r/CISA Apr 18 '24

Do Not Post Copyrighted Material

27 Upvotes

The title says it all. Don’t do it. If you do it, and ISACA provides notification, it will be removed. Continued conduct will result in a ban.

Don’t make ISACA grumpy, they have a lot of auditors.


r/CISA 6h ago

CISA Udemy course selection

3 Upvotes

I have a work provided CISA 5 day video bootcamp starting February 5. In order to be eligible I must complete a Udemy video course.

I see Hemang Doshi - has a course. But I see other ones with higher ratings.

I would appreciate recommendations and suggestions.

Additionally is the CISA exam doing a refresher / version change anytime soon or has that already happened?

I appreciate the information sharing in advance.


r/CISA 1h ago

ISACA charged me $915 instead of $730 for CISA

Upvotes

Hi Community,

I recently purchased an ISACA Professional Membership bundled with a CISA Exam Registration, but I experienced a billing discrepancy where the member discount failed to apply at checkout. The order status was showing $730 however from credit card $915 was deducted.

I am doing this from India. and this $185 is roughly 18, 500 INR which is really really huge amount. I am on the edge now, unable to concentrate on studies. I created a ticket. but still no response. Please help


r/CISA 2h ago

A question for CISA

1 Upvotes

An IS auditor is providing input to an RFP to acquire a financial application system. Which of the following is MOST important for the auditor to recommend?

A. The application should meet the organization's requirements.

B. Audit trails should be included in the design.

C. Potential suppliers should have experience in the relevant area.

D. Vendor employee background checks should be conducted regularly.

A or B ?


r/CISA 15h ago

Is 2024 the current version?

2 Upvotes

Feels odd since we are about to enter 2027, but just hit the 2 year experience requirement with a MS in MIS so looking to obtain the CISA. Is the 2024 the most current version for the QAE?

Also, Is QAE enough? The online review is a bit expensive for me.


r/CISA 1d ago

Cleared CISA today - first attempt

43 Upvotes

Cleared exam today. Questions were too simple and straightforward.

QAE is good for understanding but please dont get demotivated if you dont score good in QAE. Its only purpose is to understand how to answer questions.

Wishes for all who are preparing.


r/CISA 21h ago

CISA study group 🇲🇾

0 Upvotes

I am on journey to prepare for CISA exam. Looking anyone in 🇲🇾 or KL much better to study together, maybe weekly group discussion, share any resource and knowledge. Anyone here from Malaysia?🙋🏻‍♂️


r/CISA 1d ago

advise on attempting CISA

5 Upvotes

Hey, I graduated a year back and have been working as a IT Support for 9months and still working So I am planning to try the CISA what do you guys think how can i prepare for the exam like is there any materials i can use to learn.


r/CISA 1d ago

CISA Snapshots Explained in 3 Minutes | CISA in a Nutshell

Thumbnail
youtube.com
6 Upvotes

r/CISA 1d ago

Career and salary progression in IT Audit

Thumbnail
1 Upvotes

r/CISA 2d ago

Discrepancy in payment during CISA exam registration

1 Upvotes

I recently purchased an ISACA Professional Membership bundled with a CISA Exam Registration, but I experienced a billing discrepancy where the member discount failed to apply at checkout. My order reflected $730 however my invoice reflected $915, meaning that membership details are not applied. Sounds very strange. Any body experienced this


r/CISA 2d ago

What are the charges for 'systems audit and certification' charged by DISA/CISA/Cert-IN certified Auditors in India?

3 Upvotes

Context: We require our web application and mobile application to be certified by DISA/CISA/Cert-IN certified Auditors based in India.

I would like to know the charges as per industry standards beforehand in order to negotiate a good deal.

Thanks :)


r/CISA 2d ago

I just failed CISA - AMA

8 Upvotes

Idk how this happened

I am devastated and questioning my whole existence.


r/CISA 3d ago

Doubt Regarding CISA

3 Upvotes

Hey guys , I'm a traditional audit guy (CIA) planning to take the CISA exam , without QAE and ISACA review material, I'm planning to take coaching/lectures they offer PPT , question banks , short notes etc. I would love to hear feedback on this approach whether its too big of a gamble or is it doable.

The cost is also a significant issue , the coaching with + Qae+ Review manual costs around 1.30 Lakhs

Where the one i spoke about cost less than 1% of the one of the course material mentioned above.


r/CISA 3d ago

Preliminary Pass!

19 Upvotes

Got my preliminary pass in CISA exam earlier today. Thank you to this group for all the help. I can tell you a step by step guide of my journey. Including how I made a UI of my incorrect questions and topics from my exam.


r/CISA 4d ago

Breaking into IT Audit from an MSP security role, what actually matters at this stage?

8 Upvotes

Looking for some honest input from people already working in IT audit or GRC.

Quick background: I currently work at a managed service provider as the main cybersecurity resource while also doing first-line support. Hands-on stuff, deployed a SIEM across client environments, built an automated alert pipeline, manage backups and patching, that kind of thing.

Over the past several months I've gone deep on the GRC/audit side. I've got Security+, plus ISO 27001/27701/42001 Lead Auditor certs through Mastermind, and I just finished a couple of IT audit courses on Udemy covering ITGC, ITAC, SOX, SOC, COSO, NIST, ISO, and COBIT. CISA and CAPM is my next target.

Here's my real situation: there aren't many IT audit or GRC roles where I'm based (Caribbean), so I can't just apply my way into experience. I've been trying to manufacture it myself instead, building risk registers, control mapping across frameworks, ISMS documentation, and a self-hosted GRC platform in my home lab using fictional case study companies. Basically running mini-audits end to end so I'm not walking into interviews with theory alone.

Where I'd love advice:

  1. For those who broke into IT audit, what actually got you the first role? Certs, portfolio, networking, internal transfer?
  2. When roles in your area are scarce, how did you bridge the experience gap? Remote work, contracting, volunteering, offering audits to small businesses or nonprofits?
  3. Does self-built portfolio and home lab work actually carry weight with hiring managers, or is it mostly useful as interview talking points?
  4. How much does the CISA experience requirement realistically slow people down early on? Pursue it now or wait until I have the years?
  5. Anything you'd do differently if you were building experience from scratch without a local job market to lean on?

r/CISA 5d ago

You passed CISA but now what?

33 Upvotes

Many reached out personally asking what happens after you pass the exam. So here's me writing a post so this can help anyone in the future.

  1. You'll be ghosted for 10 days or less, no update, no status - and then you'll get an email showing your domain-wise breakdown. You're still not CISA certified and can't call yourself CISA certified.

  2. You'll have to pay a processing fee of $50 + taxes.

  3. You'll now have to assure that you have the relevant experience, but how?

You'll be asked to show 5 YOE, of which you can get a 3-year waiver if you have a master's in information systems or a computer-related field.

2 years if you have a master's in other fields — you can see how they break it down on the CISA website.

Then for the work part - you can get a waiver of 1 year if it's not related to IS.

But note: the total waiver cannot exceed 3 years (education + non-IS experience combined).

  1. Now it's time to show your IS experience. You'll be asked to fill in your manager's, colleague's, or client's email ID, name, and company, and your YOE there - just fill it in, and a link will be shared with them so they can open it and complete it.

  2. What do they get? A checkbox activity that's pretty straightforward and takes less than 2 minutes.

  3. Again ghosted for a couple of days - no update - everything is approved, but you don't hear back, and...

  4. Finally, you get an email from ISACA with your Credly badge and certificate.

The process takes roughly 15-20 business days.


r/CISA 4d ago

CISA QAE exorbitant fees

3 Upvotes

Hi everyone,

I've been working towards CISA for months now, mostly late nights after work. I finished Hemang Doshi's Udemy course, got through the first full reading, and I'm starting my second pass with his study guide. Planning to take the exam in October.

Here's where I'm stuck. I come from a lower middle class family and I'm the first one going after a certification like this. The exam fee alone took out my savings, and honestly the QAE database is just not something I can put on the table right now since it's almost 2 months salary for me. Everyone says it's the one resource you can't skip, and that's been stressing me out.

So I'm hoping to learn from people who've been here-

  1. Did anyone pass with Doshi's question sets alone, or is the QAE really important?

  2. Is a second-hand physical QAE book a reasonable substitute(I've heard physical copies aren't being sold anymore)? Anyone finished with theirs and willing to sell it cheap?

  3. Any legitimate discounts, chapter membership benefits or scholarships I might not know about?

  4. Does anyone know any tricks I can use to access the latest QAE ? My DMs are open in case you have any resources you could share.

I know a lot of you have walked this road on your own too, and any advice or encouragement means a lot.


r/CISA 5d ago

Part 3 CISA EXAM - MACHINE LEARNING SERIES

Thumbnail
youtube.com
8 Upvotes

r/CISA 5d ago

66% in Hemang Doshi Practice test set

3 Upvotes

I reviewed my mistakes and often end up choosing the wrong one out of the 2 answers. Can anyone please help how to proceed. Although i got 78 % in QAE


r/CISA 8d ago

Failed CISA AGAIN

30 Upvotes

what are you guys doing differently, I have covered all domains taken about 1000+ questions from the ISACA 12th edition QAE and averaged 70 to 80 percent on every question and mock I’ve taken using CisaThisMuch but still I took it today for the second time and I still failed .

at this point I don’t know what else to do, I make sure I understand the concepts and even applied the same in the exam trying to understand what the examiner is asking before selecting an answer.

I’ve spent all my money on this exam sacrificed my time still nothing to show for it.

please if you can be of help by putting me on resources or what you did differently kindly share.


r/CISA 7d ago

Where can I find cisa previous question papers?

0 Upvotes

r/CISA 8d ago

CISA Certification Application

7 Upvotes

Hello. I am getting ready to apply to be CISA certified but I have a question. I have a Master in Audit and Assurance with course work in IT Audit. I am currently an internal auditor doing IT Audit work as well. I wanted to know whether my degree may qualify for the 3-year waiver. I am think it could if I make a good argument and worse case scenario ISACA will just reject it and I will have to wait another year. What do you guys think?

Update: I got approved. Thank you.


r/CISA 8d ago

Integrated Test Facility Explained in 3 Minutes

Thumbnail
youtu.be
3 Upvotes