Home > Security News > Cert Spotlight: CISA focuses on information assurance
Security News:
EMAIL THIS

Cert Spotlight: CISA focuses on information assurance

By Edward Hurley, News Writer
27 Nov 2002 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

There are only a couple of security certifications that holders are sure to attach to their names on a business card. One of them is Certified Information Systems Auditor (CISA).

FOR MORE INFORMATION:
SearchSecurity.com news exclusive: "Cert Spotlight: CISSPs 'know' security"

SearchSecurity.com news exclusive: "Cert Spotlight: Hype is high over Security+"

SearchSecurity.com news exclusive: "Climate elevates importance of security certifications"

SearchSecurity.com news exclusive: "Vendor vs. independent training: Choosing the right path"


Feedback on this story? Send your comments to News Writer Edward Hurley

The CISA certification is right up there with Certified Information Systems Security Professional (CISSP) as the crÈme of the security certifications.

While the CISSP is more technology focused, the CISA is geared toward information assurance, said Peter H. Gregory, a consultant with the Woodinville, Wash.-based HartGregory Group and someone who holds both certifications. The CISA certification is focused more on business processes.

"To me, it signals the beginning of competence in both auditing and IT auditing, and it's proof that I can learn it, given the opportunity," said Leslie Van Sickel, a CISA who works for the Kansas Department of Social and Rehabilitation Services in Topeka. "Several people have been impressed, which is nice, of course, but mostly I got it for myself."

As its name implies, the biggest component of the CISA certification is auditing. "Historically, a lot of people with CISAs you met were in IT auditing with Big Six firms or in banking and finance," Gregory said.

Generally, companies might want their IT auditors and any consultants who do similar work to have the certification. People with CISSPs may want to consider the CISA because the certifications are complementary, Gregory said. "You would have good understanding of security but also of business process," he said.

The Information Systems Audit and Control Association has administered the CISA certification for the last 24 years. Today there are 29,000 CISAs worldwide. More than 10,000 people took the exam this year, though not all passed. It isn't easy. Unlike other certifications, the CISA exam is only given once a year.

"It was a stinker," Van Sickel said. "Several people there were taking it for the second time."

Exam questions focus on the following areas:

  • Management, planning and organization of IS (11%)
  • Technical infrastructure and operational practices (13%)
  • Protection of information assets (25%)
  • Disaster recovery and business continuity (10%)
  • Business application system development, acquisition, implementation and maintenance (16%)
  • Business process evaluation and risk management (15%)
  • The IS audit process (10%)

Generally, the CISA exam questions are situational, Gregory said. In other words, the taker needs to have some experience with auditing and the other subjects covered by the test. A question may begin: "'An organization wants to perform an audit of process blah, blah, blah,'" he said.

After passing the exam, the applicant must then certify they comply with the experience requirement of at least five years of "professional information systems auditing, control, or security work experience (as described in the job content areas)." A year of information systems or financial or operational auditing experience can be substituted for one of the five years.

An associate's degree can also count toward one year of experience. A bachelor's degree counts for two years.

The Information Systems Audit and Control Association is pretty strict when it comes to experience, Gregory said. "It's not enough to pass the test. Your employer has to sign off on your experience," he said.

Recipients also need to abide by a code of ethics.

Robust review materials are available from the Information Systems Audit and Control Association. At least one review book will be available by June of next year when the test is administered next, Gregory said.



Tags: Security Industry CertificationsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Industry Certifications
Straight from the inbox: Your infosec career questions answered
Despite recession, information security certification pay continues to climb
Creating a personal brand in information security
Some IT security certifications are overvalued, analyst says
Q2 2009 data shows IT security certification pay still climbing
An introduction to Information Security Career Advisor
Security jobs survey finds fewer budget cuts, lower security salaries
IT security skills and certification pay
Despite recession, pay climbs for top IT security certifications
How do I transition to a career in IT security?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts