CISA – Domain Mapping for 2011 Exam

March 23, 2011 by Kenneth Magee

Several of you have been asking for a mapping of the new CISA 5 domains to the previous year’s six domains.  The new mapping is as follows:

The major change is the old Business Continuity and Disaster Recovery domain has been split into two parts and merged into Domain 2 for Business Continutity and into Domain 4 for Disaster Recovery.

Posted: March 23, 2011
Articles Author
Kenneth Magee
View Profile

Ken is President and owner of Data Security Consultation and Training, LLC. He has taught cybersecurity at the JAG school at the University of Virginia, KPMG Advisory University, Microsoft and several major federal financial institutions and government agencies. As CISO for the Virginia Community College System, Ken’s focus was the standardization of security around the ISO 27000 series framework. Writing is one of his passions and he has authored and/or co-authored several courses, including CISSP, CISA, CISM, CGEIT, CRISC, DoD Cloud Computing SRG and a course for training Security Control Assessors using NIST SP 800-53A. Ken has also achieved a number of certifications, including CISSP, SSCP, CCSP, CAP, ISSMP, ISSAP, ISSEP, CISM, CISA, CAC, CEH, ISO9000LA, ISO14001LA, ISO27001PA, Security+, CySA+, CASP, CTT+, CPT, GSEC, GSNA, GWAPT, CIA, CGAP, CFE, MCP, MCSA, MCSE and MCT.

6 responses to “CISA – Domain Mapping for 2011 Exam”

  1. Jason says:

    Hi Sir, I have 2010 Manual and I am wondering if the information is a lot different in 2011. Thanks.

    • Kenneth Magee says:


      ISACA deleted Domain 6 Business Continuity and Disaster Recovery and merged the content into Domains 2 and 4. They’ve also changed the weight of the different domains. Domain 2 received the business continuity portion and there is some additional information regarding “Auditing Business Continuity” which wasn’t in the 2010 manual. Domain 4 has additional information on Wireless and domain 5 has some new information on forensics.


  2. Shweta says:

    Hi Jason,
    I am appearing for June 2011 exam but I am preparing using CRM of 2010.
    Would if many lot difference content wise ?
    The reason why I am still stuck to 2010 CRM is I could not clear the Dec 2010 exam.


    • Kenneth Magee says:


      There have been several changes to the material. The old domain 6 BCP and DRP have been split and updated. BCP has been moved to Domain 2 and DRP has been moved to Domain 4. You should try to find someone who has a CRM 2011 and get the updates before you sit for the exam.


  3. DIPTI says:

    HI Ken,

    I am planning to appear for an CISA exam in Dec 2011.

    Can you provide the brief listing of syllabus for CRM 2011 domainwise.?

    Thank You,

    • Kenneth Magee says:


      There are several articles which deal with each of the CISA domains. If you look at each of the individual domain articles you will get a brief overview of the important topics for each of the five CISA domains.


Leave a Reply

Your email address will not be published. Required fields are marked *