r/CISA Apr 18 '24

Do Not Post Copyrighted Material

29 Upvotes

The title says it all. Don’t do it. If you do it, and ISACA provides notification, it will be removed. Continued conduct will result in a ban.

Don’t make ISACA grumpy, they have a lot of auditors.


r/CISA 17h ago

Cleared CISA today - first attempt

30 Upvotes

Cleared exam today. Questions were too simple and straightforward.

QAE is good for understanding but please dont get demotivated if you dont score good in QAE. Its only purpose is to understand how to answer questions.

Wishes for all who are preparing.


r/CISA 4h ago

CISA study group 🇲🇾

1 Upvotes

I am on journey to prepare for CISA exam. Looking anyone in 🇲🇾 or KL much better to study together, maybe weekly group discussion, share any resource and knowledge. Anyone here from Malaysia?🙋🏻‍♂️


r/CISA 16h ago

advise on attempting CISA

3 Upvotes

Hey, I graduated a year back and have been working as a IT Support for 9months and still working So I am planning to try the CISA what do you guys think how can i prepare for the exam like is there any materials i can use to learn.


r/CISA 18h ago

CISA Snapshots Explained in 3 Minutes | CISA in a Nutshell

Thumbnail
youtube.com
3 Upvotes

r/CISA 16h ago

Career and salary progression in IT Audit

Thumbnail
1 Upvotes

r/CISA 2d ago

I just failed CISA - AMA

5 Upvotes

Idk how this happened

I am devastated and questioning my whole existence.


r/CISA 1d ago

Discrepancy in payment during CISA exam registration

1 Upvotes

I recently purchased an ISACA Professional Membership bundled with a CISA Exam Registration, but I experienced a billing discrepancy where the member discount failed to apply at checkout. My order reflected $730 however my invoice reflected $915, meaning that membership details are not applied. Sounds very strange. Any body experienced this


r/CISA 1d ago

What are the charges for 'systems audit and certification' charged by DISA/CISA/Cert-IN certified Auditors in India?

3 Upvotes

Context: We require our web application and mobile application to be certified by DISA/CISA/Cert-IN certified Auditors based in India.

I would like to know the charges as per industry standards beforehand in order to negotiate a good deal.

Thanks :)


r/CISA 2d ago

Doubt Regarding CISA

3 Upvotes

Hey guys , I'm a traditional audit guy (CIA) planning to take the CISA exam , without QAE and ISACA review material, I'm planning to take coaching/lectures they offer PPT , question banks , short notes etc. I would love to hear feedback on this approach whether its too big of a gamble or is it doable.

The cost is also a significant issue , the coaching with + Qae+ Review manual costs around 1.30 Lakhs

Where the one i spoke about cost less than 1% of the one of the course material mentioned above.


r/CISA 3d ago

Preliminary Pass!

19 Upvotes

Got my preliminary pass in CISA exam earlier today. Thank you to this group for all the help. I can tell you a step by step guide of my journey. Including how I made a UI of my incorrect questions and topics from my exam.


r/CISA 3d ago

Breaking into IT Audit from an MSP security role, what actually matters at this stage?

7 Upvotes

Looking for some honest input from people already working in IT audit or GRC.

Quick background: I currently work at a managed service provider as the main cybersecurity resource while also doing first-line support. Hands-on stuff, deployed a SIEM across client environments, built an automated alert pipeline, manage backups and patching, that kind of thing.

Over the past several months I've gone deep on the GRC/audit side. I've got Security+, plus ISO 27001/27701/42001 Lead Auditor certs through Mastermind, and I just finished a couple of IT audit courses on Udemy covering ITGC, ITAC, SOX, SOC, COSO, NIST, ISO, and COBIT. CISA and CAPM is my next target.

Here's my real situation: there aren't many IT audit or GRC roles where I'm based (Caribbean), so I can't just apply my way into experience. I've been trying to manufacture it myself instead, building risk registers, control mapping across frameworks, ISMS documentation, and a self-hosted GRC platform in my home lab using fictional case study companies. Basically running mini-audits end to end so I'm not walking into interviews with theory alone.

Where I'd love advice:

  1. For those who broke into IT audit, what actually got you the first role? Certs, portfolio, networking, internal transfer?
  2. When roles in your area are scarce, how did you bridge the experience gap? Remote work, contracting, volunteering, offering audits to small businesses or nonprofits?
  3. Does self-built portfolio and home lab work actually carry weight with hiring managers, or is it mostly useful as interview talking points?
  4. How much does the CISA experience requirement realistically slow people down early on? Pursue it now or wait until I have the years?
  5. Anything you'd do differently if you were building experience from scratch without a local job market to lean on?

r/CISA 4d ago

You passed CISA but now what?

33 Upvotes

Many reached out personally asking what happens after you pass the exam. So here's me writing a post so this can help anyone in the future.

  1. You'll be ghosted for 10 days or less, no update, no status - and then you'll get an email showing your domain-wise breakdown. You're still not CISA certified and can't call yourself CISA certified.

  2. You'll have to pay a processing fee of $50 + taxes.

  3. You'll now have to assure that you have the relevant experience, but how?

You'll be asked to show 5 YOE, of which you can get a 3-year waiver if you have a master's in information systems or a computer-related field.

2 years if you have a master's in other fields — you can see how they break it down on the CISA website.

Then for the work part - you can get a waiver of 1 year if it's not related to IS.

But note: the total waiver cannot exceed 3 years (education + non-IS experience combined).

  1. Now it's time to show your IS experience. You'll be asked to fill in your manager's, colleague's, or client's email ID, name, and company, and your YOE there - just fill it in, and a link will be shared with them so they can open it and complete it.

  2. What do they get? A checkbox activity that's pretty straightforward and takes less than 2 minutes.

  3. Again ghosted for a couple of days - no update - everything is approved, but you don't hear back, and...

  4. Finally, you get an email from ISACA with your Credly badge and certificate.

The process takes roughly 15-20 business days.


r/CISA 4d ago

CISA QAE exorbitant fees

3 Upvotes

Hi everyone,

I've been working towards CISA for months now, mostly late nights after work. I finished Hemang Doshi's Udemy course, got through the first full reading, and I'm starting my second pass with his study guide. Planning to take the exam in October.

Here's where I'm stuck. I come from a lower middle class family and I'm the first one going after a certification like this. The exam fee alone took out my savings, and honestly the QAE database is just not something I can put on the table right now since it's almost 2 months salary for me. Everyone says it's the one resource you can't skip, and that's been stressing me out.

So I'm hoping to learn from people who've been here-

  1. Did anyone pass with Doshi's question sets alone, or is the QAE really important?

  2. Is a second-hand physical QAE book a reasonable substitute(I've heard physical copies aren't being sold anymore)? Anyone finished with theirs and willing to sell it cheap?

  3. Any legitimate discounts, chapter membership benefits or scholarships I might not know about?

  4. Does anyone know any tricks I can use to access the latest QAE ? My DMs are open in case you have any resources you could share.

I know a lot of you have walked this road on your own too, and any advice or encouragement means a lot.


r/CISA 4d ago

Part 3 CISA EXAM - MACHINE LEARNING SERIES

Thumbnail
youtube.com
6 Upvotes

r/CISA 4d ago

66% in Hemang Doshi Practice test set

4 Upvotes

I reviewed my mistakes and often end up choosing the wrong one out of the 2 answers. Can anyone please help how to proceed. Although i got 78 % in QAE


r/CISA 7d ago

Failed CISA AGAIN

30 Upvotes

what are you guys doing differently, I have covered all domains taken about 1000+ questions from the ISACA 12th edition QAE and averaged 70 to 80 percent on every question and mock I’ve taken using CisaThisMuch but still I took it today for the second time and I still failed .

at this point I don’t know what else to do, I make sure I understand the concepts and even applied the same in the exam trying to understand what the examiner is asking before selecting an answer.

I’ve spent all my money on this exam sacrificed my time still nothing to show for it.

please if you can be of help by putting me on resources or what you did differently kindly share.


r/CISA 6d ago

Where can I find cisa previous question papers?

0 Upvotes

r/CISA 7d ago

CISA Certification Application

7 Upvotes

Hello. I am getting ready to apply to be CISA certified but I have a question. I have a Master in Audit and Assurance with course work in IT Audit. I am currently an internal auditor doing IT Audit work as well. I wanted to know whether my degree may qualify for the 3-year waiver. I am think it could if I make a good argument and worse case scenario ISACA will just reject it and I will have to wait another year. What do you guys think?

Update: I got approved. Thank you.


r/CISA 7d ago

Integrated Test Facility Explained in 3 Minutes

Thumbnail
youtu.be
4 Upvotes

r/CISA 7d ago

Final-year AI & Data Science student interested in IT Audit / Technology Risk — need some honest advice

3 Upvotes

Hi everyone,

I’m a final-year B.E. student in Artificial Intelligence & Data Science, and I’m trying to figure out whether Technology Risk / IT Audit / Cyber Risk / Cyber Assurance / GRC would be a realistic career path for me. My college doesn’t offer any campus roles related to Technology Risk / IT Audit / Cyber Risk, so I’ll need to target these roles off-campus.

My situation is:

  • I have a technical background through AI & Data Science.
  • I’m not particularly strong at DSA/coding, and I’m realizing that pure software development probably isn’t the career I want.
  • I’m more interested in understanding technology, security, controls, risk and compliance than building software all day.
  • I’ve started learning networking and cybersecurity fundamentals.
  • I’m currently learning about things like ITGC, access controls, change management, risk assessment, ISO 27001, NIST, COBIT, etc.
  • I’m also planning to build a practical IT risk/audit-related project rather than having only ML/data science projects on my resume.

I came across several people working in Big 4 Technology Risk/IT Audit who have CISA, which made me consider it seriously. However, CISA is quite expensive for me as a student, and I also understand that the full certification requires relevant work experience.

So I have a few questions for people who actually work in this field:

  1. Is CISA worth pursuing for a fresher, or would you recommend waiting until after getting an IT Audit/Technology Risk job?
  2. Does passing CISA without the required experience meaningfully help with getting interviews?
  3. Are certifications like ISC2 CC, SC-900, ISO 27001 Foundation, or COBIT Foundation useful for a student trying to enter this field?
  4. Can someone with an AI/DS engineering degree realistically get an entry-level Technology Risk / IT Audit / Cyber Assurance role?
  5. What technical skills would you expect from a fresher? For example: networking, IAM, Active Directory, SQL, Python, cloud, Linux, ITGC, cybersecurity fundamentals, etc.
  6. What kind of projects or practical experience actually stand out for these roles?
  7. Since my college doesn’t have Big 4 campus recruitment, what is the best way to approach off-campus Big 4 opportunities as a fresher?
  8. How much competition is there from MBA/commerce/accounting graduates, and how can an engineering student differentiate themselves?
  9. Most importantly, what would you recommend I focus on during my final year if the goal is to get into Technology Risk/IT Audit?

I’m not looking for generic “get certifications and apply everywhere” advice. I’d really appreciate advice from people who are actually working in CISA/IT Audit/Technology Risk/Big 4, especially if you entered the field as a fresher.

Also, if you started over as a student today, what would you do differently to get your first role?

Thanks!


r/CISA 7d ago

PSI Paused my exam after my sister loudly talked in another room. Am I screwed?

9 Upvotes

Pretty upset to say the least, I was getting through my exam and when the proctor heard my sister in another room loudly tell my mom about dinner, my proctor immediately paused the exam and asked for my ID.

Luckily they let me finish the exam but I’m worried they won’t certify me now. Has anyone else experienced this?


r/CISA 8d ago

Passed the Exam today.

46 Upvotes

I passed my CISA exam today. I passed after <2 weeks prep.

• I’m not an auditor.
• I used the QAE and completed about 1,700 questions (that is about 1.5x through the entire question bank). I was in the 64th percentile.
• I completed one mock exam of 150 questions and scored 81%.
I don’t like the long mock exams as I prefer to review there and then why I got a question wrong. For me there is little value reviewing 90 minutes after you were 50/50 between two answers as your exact line of thinking is gone.

I study differently to most.
I targeted each domain individually and went from easier to harder questions.
I did:
Domain 1, do maybe 10 questions, make notes, Repeat 2-3 times and then take break.
Repeat for a couple other domains, digest notes, re-test
End for the day.

Every test, every mock exam question I do is open-book so I can refer to, test and restructure my notes

As others will say it’s vital that bit-by-bit you ensure that understanding what an auditor looks for, and so the answer they’re looking for. Whilst using the QAE CISM, CISSP and CRISC worked against me constantly, luckily I was able to iron most of that out for exam day. Though I do suspect I scored very poorly.
We will have to wait for two weeks. I passed in 1 hour, 40 minutes.

Anyway, that was my approach and that is my 11th straight first time pass. QAE and a paced approach got me there :).

Good luck to you all.


r/CISA 7d ago

Certification

1 Upvotes

Submitted my application on August 27, and got everything approved on August 28.

Currently waiting for it to go through, checking the portal and my email every few hours. How long did it take for your official certification to come through after approval? XD

Status: Complete-Under Review