Related Posts
Anyone gone from PA to CBRE ? Do you like it ?
More Posts
BCG > Bain or Bain > BCG?
Any work or use to work at Chartwells K12
How much do SAP principals make with about 8 yoe
Hi how is smartims company for experienced?
Try out a new marketplace for teachers to buy and sell lessons/materials/resources. Take all of your hard work especially from virtual learning and make some extra money off them. Sellers make 100% profit off anything they sell. This is for a FREE Membership. Type in vipfree in the space that asks “how did you hear about us” on sign up. Lessontrader.com

Win $20 cash. New users welcome. Free membership with discount code “vipfree”. Until Sunday 5:00 pm eastern whatever teacher uploads the most lessons to their teacher store will win $20 cash!! Lessontrader.com is a virtual marketplace for teacher users to buy and sell resources with teacher sellers making 100% profit off anything they sell.

Additional Posts in Cyber Security Bowl
HMU for referrals
Tell me it’s not true.

New to Fishbowl?
unlock all discussions on Fishbowl.



Hello Manager!
I’ll share my perspective as a CISO
While the CISSP is a strong certification that covers a wide range of security domains, the CISA exam requires a different skillset and mindset. There are a few reasons why CISSP holders can sometimes struggle with CISA (and other exams like it) even if they have significant experience in cybersecurity.
This one is probably obvious… but I’m going to say it anyway – Unlike the CISSP, which emphasizes technical knowledge and implementation, CISA focuses on auditing, controls, and assurance. It requires candidates to think like an auditor, applying a risk-based approach to assess systems, processes, and controls.
Mindset Shift - Many CISSP holders approach CISA with a technical lens, but ISACA tests candidates on governance principles, process auditing, and evaluation of controls. This shift in perspective can be challenging, especially for those who haven’t worked in formal audit or assurance roles.
Exam Style and Preparation - this is where I think people really get hemmed up. The CISA exam is known for its tricky, scenario-based questions that emphasize finding the ***best*** answer - not just a correct one. Success requires knowledge of frameworks (COBIT, ISO, etc.) and also understanding how auditors evaluate risk and prioritize findings.
Failing CISA isn’t uncommon, even for experienced professionals and especially for highly technical professionals. It’s about adjusting to a governance and audit-oriented way of thinking.
I think you can pass this exam if you hone in on what I shared above and practice in alignment with that
Circling back to my perspective as a CISO and a hiring manager, when I looked for GRC professionals, I did not look for people with CISSP. In other words, if someone had a CISSP it did not influence my decision to interview them for my GRC function. I would be looking for some sort of GRC certification or GRC experience before even inviting them to interview and I would definitely have some GRC questions in the interview that they should be able to answer.
I hope this helps .
If you have any questions at all, please let me know
You don't need CISA if you have CISSP for Cyber GRC. Just make sure you have good knowledge of the areas like Incident Management, BCP/Disaster Recovery, Data Loss Protection, Identity and Access Management and you should be fine.
Thank you!