Overview
CISA® is a globally recognized standard of achievement among information systems (IS) audit, control and security professionals. The certification examination is designed to assess and certify individuals in the IS audit, control, assurance and security professionals.
Holder of a CISA® credential demonstrates proficiency and signifies commitment to serving an organization and the IS audit, control and security industry with distinction.
This programme is specifically designed according to the CISA® syllabus.
Private in-house training
Apart from public, instructor-led classes, we also offer private in-house trainings of this program for organizations. Call us at +852 2116 3328 or email us at [email protected] for more details.
Why Choose KORNERSTONE
- KORNERSTONE is the Only ISACA® Accredited Training Organization in HK
- ALL Official ISACA Material included
- Practical, scenario-based learning – focus on application, not just theory
- Over 85% Passing rate in ISACA program
- Pass Guaranteed (80% over attendance)
- Exclusive Offer on purchasing Exam Voucher
Skills Covered
- Conduct thorough audits of information systems and IT processes
- Assess the effectiveness of IT governance and management structures
- Review system acquisition projects and implementation lifecycles
- Evaluate operational IT processes, maintenance, and service delivery
- Safeguard critical information assets through robust security controls
Target Audience
This program is designed for IS audit, control, and security professionals who conduct IT audits and assurance engagements. It is ideal for those seeking to validate their expertise in auditing information systems, evaluating IT governance, and protecting critical information assets.
Training Highlights
- 29-hour intensive workshop
- Conducted by renowned, experienced industrial expert
- Real case study will be adopted with experience sharing
- Eligible for 29 units of PDU / CPE
Course Curriculum
- Domain 1 — The Process of Auditing Information Systems (18%)
- Domain 2 — Governance and Management of IT (18%)
- Domain 3 — Information Systems Acquisition, Development and Implementation (12%)
- Domain 4 — Information Systems Operations, Maintenance and Service Management (26%)
- Domain 5 — Protection of Information Assets (26%)
Dates & Locations
October 20, 2026 - November 20, 2026

Exam & Certification
- Pass the CISA® examination
- A minimum of five years of professional information systems auditing control or security work experience. Experience must have been gained within the 10-year period preceding the application date for certification or within five years from the date of initially passing the examination
- Adherence to the Code of Professional Ethics
- Compliance with Information Systems Auditing Standards
- Recertification is required every three years. CISA® Chartered holders are required to earn 120 Continuing Professional Education (CPE) credits every three years, with a minimum of 20 CPEs earned each year after certification
- CISA® Chartered holders need to pay annual maintenance fee of USD 45 for ISACA members and USD 85 for ISACA non-members
- The course is not a criteria or a condition of the requirement
- More details: https://www.isaca.org/credentialing/cisa/get-cisa-certified

Examination Highlights
-
CISA® Exam
- Candidates are able to schedule their exam for any available date/time/location within their 365-day eligibility period
- Consists of 150 questions in a 4-hour session
The course is not a prerequisite requirement for sitting the examination nor lead to award of any qualification
Trainer for this course
Mr. S Cheung
AAIA, CISSP, CCSP, CISA, CDPSE, ISO 27001 Lead Auditor, ISO 20000 Lead Auditor, ISO 9001 Lead Auditor, ITIL
- Over 10 years of diverse experience in information security and cybersecurity fields, covering cloud security, network security, security operations, red & blue team assessment, and SRAA.
- Skilled in providing advisory services on information security management systems, security operations, and cybersecurity defense strategies by leveraging extensive knowledge and experience.
- Proficient in offering consultancy on industrial and government security standards like C-RAF, ISO27001, CSA CCM, PCIDSS, and SRAA, and assisting clients in designing and implementing security controls.
- Certified Kornerstone trainer for CISSP (Certified Information Systems Security Professional) and CCSP (Certified Cloud Security Professional) certifications.
Mr. H Ng
CISSP®-ISSAP, CISA
- Former Managing Director of Cybersecurity APAC, Thales Critical Information and Cybersecurity Business Unit
- Former Head of Professional Services for Verizon Business leading the Asia consulting practice specialized in delivering information security and other consulting services
- Former Team Lead of HP Security Team
- Project manager and team lead for many security assessment, governance and consultancy projects for Hong Kong Government agencies, large enterprises and major banking and financial customers within APAC region
Mr. A Yau
CISSP, CISA, CISM, CGEIT, CRISC, CDPSE
- Mr. Yau is currently holding a Senior Management Role as Principal Cybersecurity Consultant and Trainer with 20+ years of experience
- Specializes in leading engagements and serving clients in Information Security, including Next Generation Security Operation Center, IT Risk Assessment, Penetration Testing and IT Audit
- Led the implementation and execution of Next Generation Security Operation Center, Security Operation Center, Infrastructure
- Security for Mobile Device Management, Security Exchange 2010 and Infrastructure Security for Enterprise Cloud Services
- Holds ISACA Accredited Trainer and Certified Mile2 Instructor credentials








