ICAI DISA Syllabus: The 6 Modules of ISA 3.0
Six modules, from audit process to blockchain and RPA. Here's every chapter in ICAI's own background material.
The ISA 3.0 course, whose certificate is the DISA, has 6 modules. The same six run through the e-learning, the 72 hours of professional training and the Assessment Test, and ICAI publishes a background-material PDF for each one.
Below is every chapter in that background material. If a page shows you eight modules, with names like "Primer on Information Technology" or "Business Continuity Management" as a module of its own, it is describing the older DISA 2.0 course.
You save ₹450 today
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Six ISA 3.0 Modules at a Glance
1
Name
Information Systems Audit Process
Chapters in the background material
6
2
Name
Governance and Management of Enterprise Information Technology, Risk Management, Compliance & BCM
Chapters in the background material
5
3
Name
System Development, Acquisition, Implementation and Maintenance; Application System Audit
Chapters in the background material
4
4
Name
Information Systems Operations and Management
Chapters in the background material
4
5
Name
Protection of Information Assets
Chapters in the background material
5
6
Name
Emerging Technologies
Chapters in the background material
6
| Module | Name | Chapters in the background material |
|---|---|---|
| 1 | Information Systems Audit Process | 6 |
| 2 | Governance and Management of Enterprise Information Technology, Risk Management, Compliance & BCM | 5 |
| 3 | System Development, Acquisition, Implementation and Maintenance; Application System Audit | 4 |
| 4 | Information Systems Operations and Management | 4 |
| 5 | Protection of Information Assets | 5 |
| 6 | Emerging Technologies | 6 |
Module 1: Information Systems Audit Process
The audit backbone of the course: how an IS audit is planned, run, evidenced and reported.
- check_circleConcepts of IS audit: IT risk, risk-based auditing, the audit universe, audit risk and materiality, internal controls and organising the IS audit function
- check_circleIS audit in phases: audit charter and engagement terms, scope, planning, objectives of IS controls, risk assessment, the risk control matrix, sampling and data analysis, compliance and substantive testing, evidence, documentation, using the work of experts, reporting and follow-up
- check_circleComputer-assisted audit tools and techniques (CAATs)
- check_circleApplication controls review
- check_circleApplication controls review for specialised systems
- check_circleIT-enabled services
Module 2: Governance, Risk Management, Compliance & BCM
How IT is directed and controlled at board and management level, and how the business keeps running when it fails.
- check_circleConcepts of governance and management of information systems
- check_circleGRC frameworks and risk management practices
- check_circleKey components of a governance system
- check_circlePerformance management systems
- check_circleBusiness continuity management
Module 3: Systems Development, Acquisition, Implementation & Maintenance; Application System Audit
How systems get built or bought, and the controls an auditor checks along the way.
- check_circleProject management for the SDLC: frameworks, initiation, planning, controlling, closing, roles and tools
- check_circleSDLC need, benefits and phases; SDLC models and how to choose one; iterative models such as prototype, spiral, rapid and agile; secure SDLC
- check_circleSoftware testing (levels, strategies, types, final testing) and implementation
- check_circleApplication controls: types, objectives, design and implementation
Audit questions, no signup.
Module 4: Information Systems Operations and Management
Running IT day to day: service management, operations and what happens when an incident hits.
- check_circleInformation systems management: organisation, service management, roles, HR, training, SCM and CRM
- check_circleIS operations: asset, change, configuration, version, log and user management, helpdesk and performance measurement
- check_circleSoftware operations and management: operating systems, application software, testing and maintenance, DBMS, network services, backup strategies and patch management
- check_circleIncident response and management: incident handling, cyber-security frameworks and SIEM tools
Module 5: Protection of Information Assets
The security-controls module, from policy down to the network.
- check_circleIntroduction to protection of information assets
- check_circleAdministrative controls: information security management, policies and standards, information classification, responsibility, training and implementation
- check_circlePhysical and environmental controls, and how to audit them
- check_circleLogical access controls: access paths, attacks, access-control mechanisms and techniques, identity and access management, single sign-on, audit trails
- check_circleNetwork security controls: threats and attack trends, network and wireless security, endpoint and VoIP security, VAPT, monitoring and auditing network controls
Module 6: Emerging Technologies
Six technologies, each covered for what it is, the risks it brings and how to audit it.
- check_circleArtificial intelligence
- check_circleBlockchain
- check_circleCloud computing
- check_circleData analytics
- check_circleInternet of Things
- check_circleRobotic process automation
No Official Marks Split per Module
ICAI states the Assessment Test is 200 marks with 60% flat to pass, but publishes no weighting by module. Treat all six as examinable and don't skip one on the hope it carries few marks.
DISA 2.0 Material Is Out of Date
ICAI's last Assessment Test announced for the old and new syllabus together was held on 24 December 2022. Its 2026 tests are for the 3.0 syllabus only, so study from the 3.0 background material and not from older 2.0 notes.
FAQs
How many modules are in the DISA syllabus?expand_more
Six in ISA 3.0: IS audit process; governance, risk, compliance and BCM; systems development and application audit; IS operations and management; protection of information assets; and emerging technologies.
Is the DISA 3.0 syllabus different from DISA 2.0?expand_more
Yes. ICAI's older course listing, which still mentions the 2.0 e-learning, shows eight modules, including a separate IT primer and a separate Business Continuity Management module. In 3.0 there are six: BCM sits inside Module 2 and emerging technologies is a module of its own.
Which emerging technologies are in the syllabus?expand_more
Artificial intelligence, blockchain, cloud computing, data analytics, the Internet of Things and robotic process automation.
Does ICAI publish marks per module for the Assessment Test?expand_more
No. ICAI states only the total (200) and the pass mark (60% flat, 120 marks).
Where can I download the DISA syllabus and material?expand_more
ICAI publishes the ISA 3.0 background material, one PDF per module plus a lab manual and case studies, on its ISA Background Material page. See our study material page for the details.
Next steps
- Exam Patternarrow_forward
- Study Materialarrow_forward
- Preparationarrow_forward
- Mock Test Papersarrow_forward
All six modules, timed and scored out of 200.
