ISACA Certifications¶
About ISACA¶
ISACA (Information Systems Audit and Control Association) is a global professional association founded in 1969 that focuses on IT governance, audit, risk, cybersecurity, and information systems assurance. Originally known as the EDP Auditors Association, ISACA was created by a group of internal auditors who needed a centralized source of information and guidance for auditing computer-based controls. ISACA now serves more than 170,000 members across 180+ countries.
ISACA maintains some of the most widely recognized credentials for IT audit, governance, and risk professionals, and publishes the COBIT framework for IT governance and management. Its certifications are accredited under ANSI/ISO/IEC Standard 17024 and are frequently cited as preferred or required qualifications for IT audit, IT governance, and information security management roles in enterprise, financial services, healthcare, government, and Big 4 advisory practices.
Certifications Offered¶
Audit and Assurance¶
- CISA (Certified Information Systems Auditor) - Flagship audit credential. Covers IS audit process, governance, acquisition/development, operations/resilience, and protection of information assets. Requires 5 years of professional IS audit, control, or security experience (substitutions available).
Governance and Risk¶
- CGEIT (Certified in the Governance of Enterprise IT) - For senior professionals responsible for IT governance. Requires 5 years of experience in IT governance.
- CRISC (Certified in Risk and Information Systems Control) - For risk management professionals. Requires 3 years of experience in IT risk management and IS control.
Security Management¶
- CISM (Certified Information Security Manager) - For information security managers. Sister certification to CISA, focused on security program management rather than audit. Requires 5 years of experience in information security management.
Privacy¶
- CDPSE (Certified Data Privacy Solutions Engineer) - For privacy engineering professionals. Requires 3 years of experience in data privacy.
Cybersecurity (Practitioner)¶
- CET (Certified Cybersecurity Operations Analyst) - Operational cybersecurity certification.
- Cybersecurity Audit Certificate - Specialized add-on certificate for auditing cybersecurity controls (no experience requirement).
Emerging Technology¶
- AAIA (Advanced in AI Audit) - AI audit credential.
- CCOA (Certified Cybersecurity Operations Analyst) - SOC analyst credential.
- Various certificate programs in cloud, blockchain, IoT, and AI.
Certifications in This Repository¶
2 certifications in this repo. Counts and statuses are generated from docs/certs.json.
| Cert | Code | Level | Status | Notes |
|---|---|---|---|---|
| CISA - Certified Information Systems Auditor | CISA | - | Ready | 5 |
| CISM - Certified Information Security Manager | CISM | - | Ready | 4 |
Certification Maintenance¶
All ISACA certifications require: - Annual Maintenance Fee (AMF): $45 USD for ISACA members, $85 USD for non-members per certification. - CPE Credits: 120 CPE hours over a 3-year reporting cycle, with a minimum of 20 CPE hours per year. - Ethics commitment: Adherence to the ISACA Code of Professional Ethics. - Audit cycle: ISACA may randomly audit CPE submissions; retain documentation for at least 12 months after the reporting cycle.
Application and Experience Requirements¶
After passing an ISACA exam, candidates have 5 years from the exam date to apply for certification and demonstrate the required work experience. Most ISACA certifications offer experience substitutions (such as a related degree, teaching experience, or another ISACA credential) that can waive 1 to 2 years.
COBIT Framework¶
ISACA publishes COBIT (Control Objectives for Information and Related Technologies), the leading framework for IT governance and management. The current edition is COBIT 2019, which separates governance objectives from management objectives and aligns with other major frameworks (ITIL, ISO/IEC 27001, NIST CSF, TOGAF). COBIT 2019 knowledge is heavily tested across CISA, CGEIT, and CRISC.
Official Resources¶
- ISACA Website: https://www.isaca.org
- My ISACA Portal: https://www.isaca.org/myisaca
- COBIT Framework: https://www.isaca.org/resources/cobit
- ITAF (IT Audit Framework): https://www.isaca.org/resources/itaf
- Engage Community: https://engage.isaca.org