
Bob Salmans
Cybersecurity & Governance, Risk, and Compliance (GRC)
Spotlight
The ISACA certifications IT leaders most often standardize their teams on — the credentials auditors and regulators specifically recognize on the engineer signing off on governance and audit documentation.
The Certified Information Security Manager (CISM) certification validates an individual's expertise in information security management, risk management, and incident response, and is ideal for IT professionals who want to demonstrate their expertise in managing and overseeing information security programs.
Exam investment: $575 for members $760 for non-members
The ISACA CISA certification validates an individual's ability to audit, control, and monitor information systems, and is designed for IT professionals with experience in auditing, risk management, and control. It demonstrates expertise in assessing vulnerabilities, reporting on compliance, and ensuring the integrity of information systems.
Exam investment: USD 575 for ISACA members, USD 760 for non-members
The Certified in Risk and Information Systems Control (CRISC) certification validates an IT professional's ability to identify and manage risk, design and implement information system controls, and maintain ongoing monitoring and reporting of IT risk. IT professionals who want to demonstrate their expertise in risk management and information systems control should consider this certification.
Exam investment: $575 for ISACA members, $760 for non-members
The ISACA Cybersecurity Fundamentals certification validates an individual's knowledge of cybersecurity concepts, threats, vulnerabilities, and risk management. It is designed for IT professionals, students, and individuals looking to enter the cybersecurity field.
Exam investment: $120 for members, $150 for non-members
The ISACA Data Science Fundamentals (ITCA) certification validates an individual's knowledge and skills in data science concepts, techniques, and tools, and is ideal for data science professionals, business analysts, and IT professionals who want to gain a deeper understanding of data science and its applications.
Exam investment: $120 for members, $150 for non-members
Directors of Security measure ISACA training value in compliance terms — defensible governance coverage for SOC 2 / ISO 27001 / NIST audit prep, a credentialed bench auditors and boards explicitly recognize, and a shared governance vocabulary across security, risk, and compliance teams. Those are the outcomes leadership cares about.
Role-based paths
Match ISACA certs to the actual roles your team holds. Each path bundles the right certs plus the operational depth engineers need day-to-day.
CISM (Certified Information Security Manager) is the management-track ISACA credential — covers governance, risk management, incident response, and security program development. The credential boards and auditors specifically recognize on the CISO and security manager bench.
The Certified Information Security Manager (CISM) certification validates an individual's expertise in information security management, risk management, and incident response, and is ideal for IT professionals who want to demonstrate their expertise in managing and overseeing information security programs.
Exam investment: $575 for members $760 for non-members
CISA (Certified Information Systems Auditor) is the gold-standard audit credential — covers audit process, governance, information systems acquisition, operations, and protection of information assets. The reference credential for internal audit and Big 4 audit teams.
The ISACA CISA certification validates an individual's ability to audit, control, and monitor information systems, and is designed for IT professionals with experience in auditing, risk management, and control. It demonstrates expertise in assessing vulnerabilities, reporting on compliance, and ensuring the integrity of information systems.
Exam investment: USD 575 for ISACA members, USD 760 for non-members
CRISC (Certified in Risk and Information Systems Control) covers enterprise IT risk identification, assessment, response, and control monitoring. The cert that ties governance frameworks (COBIT, NIST RMF) to operational IT.
The Certified in Risk and Information Systems Control (CRISC) certification validates an IT professional's ability to identify and manage risk, design and implement information system controls, and maintain ongoing monitoring and reporting of IT risk. IT professionals who want to demonstrate their expertise in risk management and information systems control should consider this certification.
Exam investment: $575 for ISACA members, $760 for non-members
ITCA (IT Certified Associate) tracks provide vendor-neutral fundamentals on-ramps for teams growing the governance/security bench. The Cybersecurity Fundamentals and Data Science Fundamentals tracks each cover their respective domain at an entry level.
The ISACA Cybersecurity Fundamentals certification validates an individual's knowledge of cybersecurity concepts, threats, vulnerabilities, and risk management. It is designed for IT professionals, students, and individuals looking to enter the cybersecurity field.
Exam investment: $120 for members, $150 for non-members
The ISACA Data Science Fundamentals (ITCA) certification validates an individual's knowledge and skills in data science concepts, techniques, and tools, and is ideal for data science professionals, business analysts, and IT professionals who want to gain a deeper understanding of data science and its applications.
Exam investment: $120 for members, $150 for non-members

Hands-on ISACA practice
Human-led training is the point: engineers practice real skills with expert guidance, not just video playback.
Why CBT Nuggets
The platform features IT directors comparing training platforms ask about most often.
Practitioner-led
Built and taught by engineers who have spent decades running production ISACA infrastructure — not crowd-sourced contributors.

Cybersecurity & Governance, Risk, and Compliance (GRC)

Offensive Security & Security Operations

Microsoft Cloud Security & Governance, Risk, and Compliance (GRC)
Team outcome
Manager reporting gives IT leaders a clearer view of assigned training, completion progress, and certification coverage.
Best fit for: compliance-sensitive teams that need evidence of progress before a review, renewal, or internal governance checkpoint.
Common questions IT directors ask when evaluating ISACA training for their team.
It depends on the role. CISM is the right cert for the security manager / CISO bench — covers program management and governance. CISA is the gold-standard audit credential for internal audit teams and Big 4 consulting. CRISC is the right cert for risk and compliance managers tying governance frameworks to operational controls. Most security teams hold a mix — CISM for management, CISA for audit, CRISC for risk.
CISSP is the broad technical security credential — what a senior security engineer or architect holds to prove technical depth. ISACA credentials are management and governance-coded — what a CISO, security program manager, or auditor holds to prove leadership and audit competency. Many security leaders hold both: CISSP for technical credibility, CISM for management framing.
For governance and audit teams, start with audit-readiness metrics — time to prepare for the next SOC 2 / ISO 27001 / regulatory review, defensible coverage of governance roles, and the audit-finding rate on internal controls. CBT Nuggets gives managers the reporting surface to track completion and cert coverage; the training itself prepares the team for the credentialing every auditor expects to see.
Yes — ISACA credentials are explicitly recognized in every major compliance framework. The CISM, CISA, and CRISC paths cover the governance, audit, and risk content auditors expect on the team signing off on framework controls. Team reporting helps managers document assigned training, completion, and certification coverage for the audit packet auditors want to see.
All three require 5 years of relevant work experience to fully certify (CISM: information security management; CISA: information systems auditing; CRISC: IT risk management). Engineers can take and pass the exam first, then complete the experience requirement within 5 years. CBT Nuggets training prepares teams for the exam regardless of where they sit in the experience timeline.
ISACA certifications require ongoing CPE (Continuing Professional Education) credit to maintain. CBT Nuggets training contributes CPE hours per ISACA's partner program. Managers can use assigned training paths to keep team CPE earning on schedule without anyone scrambling at recertification time.