A CISA is someone who checks whether a company's IT systems and security controls actually work

A Certified Information Systems Auditor (CISA) is a person who examines an organization's computer systems, security practices, and controls to find gaps and risks. They are not the same as a security informed who builds defenses — they are the person who tests whether those defenses are actually doing their job. A CISA might discover that a company has a password policy on paper but nobody is enforcing it, or that backups are scheduled but nobody has tested whether they actually restore.

The CISA credential is issued by ISACA, a nonprofit organization that sets standards for IT audit, governance, and security. To earn it, you take a four-hour exam covering five domains: IT audit processes, governance and management of IT, information systems acquisition and implementation, information systems operations and business resilience, and protection of information assets. You also need at least five years of work experience in IT audit, security, or a related field — though some education can substitute for part of that time.

CISAs work in-house at large companies, at audit firms that contract with multiple clients, or at government agencies. They report to audit committees or chief information security officers and have authority to look at systems and processes that other IT staff might not. The job exists because regulators, boards of directors, and insurance companies require independent verification that security controls are real and working.

Key Takeaways

  • A CISA examines whether a company's security controls and IT processes actually work, not whether they exist on paper.
  • The credential requires passing a four-hour exam and having at least five years of relevant work experience in audit, security, or IT operations.
  • CISAs are hired by large organizations, audit firms, and government agencies to verify that systems meet regulatory and insurance requirements.
  • The job pays between $90,000 and $130,000 annually depending on location, employer size, and years of experience, with higher pay in financial services and healthcare.

What a CISA actually does on the job

A CISA's day-to-day work depends on the employer. At a bank or insurance company, a CISA might spend a week testing whether access controls on the customer database actually prevent unauthorized viewing. They run test transactions, check logs, interview staff, and document what they find. At an audit firm, a CISA might rotate between three or four clients in a month, each time starting fresh with a new system or process to evaluate.

The work is methodical and often unglamorous. A CISA might spend two days verifying that a company's disaster recovery plan is not just written down but actually tested quarterly. They check whether the test results are documented, whether the company fixed problems found in the last test, and whether the recovery time claimed in the plan matches what actually happened. They then write a report saying either "this control is working" or "this control has gaps" and recommend fixes.

CISAs also help companies prepare for audits by external regulators. If a bank is about to face a Federal Reserve examination, the CISA might run similar tests beforehand to find problems the regulators would find. This is called an internal audit and is a major part of the job at regulated companies.

The five domains you study to pass the CISA exam

The exam covers five areas that map to what CISAs actually do. IT audit processes covers how to plan an audit, gather evidence, and write findings — the mechanics of the job. Governance and management of IT covers how companies should organize their IT function, set policies, and make decisions about technology investments. Information systems acquisition and implementation covers how to audit the process of buying or building new systems to make sure security is built in from the start, not bolted on later.

Information systems operations and business resilience covers day-to-day IT operations, backups, disaster recovery, and how to keep systems running when something goes wrong. Protection of information assets covers security controls, encryption, access management, and how to protect data from theft or loss. Each domain makes up roughly 20 percent of the exam, and you need to pass all five to earn the credential.

The exam is offered year-round at testing centers and costs around $760 to take. You have four hours to answer 150 multiple-choice questions. Most people study for two to four months using study guides, practice exams, and sometimes paid courses. ISACA publishes an official study guide, and third-party vendors like Udemy and Pluralsight offer video courses.

Who hires CISAs and what they pay

Large banks, insurance companies, healthcare systems, and government agencies are the biggest employers of CISAs. These industries face heavy regulation and need constant proof that their controls work. A bank might have 20 or 30 CISAs on staff. A mid-size company might have one or two. Small companies usually contract with an audit firm instead of hiring in-house.

Audit firms like Deloitte, EY, and KPMG employ many CISAs and assign them to clients. This path offers variety — you work with different companies and systems — but also travel and long hours during busy seasons. In-house CISAs at large companies have more stability and usually better work-life balance, but less variety in what they audit.

Salary varies by location, employer, and experience. A CISA with five years of experience in a mid-size city might earn $90,000 to $110,000. The same person in New York or San Francisco might earn $120,000 to $140,000. Financial services and healthcare pay more than other industries. Government CISAs typically earn less than private sector peers but have better benefits and job security.

How the CISA credential compares to other IT security certifications

The CISA is different from security certifications like the Certified Ethical Hacker (CEH) or Certified Information Security Manager (CISM). A CEH teaches you to find security vulnerabilities by attacking systems — it is a hands-on technical skill. A CISM is about managing a security program and reporting to executives — it is more strategic. A CISA is about auditing and verifying that controls work — it is about independent assessment and compliance.

If you want to build security defenses, pursue the CEH or CompTIA Security+. If you want to lead a security team, pursue the CISM. If you want to audit and verify that security is working, pursue the CISA. Many people earn more than one — a CISA might also hold a CISM if they move into a leadership role, or a CEH if they want to understand both attack and defense.

The CISA is also more expensive and time-consuming to earn because of the five-year experience requirement. You cannot get it straight out of school. You need years of work in IT audit, security, or operations first. This makes it a mid-career credential, not an entry-level one.

Whether you should pursue a CISA

Pursue a CISA if you work in IT audit, compliance, or security and want to move up or earn more. It is also the right choice if you work at a regulated company and want to understand how audits work from the inside. The credential opens doors at audit firms, large banks, insurance companies, and government agencies — all stable employers with good benefits.

Do not pursue a CISA if you want to work in hands-on security roles like penetration testing or incident response. Do not pursue it if you are early in your IT career and have less than two years of experience — you will not meet the requirement for several years. Do not pursue it if you work at a small company that does not do formal audits — the credential will not help you there.

The exam itself is not extremely difficult if you have audit or security experience. Most people who study for two to four months and have relevant work experience pass on the first try. The real barrier is the five-year experience requirement, which means you need to plan ahead and build the right background first.

How to build experience before taking the CISA exam

Start by working in IT audit, IT security, IT operations, or IT compliance. These roles all count toward the five-year requirement. At a bank or insurance company, an IT auditor or compliance analyst role is ideal. At an audit firm, an audit associate or junior auditor role counts. At a company without a formal audit function, a security analyst or IT operations role can count if you document the relevant work.

While building experience, take the CompTIA Security+ or similar entry-level security certification. This teaches you the fundamentals and shows employers you are serious. Read ISACA's official study guide even before you are ready to test — it will help you understand what auditors do and what to look for in your current role. Join ISACA as a member (around $200 per year) to access resources and networking events.

After four years of relevant experience, you can sit for the exam even if you have not completed the full five years. You will earn the CISA-in-progress credential, and it becomes a full CISA once you complete the fifth year. This is a common path — people test after four years and then earn the full credential a year later.

Frequently Asked Questions

Do I need a college degree to become a CISA?

No. ISACA requires five years of work experience in IT audit or a related field, but does not require a degree. However, if you have a bachelor's degree in a relevant field like computer science or information systems, you can substitute one year of education for one year of experience, reducing the requirement to four years of work.

How long does it take to study for the CISA exam?

Most people study for two to four months if they have relevant work experience. If you are new to audit or security, you might need four to six months. The exam covers a lot of ground, but the questions test understanding rather than memorization. Study guides, practice exams, and video courses are all available.

Can I work as a CISA without the credential?

Yes. Many people do IT audit work without the CISA. However, the credential is required or strongly preferred for most jobs at large companies and audit firms. It signals that you have met a standard and passed an independent exam. Without it, you may be limited to smaller companies or entry-level roles.

What happens after I earn the CISA?

You must renew it every three years by earning continuing education credits. ISACA requires 120 credits per three-year cycle, which works out to 40 credits per year. You earn credits by taking courses, attending conferences, writing articles, or teaching. Most employers support this through training budgets.

Is the CISA worth the time and cost?

If you want to work in IT audit or compliance at a large regulated company, yes. The credential is widely recognized and often required for advancement. If you work at a small company or in a hands-on security role, it may not be worth the effort. Consider your career goals and whether audit work aligns with what you want to do.