Below are the key domains, subtopics and tasks candidates will be tested on:
Providing audit services in accordance with standards to assist organizations in protecting and controlling information systems. Domain 1 affirms your credibility to offer conclusions on the state of an organization’s IS/IT security, risk and control solutions.
Domain 2 confirms to stakeholders your abilities to identify critical issues and recommend enterprise-specific practices to support and safeguard the governance of information and related technologies.
Domains 3 and 4 offer proof not only of your competency in IT controls, but also your understanding of how IT relates to business.
Cybersecurity now touches virtually every information systems role, and understanding its principles, best practices and pitfalls is a major focus within Domain 5.
wd40 said: I am CISA certified and have 0 IT Audit experience.[...]This was in 2015.
JDMurray said: wd40 said: I am CISA certified and have 0 IT Audit experience.[...]This was in 2015. This is truly a shame on ISACA's part. There was a time when the vetting was quite rigorous. This reminds me of the (ISC)2 saying that a candidate was acceptable for the full SSCP certification because they had spent one year in a help desk role resetting user's passwords. That's hardly security experience, but at least it was something. But "zero" IT audit experience qualifies for a well-known, well-respected IT auditing cert? Hmmm...