How bad is it to not have a CISA certification if you’re interested in Cyber GRC?

I have my CISSP and several Cloud Certs (which I passed the same time), and for some reason, I just can’t pass ISACA exams. I failed CISA 3 times.

like
Posting as :
works at
You are currently posting as works at

Hello Manager!

I’ll share my perspective as a CISO

While the CISSP is a strong certification that covers a wide range of security domains, the CISA exam requires a different skillset and mindset. There are a few reasons why CISSP holders can sometimes struggle with CISA (and other exams like it) even if they have significant experience in cybersecurity.

This one is probably obvious… but I’m going to say it anyway – Unlike the CISSP, which emphasizes technical knowledge and implementation, CISA focuses on auditing, controls, and assurance. It requires candidates to think like an auditor, applying a risk-based approach to assess systems, processes, and controls.

Mindset Shift - Many CISSP holders approach CISA with a technical lens, but ISACA tests candidates on governance principles, process auditing, and evaluation of controls. This shift in perspective can be challenging, especially for those who haven’t worked in formal audit or assurance roles.

Exam Style and Preparation - this is where I think people really get hemmed up. The CISA exam is known for its tricky, scenario-based questions that emphasize finding the ***best*** answer - not just a correct one. Success requires knowledge of frameworks (COBIT, ISO, etc.) and also understanding how auditors evaluate risk and prioritize findings.

Failing CISA isn’t uncommon, even for experienced professionals and especially for highly technical professionals. It’s about adjusting to a governance and audit-oriented way of thinking.

I think you can pass this exam if you hone in on what I shared above and practice in alignment with that

Circling back to my perspective as a CISO and a hiring manager, when I looked for GRC professionals, I did not look for people with CISSP. In other words, if someone had a CISSP it did not influence my decision to interview them for my GRC function. I would be looking for some sort of GRC certification or GRC experience before even inviting them to interview and I would definitely have some GRC questions in the interview that they should be able to answer.

I hope this helps .

If you have any questions at all, please let me know

helpfullike

You don't need CISA if you have CISSP for Cyber GRC. Just make sure you have good knowledge of the areas like Incident Management, BCP/Disaster Recovery, Data Loss Protection, Identity and Access Management and you should be fine.

likehelpful

Thank you!

Related Posts

Got offer from BCG for ECT. Read numerous comments about ECT being not attractive compared to Generalist track. Also heard challenges about billability/utilization. Any views/ guidance appreciated!
I am not super keen to become a partner (selling) and main reason to join will be working with different clients, smart talented people and a good brand. End goal (at the moment atleast) is to stay for few years and return to the industry. 15 YOE

like

*Keeping an eye open for new opportunities*
I have my Bachelor's degree in Healthcare Administration along with 13 years of experience in healthcare. My experience ranges from medical coding, biller/AR specialist, patient financial advocate, and since 2019 my role is in the Quality department as a health care data analyst.

like

Is there anyone who works for Google or Amazon and has a healthcare background with no tech skills? I have my MBA with a healthcare concentration and I’m looking to switch industries. I’ve started to take certification courses on Udemy but would love any insight on how I could get my foot in the door with those companies. Thank you!!

like

I’m a physician assistant with interests in technology. I’m well versed in epic. I’m looking to leave clinical medicine, what kind of roles are available with epic?

like

I‘ve currently got 5 years sales experience (sales advisor, sales specialist and currently SDR). I’m looking to stay in my SDR role for a year and then venture out. The companies I’ve worked for have been in the telecommunications and now fintech industry. What is the trajectory for sales role post sales manager or what are other career avenues I could explore with my sales experience.

like

Best books on leadership? Highly enjoyed Servant Leadership book

like

Hello,

Currently, in accenture. I have had very bad billable hours and not much achievement this fiscal year. I am worried of getting fired, so i applied for another job. Got offered may be 5% above my current pay with 5k bonus, but in lower level at Deloitte. I think working lower level will give me more opportunities to learn as i think i have lot to learn. I made decision based on my gut and accepted the offer. I have not talked to anyone on accenture side yet. What you think?

likesmart

I feel stuck as a Strategy Manager and want to make a career pivot at 35. But have no idea what i should do? Any suggestions, resources or books that I should read to help with my existential mid thirties crisis? I have experience in technology consulting, corporate strategy, freelance consulting and law. Do I go back to being an Attorney, or do I retrain and become a financial advisor or something else?

like

Does anyone practice White Collar criminal defense in NYC or know a decent amount about it? Is it fun or fulfilling? Is it a good way to break into government work in the future?

like

I am looking to get into Tech sales from healthcare sales. I have 16 years of experience. Any advice on companies to look at? Or will a Tech company expect me to come in at a lower level than Account Executive?

like

One of the reasons I want to transition from industry to consulting (tier 1) is that I get frustrated when I have to collaborate with mediocre people. My assumption is that Tier 1 consulting firms hire really sharp people and if I can get in, I’ll be collaborating with folks on top of their game (not expecting much from clients). I’m aware there are personal aspects I need to work on like my mindset, patience etc etc, but I just get so frustrated with blatant stupidity.

likefunny

How bad does it look if I've had 3 jobs in the past 3 years? Job hopper or ambitious professional?

like

Hi fishes, I got 5+ years of work ex of which 2 years was in domain non IT job. While joining Accenture I was offered level 11 (As SAP functional CONSULTANT) while I believe I should be at level 10. What can I do? Is it that just your IT work ex they consider? Suggest things I could do. Completed 8 months in Accenture now as SAP Functional consultant.

like

What is the minimum experience required for associate salesforce consultant?

like

Anyone gone from PA to CBRE ? Do you like it ?

like

I’m sure others have considered this, I really feel burned out on my specific subspecialty. For the most part I do interventional pain management. I am midway through my career, but I cannot in anyway see doing this for the future, it just doesn’t feel like I’m making a difference. I’m honored to be a physician and to help a handful of people, but any suggestions on changing specialties mid life? I have perhaps 15 to 20 years yet to practice.. I’ve looked at concierge medicine, I’m open

like

What is the longest you have seen someone with less than 50% utilization stay in a firm?

like

Fellow 🐟 any thoughts? Received an offer from Deloitte -> Role Manager, Base 180K HCOL, YOE 8, Current Base -> 150K and may get close to 160K in 3 Months. Is it worth the jump? Pros in current role -> High Visibility due to small practice, 45 to 50 Hr work week. Will be SM in next 2 to 3 Years, Cons - TC, Brand Value, Mid Tier Clients. Any opinions?

like

About to start my first PM job! Any tips to be prepared and ramp up quickly? Books to read, courses to take, etc.. any tips are appreciated! Currently in ops consulting. No tech background.

like

After you are stealth laid off, other than job search, what do you do? I assume they won’t give you work and even if they do, you can politely decline? How do you feel about you are not progressing anymore and seeing other people progressing in their career? I have no intention to make partner, but still feel a bit stuck not doing that much.

like

More Posts

BCG > Bain or Bain > BCG?

like

Anyone from Huron on the group? I see booming Oracle Cloud things on there, want to know more - Risk and Controls guy from PwC.

Appeared for an interview in TCS on 7th april and after that no mail communication, only phone calls to upload documents. Uploaded documents and it is showing in verified stage. Status in portal still showing "Resume Shortlisted", what is that mean??

like

Any work or use to work at Chartwells K12

like

What's the New joiner registration grace period at Accenture?can someone help me to understand.

like

24.5 LPA for a solution architect role in TCS.
Is the ask is high or low for 8+ yoe with javaa, aws

like

How much do SAP principals make with about 8 yoe

like

I just got into reading books, any suggestions to start with? Which could help to increase media/marketing knowledge.

like

Has anyone ever been in the position where you’re offered a job and it’s great, but it just doesn’t feel like the right time to jump? If they really like you and they’re actively hiring, is it possible to ask to be reconsidered in a year?

like

What are the healthcare options like in India? I'll be needing regular care and I'm not sure what the insurance providers are and if care works differently in general.

like

Accenture just provided notice for mandatory vaccine and required to provide proof of vaccination

likeupliftingfunnysmart

Does GDC have a reputation as a good place to work in BL?

like

What do most people invest in for their Roth IRA portfolio? I’ve heard target funds and ETF’s..which one is better?

What’s the level of evidence of review needed for controls that are not management review controls (MRC)? I’m an internal auditor and I’m documenting what is needed for lower risk controls in the SOX environment.

Does management need to have review
comments or checklist even for low or medium risk controls? And should I document those? Thanks!

like

I just spoke with a software architect that went back to school to learn software engineering after law school because it was more lucrative and had less hours. He’s worked his way up and has the skills and authority to work 6:30am-10am and gets to work remotely. We discussed that results/outputs is better than billable time like in law and public accounting. Yet, his parents and others would view him as “lazy” but he does his job and makes a fantastic living. Time>Money and Results>Hours

likefunnysmart
like

Hi how is smartims company for experienced?

like
like
like

I can't help but giggle at Joe keep lookin down at his notes

likefunny

Additional Posts in Cyber Security Bowl

HMU for referrals

funny

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Any recommended study material for CIPP and/or CIPM (still debating the two)?

Thinking of moving from Big4 cyber to Accenture cyber. Any major differences (other than no channel restrictions).

like

Tell me it’s not true.

Post Photo
funnylike

Always bragging about how awesome they are. Awesome people dont brag. They just are

like

Deloitte Cyber, how long did it take you to receive an offer after final interview?

like

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

Tired of your job and want to come to KPMG Cyber Services? Drop me a burner here.

likefunny

What are exit ops for Big 4 Cybersecurity Consultants that are non technical (Strategy/Risk)?

like

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

Laterals to Deloitte Cyber from other B4: Can you describe your interview process and what each one entailed? TIA!

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

What is everyone's view on getting a Masters in Cyber security?

likefunny

Anyone currently enrolled or will be enrolled in the online masters cyber degree at Georgia Tech?

like

Joining a group that specializes in incident response. Any recommendations on things I can do this summer to prepare on fundamentals/certs?

like

Accenture or Deloitte for cyber security strategy? Who’s on top?

like

What other professional services firms have people who have technical skills. Most the people I work with are security paper pushers who couldn’t tell you basic security shit.

like

Have any of you pursued a graduate certificate in cyber security? If so, did you find any value in it? I currently have Bachelors and Sec+. I’m looking to obtain my AWS CCP in the few coming weeks and was looking for what to get next. I entertain the idea of continuing to pursue my education but I don’t want to incur too much debt with a masters.

like

Any BCG Platinion Cyber folks here?
What kinna work do you guys do? Planning to make the switch after 5 years with Uncle D. Wanna hear from you guys about culture, projects and areas of expertise.

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal