
Bob Salmans
Cybersecurity & Governance, Risk, and Compliance (GRC)
Spotlight
The ISACA certifications IT leaders most often standardize their teams on — the credentials auditors and regulators specifically recognize on the engineer signing off on governance and audit documentation.
The Certified Information Security Manager (CISM) certification validates an individual's expertise in information security management, risk management, and incident response, and is ideal for IT professionals who want to demonstrate their expertise in managing and overseeing information security programs.
Exam investment: $575 for members $760 for non-members
The ISACA CISA certification validates an individual's ability to audit, control, and monitor information systems, and is designed for IT professionals with experience in auditing, risk management, and control. It demonstrates expertise in assessing vulnerabilities, reporting on compliance, and ensuring the integrity of information systems.
Exam investment: USD 575 for ISACA members, USD 760 for non-members
The Certified in Risk and Information Systems Control (CRISC) certification validates an IT professional's ability to identify and manage risk, design and implement information system controls, and maintain ongoing monitoring and reporting of IT risk. IT professionals who want to demonstrate their expertise in risk management and information systems control should consider this certification.
Exam investment: $575 for ISACA members, $760 for non-members
The ISACA Cybersecurity Fundamentals certification validates an individual's knowledge of cybersecurity concepts, threats, vulnerabilities, and risk management. It is designed for IT professionals, students, and individuals looking to enter the cybersecurity field.
Exam investment: $120 for members, $150 for non-members
The ISACA Data Science Fundamentals (ITCA) certification validates an individual's knowledge and skills in data science concepts, techniques, and tools, and is ideal for data science professionals, business analysts, and IT professionals who want to gain a deeper understanding of data science and its applications.
Exam investment: $120 for members, $150 for non-members
Mid-market security leaders measure ISACA training value in compliance terms — defensible governance coverage for SOC 2 / ISO 27001 / NIST audit prep, a credentialed bench auditors and boards explicitly recognize, and a shared governance vocabulary across security, risk, and compliance teams. Those are the outcomes leadership cares about.
Role-based paths
Match ISACA certs to the actual roles your team holds. Each path bundles the right certs plus the operational depth engineers need day-to-day.
CISM (Certified Information Security Manager) is the management-track ISACA credential — covers governance, risk management, incident response, and security program development. The credential boards and auditors specifically recognize on the CISO and security manager bench.
The Certified Information Security Manager (CISM) certification validates an individual's expertise in information security management, risk management, and incident response, and is ideal for IT professionals who want to demonstrate their expertise in managing and overseeing information security programs.
Exam investment: $575 for members $760 for non-members
CISA (Certified Information Systems Auditor) is the gold-standard audit credential — covers audit process, governance, information systems acquisition, operations, and protection of information assets. The reference credential for internal audit and Big 4 audit teams.
The ISACA CISA certification validates an individual's ability to audit, control, and monitor information systems, and is designed for IT professionals with experience in auditing, risk management, and control. It demonstrates expertise in assessing vulnerabilities, reporting on compliance, and ensuring the integrity of information systems.
Exam investment: USD 575 for ISACA members, USD 760 for non-members
CRISC (Certified in Risk and Information Systems Control) covers enterprise IT risk identification, assessment, response, and control monitoring. The cert that ties governance frameworks (COBIT, NIST RMF) to operational IT.
The Certified in Risk and Information Systems Control (CRISC) certification validates an IT professional's ability to identify and manage risk, design and implement information system controls, and maintain ongoing monitoring and reporting of IT risk. IT professionals who want to demonstrate their expertise in risk management and information systems control should consider this certification.
Exam investment: $575 for ISACA members, $760 for non-members
ITCA (IT Certified Associate) tracks provide vendor-neutral fundamentals on-ramps for teams growing the governance/security bench. The Cybersecurity Fundamentals and Data Science Fundamentals tracks each cover their respective domain at an entry level.
The ISACA Cybersecurity Fundamentals certification validates an individual's knowledge of cybersecurity concepts, threats, vulnerabilities, and risk management. It is designed for IT professionals, students, and individuals looking to enter the cybersecurity field.
Exam investment: $120 for members, $150 for non-members
The ISACA Data Science Fundamentals (ITCA) certification validates an individual's knowledge and skills in data science concepts, techniques, and tools, and is ideal for data science professionals, business analysts, and IT professionals who want to gain a deeper understanding of data science and its applications.
Exam investment: $120 for members, $150 for non-members

Hands-on ISACA practice
Human-led training is the point: engineers practice real skills with expert guidance, not just video playback.
Why CBT Nuggets
The platform features IT directors evaluating us against Pluralsight, Udemy Business, and LinkedIn Learning ask about most often.
Practitioner-led
Built and taught by engineers who have spent decades running production ISACA infrastructure — not crowd-sourced contributors.

Cybersecurity & Governance, Risk, and Compliance (GRC)

Offensive Security & Security Operations

Microsoft Cloud Security & Governance, Risk, and Compliance (GRC)
Team outcome
Manager reporting gives IT leaders a clearer view of assigned training, completion progress, and certification coverage.
Best fit for: compliance-sensitive teams that need evidence of progress before a review, renewal, or internal governance checkpoint.
Common questions IT directors ask when evaluating ISACA training for their team.