination is open to all individuals who have an interest in information systems audit, control and security. All are encouraged to work toward and take the examination. Successful examination candidates will be sent all documents required to apply for certification with their notification of a passing score. For a more detailed description of the exam see Exam Information. Also, CISA Exam Preparation resources are available through the association and many chapters host CISA Exam Review Courses (contact your local chapter).
The CISA examination is offered twice a year, in June and December. The Bulletin of Information (BOI) is published online when it becomes available for each exam. You may also request a BOI by completing the online Request for Information form or by emailing your complete mailing address to
certification@isaca.org. You may register online or by completing the registration form within the BOI and faxing or mailing it to ISACA for processing. For registration dates and deadlines please see the Exam Information page.
2. Experience as an Information Systems Auditor
A minimum of five years of professional information systems auditing, control or security work experience (as described in the job content areas) is required for certification. Substitutions and waivers of such experience may be obtained as follows:
A maximum of one year of information systems experience OR one year of financial or operational auditing experience can be substituted for one year of information systems auditing, control or security experience.
60 to 120 completed college semester credit hours (the equivalent of an Associate or Bachelor degree) can be substituted for one or two years, respectively, of information systems auditing, control or security experience.
A bachelor's or master's degree from a university that enforces the ISACA sponsored Model Curricula can be substituted for one year of information systems auditing, control, assurance or security experience. To view a list of these schools, please visit
www.isaca.org/modeluniversities. This option cannot be used if three years of experience substitution and educational waiver have already been claimed.
Two years as a full-time university instructor in a related field (e.g., computer science, accounting, information systems auditing) can be substituted for one year of information systems auditing, control or security experience.
Experience must have been gained within the 10-year period preceding the application date for certification or within five years from the date of initially passing the examination. Retaking and passing the examination will be required if the application for certification is not submitted within five years from the passing date of the examination. All experience must be verified independently with employers.
3. The Code of Professional Ethics
Members of ISACA and/or holders of the CISA designation agree to a Code of Professional Ethics to guide professional and personal conduct.
4. Continuing Professional Education (CPE) Policy
The objectives of the continuing education program are to:
Maintain an individual's competency by requiring the update of existing knowledge and skills in the areas of information systems auditing, management, accounting and business areas related to specific industries (e.g., finance, insurance, business law, etc.)
Provide a means to differentiate between qualified CISAs and those who have not met the requirements for continuation of their certification
Provide a mechanism for monitoring information systems audit, control and security professionals' maintenance of their competency
Aid top management in developing sound information systems audit, control and security functions by providing criteria for personnel selection and development
Maintenance fees and a minimum of 20 contact hours of CPE are required annually. In addition, a minimum of 120 contact hours is required during a fixed 3-year period. Upon completing the requirements for initial certification, the CISA will be provided with the CPE policy booklet for detailed criteria to be used in developing a personal CPE program.
View the complete Continuing Professional Education Policy.
5. Information Systems Auditing Standards
Individuals holding the CISA designation agree to adhere to the Information Systems Auditing Standards as adopted by ISACA.
CISA FAQ Answers
Exam Registration & Administration
When will the exam results be released?
The exam results will be released approximately 8 weeks after the exam date.
How will my exam results be released?
If at the time of registration you selected to be notified by email, a one-time email notification will be sent within 8 weeks of the exam date. Candidates will also receive a hard copy result letter sent by post within 8 weeks of the exam date.
What is the date of the next CISA exam?
The next exam is Saturday, 9 June 2007.
When does registration begin for the 9 June 2007 exam?
Registration for the 9 June 2007 exam is currently available at
www.isaca.org/examreg.
What is the cost of the June 2007 exam and what are the deadlines?
On or before 14 February 2007:
ISACA Members: US $360
Nonmembers: US $480
After 14 February through 11 April 2007:
ISACA Members: US $410
Nonmembers: US $530
Candidates can save $50 on the exam registration fee by registering online.
How do I know if my online registration has been confirmed?
An online acknowledgement appears directly after finishing the checkout process. An email confirmation is sent immediately after completing your registration. This email has a subject line of ISACA.ORG Purchase Confirmation. If you have not received this email, please check your Spam folder. Additionally, you may confirm your order by clicking on "My Order History" in your online profile.
Will I receive a receipt for my registration payment?
Yes, a receipt for the payment is mailed to you automatically once the registration form and payment have been processed.
How can I defer my exam?
Candidates unable to take the exam can request a deferral of their registration fees to the next exam date. Deferral requests received on or before 2 May 2007 will be charged a US $50 processing fee. From 3 May 2007 through 1 June 2007, a processing fee of US $100 will be charged. Deferral requests will not be accepted after 1 June 2007. To request a deferral, please go to
www.isaca.org/examdefer. The exam and deferral fees are nonrefundable.
How do I request a cancellation of my registration?
Candidates unable to take the exam are eligible for a refund of registration fees, less a US $100 processing fee, if such a request is received in writing on or before 20 April 2007. All requests for a refund after this date will be denied.
Can I take the CISA and CISM exams on the same day?
The CISA and CISM exams will be held simultaneously; therefore, they cannot be taken on the same day.
Certification Requirements
When can I renew my certification and enter my CPE hours?
Online renewal is currently available. The hard copy invoice was sent by post during the last week of November. Please remember to record your CPE hours, if applicable, when making your payment.
A second invoice will automatically be resent at the end of January to anyone who has not paid and/or reported CPE hours.
Where can I find the CISA application for certification?
CISA applications are located at
www.isaca.org/CISAapp. Please be aware that there are two different applications available depending upon the year that you passed the exam.
What are the qualifications to earn the CISA credential?
Qualifying for CISA requires a combination of four "e's": experience, ethics, education and exam. Specifically, the requirements are:
Successful completion of the CISA exam
Adherence to a code of professional conduct
Commitment to continuing professional education
A minimum of five years of professional information systems auditing, control or security work experience (as described in the job content areas) is required for certification. Substitutions and waivers of such experience may be obtained if certain education and general IS or audit experience requirements are met.
For further details, click here.
What does the CISA continuing professional education program require?
In order to become and remain a CISA an individual must agree to comply with the CISA continuing professional education program. This program requires an individual to earn a minimum of twenty (20) hours annually and one hundred twenty (120) hours every three years of continuing professional education. In addition, an annual maintenance fee of US $40 ISACA member and US $70 non-member is required.
To access the CPE policy, click here.
When can I report my 2006 CPE hours?
The ability to enter CPE hours for 2006 is currently available online. You may provide your hours online in one of two ways. You may either click on My Renewals to enter both your annual payment and your CPE hours. Or, if you have already submitted payment, or intend to submit payment at a later date, and wish to report hours only, please click on ISACA > My Profile > Certification Profile and then scroll down to the CPE Hour Summary Chart.
Additionally, a hard copy invoice was sent to each certificate holder in late November. A second invoice will automatically be resent at the end of January to anyone who has not paid and/or reported CPE hours.
How can I earn CPE credits online?
ISACA members can earn CPE hours by taking an Information Systems Control Journal CPE Quiz online. One contact hour is awarded per quiz.
What do I need to do if I’ve received a revocation notice?
If you have received a revocation notice, please contact
certification@isaca.org.
Exam Content
How long is the exam?
A candidate is given 4 hours to complete a 200 multiple-choice question exam.
What does the CISA exam cover?
The CISA exam will cover six IS audit, control or security areas, each of which is further defined and detailed through task and knowledge statements. For specific details, please go to
www.isaca.org/cisacontentareas.
Other
How do I request additional information or report an issue regarding a current or past credential holder?
To request additional information or to report an issue regarding a current or past credential holder, please contact the ISACA certification department at:
Email:
certification@isaca.org Tel: +1.847.253.1545, ext. 403 or ext. 471
Fax: +1.847.253.1443
How can I become a CISA Exam Item Writer?
You can apply online to become a CISA Exam Item Writer at
www.isaca.org/CISAexamitemwriter.