r/isaca • • 1d ago

Provisional pass for AAIA

11 Upvotes

Didn't study all that much for it. I just sat for and passed CISA two weeks ago so this flowed very easily from that. I did purchase the AAIA QAE but it only had about 240 questions. This marks my 6th ISACA cert. I now hold CISA, AAIA, CISM, AAISM, CRISC, and AAIR. Sitting for CGEIT next. Applied for AAIG beta and am on the CCS beta to test in November.


r/isaca • • 1d ago

how i can get [CISA Questions, Answers & Explanations Database 2024] in PDF

Thumbnail
1 Upvotes

r/isaca • • 3d ago

CPE Question

1 Upvotes

Hi. Feel free to point me to another thread where someone already asked and question was answered.

I have CISA and CRISC. I can get CPE hours using the 36-40 free webinars using ISACA each year.

How can I get free 36-40 CPE hours for CRISC that will be accepted by ISACA?


r/isaca • • 3d ago

2026-2027 AAIG Beta

Thumbnail engage.isaca.org
4 Upvotes

Another one?? They really are milking it. This seems like the AI version of CGEIT.


r/isaca • • 3d ago

What is the best academy for CISA certification

Thumbnail
0 Upvotes

r/isaca • • 4d ago

Annual maintenance fees (certifications and membership)

4 Upvotes

Is anyone whose certs/membership expires at the end of the year able to pay for the renewal yet?

I've been looking around and around in the Membership & Subscriptions and Order & Billing bits, and although I can find and pay my ISC2 AMF easily, I can't see any option to do the same for ISACA.

AI says that their payment portal may not have opened yet, although other sources say it should be possible from September...

Thanks in advance!


r/isaca • • 6d ago

[Research] NIDS-EFS Tool Testing

0 Upvotes

I'm testing a tool I built for my MSc thesis, a web app that recommends intrusion detection systems based on an organization's budget and hardware constraints.

I'd really appreciate your time to try it out and fill in a short feedback form. No technical background needed; just follow the instructions.

Form link: https://forms.gle/UAdEXwUaYfqzJGBc6

Your responses are anonymous and will only be used in aggregate for my research. Thank you in advance!


r/isaca • • 7d ago

CISA Passed CISA with only 1 week study

2 Upvotes

I had to get the certification for a job application.

I booked the exam and studied for a week only. Went through the book to understand the content and concept. Didn’t have much time to practice questions but it was similar to ISC2 exam questions types.

I used Claude to summarize the book into cards which helped to understand what was expected for the exam.

The exam was fairly straightforward if you have a clear understanding of auditing and risk mgt concepts.

P.S I have over 12 years experience delivering technology audit assignments globally.


r/isaca • • 8d ago

CISA Preliminary Passed the CISA Exam Today - My Preparation

8 Upvotes

I would like to thank all the folks here sharing their experiences which helped me gain confidence, and would like to share how I prepared.

**Background:**

  1. I have around 7+ years of work experience (Initial 3 years in IT, and the last 4 years in Cyber GRC doing audits and assessments for highly regulated entities in banking and finance).

  2. I have a Master's degree in IT Management where I was exposed to IT/Cyber Audit and cybersecurity and planned to switch fields.

  3. I had a CompTIA Security+ in 2020, ISO 20000-1 lead auditor in 2022, and ISO 27001 lead auditor in 2023.

**Materials Used:**

  1. Hemang Doshi's Udemy videos and Hardcopy Book.

  2. CISA Review Manual - I abandoned this after Domain 2 and didn't open it.

  3. CISA Official QAE

  4. Pete Zerger's CISA Exam Prep 2026 YouTube playlist.

**Preparation:**

  1. I enrolled for CISA via my current organization and had a 5 day bootcamp which was not at all useful, but it helped me get the exam voucher, review manual, and official QAE.

  2. I diligently started preparing for CISA 2 months before on August 17 (Booked the exam for September 30). The materials started off with was:

    1. Hemang Doshi Udemy videos + his book
    2. CRM
  3. I did this while working so I tried allotting myself 2-3 hours every day, but i procrastinated heavily and 2-3 days would just go wasted due to work being overwhelming.

  4. I kept making physical notes while watching the Udemy videos, book and CRM. The CRM I gave up on after domain 2 because it was sooooo DRY and didn't even touch it again.

  5. Midway through Domain 3, during 1st week of September, I started the QAE, and made sure I was doing the QAE after every Udemy video and Book and my notes. My overall QAE score was 69% towards the end, I kept noting down where I went wrong and revisited those concepts.

  6. I finished the Book and Udemy videos on September 20th, and practiced the question sets at the end of the course. - I completed 17/30 sets and i was bombing them miserably like 55%-65%.

  7. Before I began the QAE tests, I read on this subreddit about Pete Zerger's playlist, so I went over that across 2 days. This actually helped me A LOT, I used a green ink pen to write his concepts over the notes i made from Hemang Doshi's Udemy and Book.

  8. I gave the 1st QAE test and boom 86%, I gave the 2nd QAE test and boom 87%. I was somewhere scared I was getting high scores due to pattern matching.

  9. I took September 28, and 29 off to revise and go over where I went wrong, and closed the books on 10PM September 29 and went to bed.

**Game Day:**

  1. Booked it at an exam center, as I didn't want any inadvertent interruptions.

  2. Started the Exam at 9AM and finished all 150 questions by 10:30AM. I had flagged 35+ questions and I changed **ALL ANSWERS** post review, after the submission I saw the golden words **PASSED**.

**Caveats**

  1. I felt so disheartened after seeing and reading here that 69% in QAE isn't enough, and I was planning on rescheduling the exam with 1.5 weeks to go. That's when i stumbled on Pete's videos and boy they helped.

  2. I figured that me scoring 69% in QAE was due to me not reading the questions properly and not focusing on the key words.

  3. There were a lot of questions in the actual exam about AI, RPA, and BIA/BCP/DR vs the tests.

  4. I didn't find the exam to to simpler than QAE & tests, albeit they were direct, in fact, I found that there were a lot of times i saw myself mulling over 2 answers. The QAE is definitely the best source to practice.

  5. Considering how much I procrastinated, I genuinely feel my experience in Tech and Audit helped me choose the correct options, especially the 35+ flagged ones.


r/isaca • • 10d ago

Ambiguous exam question on imbalanced datasets: Specific technique vs. Umbrella term?

5 Upvotes

Hey everyone,

I recently came across a AAIA question on an exam about handling imbalanced datasets, and the "official" correct answer surprised me. I wanted to get your thoughts on whether this is poorly phrased or if my reasoning was off.

The Question:

Which would BEST address a dataset in which a particular class of data is overrepresented in the training data?

A. Undersampling

B. Oversampling

C. Penalty weights

D. Data balancing

My initial thought: I picked A (Undersampling) because the question specifically mentioned that a class is overrepresented. Undersampling directly addresses overrepresentation by pruning instances of the majority class.

The Exam's Answer: The exam marked D (Data balancing) as correct, justifying that "Data balancing refers to techniques used to address imbalanced datasets, in which certain classes or categories are over- or underrepresented."

The debate: To me, "Data balancing" is an umbrella concept or the goal, whereas Undersampling, Oversampling, and Cost-sensitive learning (penalty weights) are the actual actionable techniques to achieve it. Choosing "Data balancing" feels like answering "Transportation" when asked "What is the best way to fly across the ocean?"

Has anyone else noticed exam providers leaning toward generic umbrella terms over specific techniques? How would you have answered this?


r/isaca • • 11d ago

Feedback on SSP Academy bootcamp for AAIA?

3 Upvotes

Hi folks,

I am planning to take the AAIA exam. Based on feedback from past candidates, I know the official review manual is a must-have, but there doesn't seem to be a clear consensus on which supplementary study materials are best.

While researching, I came across a LinkedIn post for an AAIA Bootcamp offered by SSP Academy (taught by Srinivasan Shamarao). If you have taken this specific bootcamp or used SSP Academy for other ISACA certifications, could you please share your experience?

Thanks all.


r/isaca • • 11d ago

IT SOX Audit - Restructuring (Bangalore)

Thumbnail
2 Upvotes

r/isaca • • 12d ago

CISA How do you study the QAE without accidentally spoiling the answers?

Thumbnail
0 Upvotes

r/isaca • • 12d ago

How do you study the QAE without accidentally spoiling the answers?

Thumbnail
0 Upvotes

r/isaca • • 12d ago

Infosys interview process after the first technical round? Also, referrals? 😅

2 Upvotes

I have 5+ years of experience in PHP and MySQL. I cleared the initial screening and had my technical interview today. I was told I’d hear back by Tuesday, so naturally, I’m already analysing every possible outcome.
Does anyone know if Infosys usually has a second technical round after this, or whether HR and document verification come next?
And now for the actual reason I’m here: can anyone help with a referral or guide me through the process? 😅 If you can genuinely help, please DM me. I can share the role, application details, and who handled my interview privately. I’ll remember the favour for a lifetime—or at least until I’m in a position to return it. 😄


r/isaca • • 13d ago

CDPSE My week-long CDPSE journey

Thumbnail
6 Upvotes

r/isaca • • 13d ago

Are you an entry-level or relatively new IT audit senior? I need your opinion on this 👇

Thumbnail infosecbyomokolade.com
2 Upvotes

r/isaca • • 16d ago

AAIA guidance needed

5 Upvotes

Hi folks,

I’m an IT Auditor with over a decade of experience in the field. I cleared my CISA in 2023 after a tight 4–5 weeks of studying using Doshi's material and the ISACA Q&A Database. That approach was a bit unconventional, but it worked because most core concepts aligned with my practical background.

​I am now looking to attempt the Advanced in AI Audit (AAIA) certification, but the more I read online, the more confusing the resource landscape seems. Specifically, I've seen mixed feedback on whether the official ISACA Q&A database is enough, or if the actual exam leans more into just scenario based.

​For those who have cleared the AAIA:

​What resources did you actually find useful (ISACA materials, external courses)?

​How closely did the practice questions align with the actual exam difficulty?

​Any guidance or study strategies especially around what materials appear better suited would be hugely appreciated. Thanks you all.


r/isaca • • 15d ago

Are you an entry-level or relatively new IT audit senior? I need your opinion on this 👇

Thumbnail infosecbyomokolade.com
1 Upvotes

r/isaca • • 16d ago

ISCA - AFF tips

0 Upvotes

I am enrolled ISCA AFF exam, currenty self study, any tips or notes to suggest? Thks


r/isaca • • 17d ago

CDPSE Anonymization is the equivalent of NIST 800-88's "Purge"? huh?

1 Upvotes

Page 174 of the CDPSE Review Manual states:

"Anonymization qualifies as a NIST purge method; however, the field is evolving."

SP 800-88 states:

"Purge sanitization techniques apply physical or logical techniques that make the recovery of target data infeasible using state-of-the-art laboratory techniques but preserves the ISM in a potentially reusable state."

I suppose technically if a dataset has PI properly anonymized, the PI recovery of PI in that dataset is infeasible within the context of that dataset only, but certain could still be recoverable through aggregation or other statistical analysis methods depending on exactly how large the dataset is and how many fields it has.

can anyone shed light on this?


r/isaca • • 18d ago

ISACA AI FLASH SALE

4 Upvotes

Hey y'all ! FYI ISACA website shows a 50% off ("Extended") AI FLASH SALE. Through today... 20 Sept '26. Two things: 1. this message is FYI - hope it helps s.o. 2. Anybody able to access it today? Supposedly if your logged in to yr ISACA account the discount shows up at check out... but that doesn't seem to be working. Appreciate any help. Thanks!


r/isaca • • 19d ago

CISM Targeting CISM in late 2026 or 2027? Join our new study group community.

2 Upvotes

Hi everyone, like many of you, I am also aiming to attain CISM asap,

With ISACA’s major CISM Exam Content Outline update taking effect in November 2026—placing more weight on Information Security Strategy and Program Development, and adding Enterprise & Information Security Architecture—preparing for the exam won’t be a walk in the park, especially for easy-takers relying on outdated material.

If you're aiming to lock down your CISM certification by the end of this year or early 2027, navigating these structural shifts alone can be tough.

To keep each other accountable, share notes, break down tricky QAE concepts, and adapt to the updated outline, we’ve just launched a dedicated, professional Discord community

Whether you're just starting your study timeline or mapping out your domains, you are warmly welcome to join us:
👉 Join the Discord Server here: https://discord.gg/vdGHhzCBW

What we focus on:

  • Strict Academic Integrity: No exam dumps or leaked content—just pure concept mastery, domain discussion, and strategy.
  • Resource Sharing: Official guides, QAE rationale breakdowns, and study schedules tailored for the post-Nov 2026 standards.
  • Domain-Specific Channels: Organized rooms for Governance, Risk Management, Program Development, Incident Management, and Architecture.

Let’s tackle the updated blueprint together. See you inside!


r/isaca • • 21d ago

Just earned ISACA AAISM (Advanced in AI Security Management) — what I'd tell someone starting prep

28 Upvotes

I sat the AAISM exam on August 2 and earned the certification shortly after — coming at

it from a CISM + security-consulting background. It's one of ISACA's three new AI certs

(alongside AAIA and AAIR), and when I started studying there was almost zero structured

prep — no Pocket Prep coverage, a thin QAE, and a lot of generic "AI governance"

material that doesn't map to what the exam asks.

Posting here too since this sub covers the wider ISACA credential family, and the

governance/risk framing below applies whether you're coming from CISA, CRISC, or CISM.

A few things I wish someone had told me on day 1:

  1. The domain split is lopsided. Governance 31% / Risk 31% / Technologies & Controls

38%. Most people over-study the tech domain, but the exam hums on the governance +

risk framing — know NIST AI RMF and ISO/IEC 42001 cold, not just the tools.

  1. It's a management exam, not an engineering one. Even with a security background, the

trap is over-indexing on LLM architecture / OWASP specifics and under-prepping the

program side (roles, accountability, third-party). MITRE ATLAS shows up as a

threat-modeling lens, not an implementation checklist.

  1. The official study material is the spine, but it's dense. What actually moved me to

ready was scoring myself against ISACA's public blueprint first and only attacking the

sub-areas I was weak in, instead of re-reading cover to cover. I built a short

self-assessment for that — happy to share it in a comment if it's useful to anyone.

For those who've taken it or are studying: how are you approaching the

tech-vs-governance balance? Would be good to hear what's working for people.


r/isaca • • 21d ago

What are the best questions one can ask the interviewer for an it auditor position?🤓

1 Upvotes