Exam Candidate Guide Continuous Testing
Exam Candidate Guide Continuous Testing
Exam Candidate Guide Continuous Testing
Candidate Guide
Table of Contents
Candidate Guide Overview ...................................................................................................... 1
Section I: Introduction ............................................................................................................. 2
1.1 - ISACA Overview and Code of Ethics.............................................................................. 2
1.2 - ISACA Certification Program Summary .......................................................................... 4
Section II: Exam Registration and Scheduling ...................................................................... 6
2.1 - Before You Register ....................................................................................................... 6
2.2 - Registering for the Exam ................................................................................................ 6
2.3 - Scheduling the Exam Appointment ................................................................................ 9
Section III - Exam Preparation ................................................................................................10
3.1 - Getting Ready for the Exam ..........................................................................................10
3.2 - Exam Day Rules ...........................................................................................................12
3.3 - Exam Administration .....................................................................................................14
Section IV - After the Exam ....................................................................................................15
4.1 - Exam Scoring................................................................................................................15
4.2 - Retake Policy ................................................................................................................16
4.3 - Post Exam Feedback ....................................................................................................16
4.4 - Certification ...................................................................................................................17
APPENDIX A ............................................................................................................................19
ISACA Certification Exam Terms and Conditions ..................................................................19
APPENDIX B ............................................................................................................................20
Candidate Security Agreement..............................................................................................20
1
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Section I: Introduction
Section Topic Page
1.1 ISACA Overview and Code of Ethics 2
1.2 ISACA Certification Programs Summary 4
1.1 - ISACA Overview and Code of Ethics
Now in its 50th year, ISACA is a pace-setting, global association helping
individuals and enterprises achieve the positive potential of technology.
ISACA equips professionals with the knowledge, credentials, education
and community to advance their careers and transform their organizations.
ISACA leverages the expertise of its 460,000 engaged professionals in information and cybersecurity,
governance, assurance, risk and innovation, as well as its enterprise performance subsidiary, CMMI®
Institute, to help advance innovation through technology.
ISACA has a presence in 188 countries, including more than 220 chapters worldwide and offices in
both the United States and China.
ISACA Products and Services
Membership:
Being an ISACA member gives you access to exclusive member benefits including savings on ISACA
products like Certification Exams, Conferences and Exam Prep materials.
Knowledge & Insights:
Explore the latest research, guidance and expert thinking on standards, best practices and emerging
trends.
Training:
ISACA's globally respected training and certification programs inspire confidence that enables
innovation in the workplace and career progression.
Cybersecurity NexusTM (CSX)
Enhance your expertise. Advance your career. Quickly find the ISACA training solutions that are right
for your needs, goals, study preferences and availability.
COBIT 2019®
ISACA’s legacy framework for customizing and right-sizing enterprise governance of information and
technology.
2
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Certificate Programs
• COBIT 2019 Foundations
• COBIT 2019 Design and Implementation
• Cybersecurity Audit
• CSX Technical Foundations
• Cybersecurity Fundamentals
Certification Programs
Code of Ethics
ISACA sets forth a Code of Professional Ethics to guide the professional and personal conduct of its
members and/or certification holders.
• Members and those certified are required to abide by ISACA’s Code of Professional Ethics.
• Failure to comply can result in an investigation and, ultimately, disciplinary measures.
3
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Designed for IT/IS auditors, Designed for those Designed for those who CGEIT recognizes a wide
control, assurance and experienced in the manage, design, range of professionals for
Description information security management of IT risk and oversee and assess an their knowledge and
professionals. the design, implementation, enterprise’s information application of enterprise IT
monitoring and maintenance security function. governance principles and
of IS controls. practices.
Five (5) or more years of Three (3) or more years of Five (5) or more years of Five (5) or more years of
experience in IS/IT audit, experience in IT risk experience in experience in an advisory
control, assurance, or management and IS control. information security or oversight role
security. management. supporting the governance
Eligibility No experience waivers or of the IT-related
Requirements Experience waivers are substitutions Experience waivers are
available for a maximum contribution to an
available for a maximum of enterprise.
three (3) years. of two (2) years.
No experience waivers or
substitutions
4
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Exam Questions
All certification exams consist of 150 multiple choice questions that cover the respective job practice
areas created from the most recent job practice analysis.
Candidates have up to 4 hours (240 minutes) to complete the exam.
Exam Fees
Exam registration fees are based on membership status at the time of exam registration.
• ISACA Member: US $575
• ISACA Nonmember: US $760
Exam registration fees are non-refundable and non-transferrable.
Resources
Below are some useful links and resources to help exam candidates learn more about ISACA
Certification exams.
CISA Certification
• CISA Certification Overview
• CISA Requirements
• CISA Job Practice
CRISC Certification
• CRISC Certification Overview
• CRISC Requirements
• CRISC Job Practice
CISM Certification
• CISM Certification Overview
• CISM Requirements
• CISM Job Practice
CGEIT Certification
• CGEIT Certification Overview
• CGEIT Requirements
• CGEIT Job Practice
5
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Please note, during the exam registration process you will be required to accept ISACA’s exam
candidate terms and conditions (Appendix A), including the conditions set forth in this Candidate Guide
covering exam administration, certification rules, and the release of test results.
For step-by-step instructions on completing your online registration, please refer to the How to Register
Guide.
Candidates cannot schedule a testing appointment until exam registration fees are paid in full.
Exam fees are non-refundable and non-transferrable.
6
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Registration Acknowledgement
You will receive a Notification to Schedule email within one (1) business day following registration
and payment of the exam.
The Notification to Schedule email provides information on scheduling your exam appointment.
Registering for the Exam with Special Accommodations
Special testing accommodations must be requested during the registration process and approved by
ISACA before scheduling the exam.
To request special testing accommodations please follow the steps below:
Step Action
1. During the exam registration process, make sure to mark the special accommodation
requirement field.
2. Print the Special Accommodation Request Form.
3. Complete the ISACA Special Accommodation Request Form.
Note: Form must be completed by you and your health care professional.
4. Submit form to ISACA at https://isaca.force.com/support/s/contactsupport.
Special accommodation requests will not be considered until exam registration fees are paid in
full. All requests must be submitted to ISACA no later than 4 weeks prior to your preferred exam
date and are only valid for that one exam administration.
7
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Registration Changes
There are three common registration changes that candidates request. Refer to the table below.
Type of Change Steps
Name 1. Log in to https://www.isaca.org.
2. Click the MyISACA tab.
3. Click the myProfile>Account-Address-Demographic Info tab.
4. Click the Edit button at the bottom of the profile to make your changes.
5. Click Save.
Exam 1. Login at https://www.isaca.org/myisaca.
Language 2. Click myCertifications.
3. Click the “Re-Schedule or Cancel Exam” URL in the Pre-Certification
Summary section to proceed to PSI’s scheduling page
4. Follow the on-screen instructions to schedule your testing. appointment.
The How to Schedule Guide is available to help you schedule and
reschedule.
Note: If you need to change your exam language, you also must
reschedule the testing appointment. See Rescheduling an Exam
for details.
All change requests must be completed a minimum of 48 hours prior to your scheduled testing
appointment.
Security Agreement
You are required to agree to ISACA’s Candidate Security Agreement by signing an agreement
statement online prior to your exam launch at the testing center. The Candidate Security Agreement is
located on the last page of this guide (APPENDIX B) for your advance review prior to exam day.
8
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
You will receive a confirmation email from [email protected] confirming your exam appointment.
Please view the How-to-Schedule Guide for additional scheduling assistance.
Rescheduling an Exam
You can reschedule your exam anytime, without penalty, during your eligibility period if done a
minimum of 48 hours prior to your scheduled testing appointment.
If you are within 48 hours of your scheduled testing appointment, you must take the exam or
forfeit the registration fee. To reschedule an appointment: Log in into your MyISACA Account
and click MyCertification.
Emergency Closing
Severe weather or an emergency could require canceling scheduled exams. If this occurs, PSI will
attempt to contact you by phone or email; however, ISACA suggests that you check for test center
closures by referencing www.psiexams.com. If the site is closed, the exam will be rescheduled without
a rescheduling fee.
9
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
10
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Before You Arrive at the Exam
Make sure you are prepared before the day of the exam by doing the following:
• Locate the test center address and confirm the start time.
• Map out your route to the testing center.
• Plan to arrive at least 15 minutes prior to the exam start time.
• Plan to store your personal belongings.
*See the Exam Day Rules for more information.
Identification Requirements
To enter the testing center, you must present an acceptable form of identification (ID).
An acceptable form of ID must be a current and original government-issued ID that contains:
• Candidate’s name (as it appears on the Notification to Schedule email from ISACA)
• Candidate’s signature
• Candidate’s photograph
All information must be demonstrated by a single form of ID (cannot be a copy or handwritten).
Any candidate who does not provide an acceptable form of ID will not be allowed to sit for the
exam and will forfeit his/her registration fee.
Acceptable Forms of Identification
Acceptable forms of identification include:
• Driver’s license
• State identity card (non-driver’s license)
• Passport
• Passport card
• Military ID
• Green card
• Alien registration
• Permanent resident card
• National identification card
The testing center reserves the right to ask for additional forms of identification for verification
purposes. If there is any doubt surrounding your identity, you will be turned away from the test
and ISACA will be notified. This will be considered a no-show and you forfeit your exam fees.
To take the test in the future, you will be required to re-register and pay the exam fee again.
11
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
12
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Personal Hardship Guidelines
If you fail to arrive for a testing appointment due to a personal hardship you may be able to reschedule
without forfeiting your exam registration fee.
Step Action
1. Contact PSI* no later than 72 hours following the scheduled appointment.
If the request is denied, you are required to register again and pay the full exam registration fee.
13
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Leaving the Testing Center
You must gain authorization from the test proctor to leave the testing center.
Reason for leaving: Directions:
An emergency • The exam will be paused temporarily.
• Once it is confirmed as an emergency, the test will end.
To use the facilities • You will be required to check out and check back in.
• The exam time will not stop, and no extra time will be permitted.
Consequences
If you violate the Exam Day Rules or engage in any kind of misconduct you may be subject to the
following:
• Dismissal or disqualification
• Voiding of exam
• Revocation of ISACA membership and any certifications currently held
• Banned from taking any ISACA exam
• Legal ramifications
Proctors in PSI testing kiosks use 3 digital cameras, an on-screen chat and microphone to
communicate with you. Proctors can pause the exam whenever unauthorized persons or activity are
detected on any of the video or audio.
You are expected to protect the security of the exam and maintain the validity of the scores as stated in
the Candidate Security Agreement (APPENDIX B).
You can compare experiences. Visit: Compare Exam Experiences.
There are also YouTube videos to watch to get familiar with each exam experience:
• Visit: PSI Testing Center Location Experience Video
Your exam may be administered in a room with other test takers. Please note that some noise should
be expected and is considered normal.
14
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
15
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
ISACA does not reissue scores based on question updates. Our subject matter experts use
these comments to improve future examinations.
16
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
4.4 - Certification
How to become Certified
Taking and passing an ISACA certification exam is just the first step in becoming certified.
To become certified, an individual must first meet the following requirements:
Step Action
1. Successfully pass the Certification Exam.
2. Submit an application to demonstrate the experience requirements.
3. Adhere to the Code of Professional Ethics.
4. Adhere to the Continuing Professional Education Program.
Candidates have (5) five years from passing the exam to apply for certification.
Additional resources are included below for more information about becoming certified.
CISA
1. Successful completion of the CISA examination
2. Submit the Application for CISA Certification
3. Adherence to the Code of Professional Ethics
4. Adherence to the Continuing Professional Education Program
5. Compliance with the Information Systems Auditing Standards
CRISC
1. Successful completion of the CRISC examination
2. Submit the Application for CRISC Certification
3. Adherence to the Code of Professional Ethics
4. Adherence to the Continuing Professional Education (CPE) Policy
CISM
1. Successfully pass the CISM exam
2. Submit the Application for CISM Certification
3. Adhere to ISACA's Code of Professional Ethics
4. Agree to comply with the Continuing Education Policy
CGEIT
1. Successfully pass the CGEIT Exam
2. Submit the Application for CGEIT Certification
3. Adhere to ISACA’s Code of Professional Ethics
4. Adhere to the Continuing Professional Education (CPE) Policy
17
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
Why certify?
ISACA certifications are globally accepted and recognized. They combine the achievement of passing
an exam with credit for your work and educational experience, giving you the credibility, you need to
move ahead in your career. Certification proves to employers that you have what it takes to add value
to their enterprise. In fact, many organizations and governmental agencies around the world require or
recognize ISACA’s certifications.
Independent studies consistently rate ISACA’s designations among the highest paying IT and impactful
certifications that an IT professional can earn. Earning and maintaining an ISACA certification:
• Boosts your earning potential.
• Counts in the hiring process.
• Enhances your professional credibility and recognition.
• See special recognitions for more information.
ANSI Accredited
• ISACA Certifications are ANSI accredited.
• The American National Standards Institute (ANSI) has accredited the CISA, CRISC, CISM and
CGEIT certifications under ISO/IEC 17024:2012, General Requirements for Bodies Operating
Certification Systems of Persons.
• Accreditation by ANSI signifies that ISACA’s procedures meet ANSI’s essential requirements for
openness, balance, consensus, and due process.
• With this accreditation, ISACA anticipates that significant opportunities for CISAs, CRISCs,
CISMs and CGEITs will continue to present themselves around the world.
ANSI Accredited Program
PERSONNEL CERTIFICATION #0694
ISO/IEC 17024
CISA, CISM, CGEIT and CRISC Program Accreditation
Renewed Under ISO/IEC 17024:2012
• ANSI is a private, nonprofit organization that accredits other organizations to serve as third-
party product, system, and personnel certifiers.
• ISO/IEC 17024 specifies the requirements to be followed by organizations certifying individuals
against specific requirements.
ANSI describes ISO/IEC 17024 as “expected to play a prominent role in facilitating global
standardization of the certification community, increasing mobility among countries, enhancing
public safety and protecting consumers.”
18
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
APPENDIX A
ISACA Certification Exam Terms and Conditions
1. I have read and agree to the conditions set forth in the ISACA Certification Exam Guide,
including ISACA exam management, ISACA Code of Ethics, certification rules, policies and
procedures, and the release of test results.
2. I understand that if false or misleading information is provided, or if the test rules, policies or
procedures are violated, the test will be disqualified, the test results will be cancelled, or ISACA
will take other measures as appropriate, including but not limited to prohibiting me from taking
exams or applying for ISACA certification in the future. I understand that as a participant in the
certification exam, I will be solely responsible for the complaints I file and bear the relevant
expenses.
3. I hereby agree and warrant that ISACA and its officers, supervisors, invigilators, members,
employees, agents and ISACA's affiliates and licensors will not be liable for any complaints,
claims or other losses caused by any of ISACA’s acts or omissions, or any acts or omissions
related to my registration for the exam.
4. I understand that ISACA will have the final and sole authority to decide whether or not I pass the
ISACA exam. In addition, I understand that ISACA will inform its local branches of my passing of
ISACA exams or may inform related parties of my test results as required by law.
5. I agree that in the event of a lawsuit related to an exam registration or an ISACA exam, the
lawsuit must be filed with the Court of Circuit, Cook County, Illinois, USA, and must be decided
in accordance with the laws of the State of Illinois, USA.
6. Upon participating in the ISACA exam, I understand and agree that the ISACA exam (including
all aspects related to the exam, including but not limited to questions, answers, examples, and
other information that appear or are included in the exam) belongs to ISACA and constitutes
ISACA's confidential information (collectively referred to as "confidential information"). I agree to
keep all confidential information of ISACA confidential and understand that failure to do so may
result in ISACA’s disciplinary action against me or other adverse consequences, including but
not limited to my own exam void and loss of certification and/or litigation. Specifically, I
understand that I should not discuss, post or share any test questions, my answers or exam
forms with anyone through any forum or media (e.g., email, Facebook, LinkedIn, or any other
social media).
7. I understand that my information will be used to complete the application or for other purposes
as described in the ISACA Privacy Policy. Should you be granted certification, you will receive
an electronic badge from ISACA.
8. By signing below, I authorize ISACA to contact me at the address and phone number provided. I
further declare that the information provided is true and accurate. To learn more about how
ISACA uses the information you provide in this form, please read our Privacy Policy at
www.isaca.org/privacy.
19
® 2019 ISACA. All Rights Reserved.
ISACA Certification Exams
Candidate Guide
APPENDIX B
Candidate Security Agreement
THIS IS A LEGAL AGREEMENT BETWEEN YOU AND ISACA. BY PROCEEDING TO TAKE THE EXAM YOU
ARE ACCEPTING THIS AGREEMENT, AND HEREBY AGREE THAT THE FOLLOWING TERMS AND
CONDITIONS SHALL GOVERN YOUR PARTICIPATION IN AN ISACA/PSI TEST ADMINISTRATION. IF YOU
DO NOT OR CANNOT AGREE TO THE TERMS CONTAINED HEREIN, THEN DO NOT ACCEPT THESE
TERMS AND DO NOT CONTINUE WITH THE EXAM. IF YOU DO NOT AGREE TO BE BOUND BY THIS
AGREEMENT YOU WILL BE ASKED TO LEAVE BEFORE THE EXAM CAN COMMENCE. I HAVE READ THE
FOLLOWING ISACA/PSI LEGAL AGREEMENT, UNDERSTAND THAT THE CONTENT OF THIS ISACA EXAM
IS PROPRIETARY AND STRICTLY CONFIDENTIAL INFORMATION, AND CONSENT TO TAKE THE
EXAMINATION UNDER THE CONDITIONS STATED HEREIN:
• I hereby acknowledge that:
- I do not have in my possession any study material, notes, not pads, cell phone(s), recording
device(s), and any other electronic device(s) while in the testing area.
- I will not copy, photograph, or remove exam questions or answers in any manner from the test area.
- I will not sell, license, distribute, exchange, give away, comment on or discuss, either directly or
indirectly, any question or any part of any question from this ISACA exam to any person or entity
before, during or after this ISACA exam. This includes publication or sharing of ISACA exam
questions, answers or thoughts on any questions or the exam's format in any live or online forum or
media (i.e., via email, Facebook, LinkedIn, online communities or other social media applications).
- I will not give or receive assistance while taking this ISACA exam, including the use of unauthorized
study material or unauthorized notes.
- I will inform the proctor when needing to use the rest room, but I understand that leaving the building
at any time before completing the exam is prohibited.
- ISACA, or its designated agents, have the right to research this ISACA exam results and exam data
to monitor for exam fraud and exam irregularities.
- ISACA reserves the right, in its sole discretion, to disqualify me from taking or continuing to sit for this
ISACA exam, or from receiving my exam score if ISACA, or its designated agents, determine, through
proctor observation, statistical analysis, or any other means that I was engaged in collaborative,
disruptive, or other unacceptable behavior before, during or after the administration of this ISACA
exam.
- The unauthorized receipt, retention, possession, copying, or disclosure of any ISACA exam materials,
including but not limited to the content of this ISACA exam, before, during, or after the exam is in
violation of the confidential nature of this ISACA exam and can result in disciplinary or legal action
such as severe civil or criminal penalties, invalidation of exam scores, and revocation of ISACA
membership and ISACA certifications currently held.
- ISACA reserves the right to invalidate test scores if ISACA has any reasonable basis to question the
validity of a test score.
BY PROCEEDING WITH THIS EXAM, I ACKNOWLEDGE THAT I HAVE READ, UNDERSTAND, AND AGREE
TO COMPLY WITH THE ABOVE ISACA/PSI SECURITY AGREEMENT AND CONSENT TO TAKE THIS ISACA
EXAM UNDER THE CONDITIONS STATED HEREIN.
Note: If a candidate refuses to consent to the conditions of this ISACA/PSI Security Agreement, the proctor will
notify the candidate that he/she will not be authorized to take the examination. PSI and ISACA Headquarters will
be so informed. This form is retained as a permanent part of the candidate file.
All CISA, CRISC, CGET and CISM exam items are owned and copyrighted by ISACA. © 2003-Present, ISACA.
All rights reserved.
20
® 2019 ISACA. All Rights Reserved.