Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - What Is A Certified Information Systems Auditor (CISA) Designation?
Articles

What Is A Certified Information Systems Auditor (CISA) Designation?

Tom DeSotBy Tom DeSotOctober 29, 2019Updated:December 30, 20215 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Certified Information Systems Auditor (CISA)

A CISA, or Certified Information Systems Auditor is someone that is certified to audit information systems (computers and networks) and the internal controls that a company has put around them to protect them from attack and subsequent compromise.

What is a CISA Designation?

The CISA designation is assigned to those individuals that have passed a rigorous exam developed and utilized by ISACA also known as the Information Systems Audit and Control Association.  These individuals are primarily employed to ensure that the controls that an organization has put in place effective and working as intended to protect the IT assets and sensitive information that the company is seeking to protect.

According to the ISACA, the CISA exam consists of 150 questions from 5 “domains”:

Domain 1—The Process of Auditing Information Systems (21%)
Domain 2—Governance and Management of IT (16%)
Domain 3—Information Systems Acquisition, Development and Implementation (18%)
Domain 4—Information Systems Operations, Maintenance and Service Management (20%)
Domain 5—Protection of Information Assets (25%)

Who Employs a CISA?

Actually, just about any firm can employ a CISA, however it is typically larger firms that have more complex controls that need to be validated on a recurring basis.  This is especially true if the company employing the CISA operates in regulated industry such as banking (GLBA), healthcare (HIPAA), or retail (PCIDSS).

What is the Difference Between a CISA and CISSSP?

According to the ISC2,

“The CISA certification, as its name implies, is about the audit of information systems. The CISSP is focused on the implementation, operation and maintenance of secure information systems. There is a slight overlap in content, but the primary focus is different. Both certifications are highly regarded by the industry, but each validates a different skillset, so it comes down to the kind of job being sought in the cybersecurity field – IT audit, or information security.”

As you can see, the CISSP focuses more on the security of an IT system rather than the controls surrounding it which would be the focus of the CISA.

Many would argue that the two certifications are complementary and give the individual holding the certifications a more holistic view of information system security as well as the controls that should be put in place to protect the system and the data that resides on it or passes through it.

Should I Get a CISA or CISSP Certification?

Really this depends upon your career goals.  Are you looking at becoming an auditor or are you looking at becoming a systems administrator or security analyst?  Deciding on your career path will go a long way in helping you determine which certification is the most appropriate for you to obtain.

Will the CISA Certification Help My Compensation?

In a word, yes!

According to a salary comparison:

“According to this recent IIA salary report, the 236 survey respondents with a CISA certification have an average salary of $105K, versus $65K for those without certification. This staggering statistic shows that the certification can make a huge difference in how much you get paid annually. What it doesn’t show, is that it also opens you up to positions you may not have been qualified for without the certification. But, more on that later.

This is only a rough comparison as they are many factors involved, including the number of years in the field, education level and type of companies they work for. But overall, the 61% premium is a big enough incentive for you to take the CISA certification seriously.”

Do I Have to Have a Degree to Get a CISA Certification?

No, but there are minimum work experience requirements. You need to have at least 5 years of work experience in a related field.  College credit will count towards these years, but as an example, a Master’s degree will only provide you a substitute for 1 year of work experience.

With that being said, a degree in a related field such as accounting or information security will go a long way to helping you prepare for and pass the CISA exam.

Once I Have My Certification, Am I Done?

Unfortunately, no.  Even after receiving your certification, you will have to maintain a certain number of hours of continuing education credits.  Per the ISACA:

“The CISA CPE policy requires the attainment of CPE hours over an annual and three-year certification period. CISAs must comply with the following requirements to retain certification:

  • Attain and report an annual minimum of twenty (20) CPE hours. These hours must be appropriate to the currency or advancement of the CISA’s knowledge or ability to perform CISA-related tasks. The use of these hours towards meeting the CPE requirements for multiple ISACA certifications is permissible when the professional activity is applicable to satisfying the job-related knowledge of each certification.
  • Submit annual CPE maintenance fees to ISACA international headquarters in full.
  • Attain and report a minimum of one hundred and twenty (120) CPE hours for a three-year reporting period.
  • Respond and submit required documentation of CPE activities if selected for the annual audit.”

Is a CISA Certification Worth the Work?

Yes! 

A CISA certification helps with not only your career advancement, but also your general knowledge of IT controls and how to properly protect systems from compromise.  While not as security focused as the CISSP certification, it will go a long way to improve your knowledge of the security industry as a whole and why organizations must put into place certain controls to protect their computing platforms.

Tom DeSot

EVP

  • Tom DeSot
    Being Prepared For Iranian Cyber Attacks

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The next phase of endpoint security starts with simplicity

June 24, 20266 Mins Read

Klue supply chain breach exposes Salesforce data at several security firms

June 24, 20266 Mins Read

What Are AI SOC Agents? Use Cases, Architecture, and the Leading Vendors

June 19, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}