Skip to content
CBT Nuggets

Governance, risk, and audit credentials

ISACA Certification Training & Courses for IT Teams

CISM, CISA, CRISC, and the ISACA Fundamentals tracks — the credentials auditors and regulators specifically recognize on governance, risk, and audit teams. Every path comes with structured training, exam-aligned content, and team admin reporting.

5
Certifications
4
Role paths
1
Levels
Information security governance team reviewing audit documentation and risk register

Audit-recognized credentials

Built for teams that need to prove governance and audit readiness to regulators.

CertificationsISACA

Spotlight

4 certifications

The ISACA certifications IT leaders most often standardize their teams on — the credentials auditors and regulators specifically recognize on the engineer signing off on governance and audit documentation.

CISM – Certified Information Security Manager

ProfessionalLabsPracticeCISM
Information Security GovernanceRisk ManagementInformation Security Program Development and Management

The Certified Information Security Manager (CISM) certification validates an individual's expertise in information security management, risk management, and incident response, and is ideal for IT professionals who want to demonstrate their expertise in managing and overseeing information security programs.

Exam investment: $575 for members $760 for non-members

CISA – Certified Information Systems Auditor

ProfessionalLabsPracticeCISA
Information Systems AuditingGovernance and Management of ITInformation Systems Acquisition, Development, and Implementation

The ISACA CISA certification validates an individual's ability to audit, control, and monitor information systems, and is designed for IT professionals with experience in auditing, risk management, and control. It demonstrates expertise in assessing vulnerabilities, reporting on compliance, and ensuring the integrity of information systems.

Exam investment: USD 575 for ISACA members, USD 760 for non-members

CRISC – Certified in Risk and Information Systems Control

ProfessionalLabsPracticeCRISC
Risk IdentificationRisk AssessmentRisk Response and Mitigation

The Certified in Risk and Information Systems Control (CRISC) certification validates an IT professional's ability to identify and manage risk, design and implement information system controls, and maintain ongoing monitoring and reporting of IT risk. IT professionals who want to demonstrate their expertise in risk management and information systems control should consider this certification.

Exam investment: $575 for ISACA members, $760 for non-members

ISACA Cybersecurity Fundamentals (ITCA)

ProfessionalLabsPracticeITCA
Cybersecurity FundamentalsThreats and VulnerabilitiesRisk Management

The ISACA Cybersecurity Fundamentals certification validates an individual's knowledge of cybersecurity concepts, threats, vulnerabilities, and risk management. It is designed for IT professionals, students, and individuals looking to enter the cybersecurity field.

Exam investment: $120 for members, $150 for non-members

Professional Level

1 certification

ISACA Data Science Fundamentals (ITCA)

ProfessionalLabsPracticeITCA
Data Science ConceptsMachine LearningData Visualization

The ISACA Data Science Fundamentals (ITCA) certification validates an individual's knowledge and skills in data science concepts, techniques, and tools, and is ideal for data science professionals, business analysts, and IT professionals who want to gain a deeper understanding of data science and its applications.

Exam investment: $120 for members, $150 for non-members

Customer outcome

Audit-recognized credentials your auditor explicitly asks for

Mid-market security leaders measure ISACA training value in compliance terms — defensible governance coverage for SOC 2 / ISO 27001 / NIST audit prep, a credentialed bench auditors and boards explicitly recognize, and a shared governance vocabulary across security, risk, and compliance teams. Those are the outcomes leadership cares about.

Role-based paths

ISACA certifications by IT job role

Match ISACA certs to the actual roles your team holds. Each path bundles the right certs plus the operational depth engineers need day-to-day.

ISACA certs for Security Managers & CISOs

1 certification

CISM (Certified Information Security Manager) is the management-track ISACA credential — covers governance, risk management, incident response, and security program development. The credential boards and auditors specifically recognize on the CISO and security manager bench.

CISM – Certified Information Security Manager

ProfessionalLabsPracticeCISM
Information Security GovernanceRisk ManagementInformation Security Program Development and Management

The Certified Information Security Manager (CISM) certification validates an individual's expertise in information security management, risk management, and incident response, and is ideal for IT professionals who want to demonstrate their expertise in managing and overseeing information security programs.

Exam investment: $575 for members $760 for non-members

ISACA certs for IT Auditors

1 certification

CISA (Certified Information Systems Auditor) is the gold-standard audit credential — covers audit process, governance, information systems acquisition, operations, and protection of information assets. The reference credential for internal audit and Big 4 audit teams.

CISA – Certified Information Systems Auditor

ProfessionalLabsPracticeCISA
Information Systems AuditingGovernance and Management of ITInformation Systems Acquisition, Development, and Implementation

The ISACA CISA certification validates an individual's ability to audit, control, and monitor information systems, and is designed for IT professionals with experience in auditing, risk management, and control. It demonstrates expertise in assessing vulnerabilities, reporting on compliance, and ensuring the integrity of information systems.

Exam investment: USD 575 for ISACA members, USD 760 for non-members

ISACA certs for Risk & Compliance Managers

1 certification

CRISC (Certified in Risk and Information Systems Control) covers enterprise IT risk identification, assessment, response, and control monitoring. The cert that ties governance frameworks (COBIT, NIST RMF) to operational IT.

CRISC – Certified in Risk and Information Systems Control

ProfessionalLabsPracticeCRISC
Risk IdentificationRisk AssessmentRisk Response and Mitigation

The Certified in Risk and Information Systems Control (CRISC) certification validates an IT professional's ability to identify and manage risk, design and implement information system controls, and maintain ongoing monitoring and reporting of IT risk. IT professionals who want to demonstrate their expertise in risk management and information systems control should consider this certification.

Exam investment: $575 for ISACA members, $760 for non-members

ISACA fundamentals for new hires

2 certifications

ITCA (IT Certified Associate) tracks provide vendor-neutral fundamentals on-ramps for teams growing the governance/security bench. The Cybersecurity Fundamentals and Data Science Fundamentals tracks each cover their respective domain at an entry level.

ISACA Cybersecurity Fundamentals (ITCA)

ProfessionalLabsPracticeITCA
Cybersecurity FundamentalsThreats and VulnerabilitiesRisk Management

The ISACA Cybersecurity Fundamentals certification validates an individual's knowledge of cybersecurity concepts, threats, vulnerabilities, and risk management. It is designed for IT professionals, students, and individuals looking to enter the cybersecurity field.

Exam investment: $120 for members, $150 for non-members

ISACA Data Science Fundamentals (ITCA)

ProfessionalLabsPracticeITCA
Data Science ConceptsMachine LearningData Visualization

The ISACA Data Science Fundamentals (ITCA) certification validates an individual's knowledge and skills in data science concepts, techniques, and tools, and is ideal for data science professionals, business analysts, and IT professionals who want to gain a deeper understanding of data science and its applications.

Exam investment: $120 for members, $150 for non-members

Every certification includes

Expert-led video training
Virtual labs
N2K practice exams
Per-team completion reporting

Practitioner-led

ISACA training your team learns from

Built and taught by engineers who have spent decades running production ISACA infrastructure — not crowd-sourced contributors.

Bob Salmans

Bob Salmans

Cybersecurity & Governance, Risk, and Compliance (GRC)

Erik Choron

Erik Choron

Offensive Security & Security Operations

John Munjoma

John Munjoma

Microsoft Cloud Security & Governance, Risk, and Compliance (GRC)

Team outcome

Audit-ready training visibility

Manager reporting gives IT leaders a clearer view of assigned training, completion progress, and certification coverage.

Best fit for: compliance-sensitive teams that need evidence of progress before a review, renewal, or internal governance checkpoint.

Frequently asked questions about ISACA training

Common questions IT directors ask when evaluating ISACA training for their team.

Ready to certify your team?

Build ISACA certification coverage across your team

See how CBT Nuggets helps IT Directors plan and track ISACA certifications.