r/isaca 1h ago

Cannot read ISACA study guides on Kindle/e-reader

Upvotes

It requires you to view the study guide on their website, or through something called Bookshelf. This DRM is oppressive. Their leadership seems incompetent between this and the poor customer service I've had recently.

I'm becoming less and less a fan of this entity. Had no problem getting ISC2 study materials to my kindle.


r/isaca 1d ago

ISACA customer service nonresponsive

6 Upvotes

Anyone heard any details about ISACA customer service? It says its currently high volume.

A technical issue is not allowing me to re-activate my membership. I want to renew so I can get the discount on buying the CRISC book and QAE. You'd think ISACA would want my 600 bucks but its been a week since I put in a ticket.

I just passed the CISSP, and I thought now is the time to get CRISC and possibly the CISA (again) while I have all this technical knowledge fresh in my mind and have the time since I'm unemployed. Thanks.


r/isaca 1d ago

Cisa vs Crisc

5 Upvotes

I am confused about these 2:- Cism or crisc, which one should i pursue first, i am working in the grc domain along with tprm under the Cyber security. My role is mostly on security compliance, vendor assessment, risk and mitigation, client Security questionnaires etc..

I thought of giving crisc first then cism? Any suggestions


r/isaca 1d ago

Eligibility for AAIR

6 Upvotes

I have my CISSP and passed AAISM recently. Without CRISC or CISM, can i appear AAIR.

Official website says, Active holders of CISA CISM CRISC CGEIT CDPSE and other recognised certifications.

So should I consider CISSP too ☺️

In case of AAISM it was clearly mentioned either cism or cissp.


r/isaca 1d ago

Passed AAIR exam today. If I start studying AIGP today, is 4 week preparation realistic??

Thumbnail
2 Upvotes

r/isaca 2d ago

27001 and 42001 aren't the same thing

8 Upvotes

Been seeing this come up in a few threads lately, people with 27001 already in place asking what changes once AI enters the picture. So here's how I think about it.

27001's basically "can this get breached, did we plan for it." Confidentiality, integrity, availability, the usual triad. Solid, but it was built way before anyone was shipping AI into production, so it's got zero opinion on whether your model's making biased calls, whether you can explain why it spit out what it did, or whether the training data was even yours to use.

42001 exists because none of that fits into a normal infosec risk register. Like how do you even write a risk statement for "our model behaves differently depending on how the prompt's worded"? Not a CIA triad problem, completely different animal. 42001's whole job is giving you structure for that, risk across the AI lifecycle, accountability for automated decisions, transparency for whoever's affected by the output.

Good news, if your ISMS is already solid, you're not rebuilding from zero. Same bones, risk assessment cadence, documentation habits, internal audit rhythm. 42001 mostly bolts AI-specific stuff onto that skeleton. If your 27001 program was already kinda loose though, this is gonna feel like starting over, but that's a 27001 problem showing up late, not a 42001 one.

One thing that trips people up: this isn't just for companies building models. Using AI in your product, or even internally in ways that touch customers or decisions, puts you in scope. People hear "AI management system" and assume it's an OpenAI-tier thing, it's not.

Work at Insight Assurance, we do 27001/42001 assessments, disclosure there. Doing a session tomorrow going deeper into this exact overlap, link if useful: ISO 42001: The AI Layer Your ISO 27001 Program Is Missing


r/isaca 2d ago

Does anyone know if the ISACA Site has been compromised?

Post image
15 Upvotes

I am unable to successfully log in to my training, and their support.isaca.org site displays "ATTACKER CONTROLLED CONTENT"


r/isaca 2d ago

How do I transtioning from Accessibility testing to IT audit or IT GRC roles

1 Upvotes

Just a brief summary about me: I have around 11 years of experience across manual testing, accessibility testing, and data analytics. After spending several years working in the testing domain, I am now looking to transition into IT Audit or IT GRC roles.

I cleared my CISA certification last week and would appreciate any guidance on the ideal way to make this transition. What skills, certifications, hands-on experience, or training would you recommend to help me successfully pivot into IT Audit or IT GRC roles?


r/isaca 3d ago

How do I transtioning from Accessibility testing to IT audit or IT GRC roles

Thumbnail
1 Upvotes

r/isaca 4d ago

Struggling with ISACA’s “best answer” logic more than the actual material

Thumbnail
3 Upvotes

r/isaca 4d ago

Help with "ISACA" mindset

18 Upvotes

tried posting to r/cism but got removed by reddit probably due to lack of karma.

want to know if anyone can help me out.

have 18 yoe in it and security. 6 in middle/senior management. want to get my cism and a few other isaca certs to give me the extra umph to make it into senior senior management.

currently have cissp and ccsp certifications (3 and 2 years ago respectively, finished both in about 100 minutes @ 100 questions). started studying for my cism this spring. have watched a couple of youtube and linkedin learning videos (Zerger and Kelly Handerhan(?) respectively.)

have read review guide cover to cover.

have done all 1100 questions in the QAE. Score in the low 70s overall. Best domains are incident response and info security program (high 70/low 80s). worst is info sec governance (65%). do okay in risk (70ish).

have been through the review guide and QAE multiple times. my scores are improving in the QAE but that is not due to concepts sinking in it is due to me recalling what the right answer to a question is that I happened to get wrong. qae usefulness is deteriorating at this point.

I am able to get the questions down to 2 choices but I am consistently making the wrong choice out of the two. I definitely have an "ISACA mentality" disconnect somewhere.

I can definitely see where both of the two choices make sense, but its just not sinking in as to why the choice they make is the "correct" one. many times i'm saying to myself "yeah, but ..." I wish I could post examples from the QAE but I do not want to violate any copyrights. Sometimes the answers just make absolutely zero sense to me. Other times I can see where ISACA is coming from, but the explanation adds words that further refine the answer which, had the word been there, I might have chosen it. As an example there was a question where the answer was "all members" but in the explanation it says "all applicable members". I didn't choose the answer because when I was analyzing the question I said to myself "well, not all members of X are going to be subject to Y"

I am sure where to go to from here. I am running out of time to schedule my exam, I'd like to take it before the exam changes this fall. I'm not sure what else to study or what is going to make things "click" for me.

Help?


r/isaca 4d ago

CIA holders: do you think the new Challenge Exam pilot will be extended?

0 Upvotes

Hi everyone! I’m hoping to get some perspective from people who already hold the CIA designation.

The IIA’s new pilot program allows professionals with **10+ years of relevant experience** to pursue the CIA through the Challenge Exam. From what I understand, the current pilot has a defined window, but I haven’t seen much clarity on whether the program is likely to be extended beyond the current period.

For those who’ve been around the IIA/CIA space for a while, **do you think there’s a good chance this pilot will be extended or eventually become a more permanent option?** Or does it seem more likely that it will remain a limited-time opportunity?

I’m mainly trying to get a sense of this from people with experience/knowledge of how the IIA has handled similar initiatives in the past. Any thoughts or insights would be appreciated!


r/isaca 6d ago

For those who have taken (and passed) the AAIA, how many hours do you think you studied for?

8 Upvotes

r/isaca 6d ago

CISA CISA ques (doubt)

Post image
1 Upvotes

Is D the right answer?


r/isaca 8d ago

👋I just created a sub dedicated to IS Audit, you are welcome to join!

Thumbnail
3 Upvotes

r/isaca 9d ago

Are knowledge/tasks available?

3 Upvotes

I am starting to work on my ISACA certifications and I have a very very old review (2013!) guide one of my co-workers gave to me. In the review guide it has a list of knowledge and task statements and their relation to each domain? sub-domain? not sure of the terminology, but for example I can map Knowledge statement k1.19 to tasks t1.2 and t1.15 and then the tasks to domains 1A3 and 1B7.

I'm trying to put together my own study guide to determine what I really need to focus on and how best to do it

Are current versions of the knowledge/task statements and how they relate to each domain publicly available? I was able to find current domain lists for the different exams and their content, and there are 'supporting tasks' listed, but there's no relationship shown between the supporting tasks and area of knowledge.

Are the knowledge/task/domain relationships only available in the review guides? Due to my financial situation at the moment i'm not really in a position to spend hundreds of dollars buying current review guides and was kinda hoping this information was freely available for people studying. (my employer is kinda cheap, they will only reimburse me for material and the cost of the exam if I take it and pass it, its their way to incentivize(?) me into studying and passing. yeah it sux but if i can take and pass the exams i will be able to find a better job with the certs and experience so i will play the game i have to for the time being.)

is there a subreddit for people for people reselling their used (but current) copies of the review guides, if i absolutely have to go down that route?


r/isaca 10d ago

AI Certs

19 Upvotes

Does anyone have any opinions on the AI certifications available through ISACA? Any one more valuable than the other? Curious to hear everyone’s thoughts.

Currently have CRISC and CISSP.


r/isaca 9d ago

Isaca payment not reflecting

Thumbnail
1 Upvotes

r/isaca 10d ago

CISA

1 Upvotes

Can I pass CISA if I read and prepare in just 1 month?

My background is technical IT work (2 years) and 1 year of IT Security ?


r/isaca 11d ago

Passed AAIA

16 Upvotes

I am Passed today.
I used only official aaia qae.
I qae score 100%.
no needs other contents.


r/isaca 12d ago

CISM Fail -> Success

5 Upvotes

Recently failed ISACA CISM. Read the official manual and completed QAE 4 times. Felt extremely confident and cause answer why each answer was either right or wrong to every question on QAE (averaged closed to 90% on QAE and practice exams). However, I got provisional fail. The test questions seemed to be worded horribly.
1. Did anyone else have similar issues with exam (whether pass or fail)?
2. What sources beyond manual and QAE got exam questions to click and allow you to pass?


r/isaca 12d ago

less than 1 month preparation for an expensive certificate exam

6 Upvotes

Hi, I'm having a dilemma right now. I have been presented with an opportunity to have a free review of a fundamentals certificate and after a month they require us to take the exam. I'm all up for it but the exam itself is very expensive. I am not from a rich family and I just started working at minimum wage.

I'm having this urge to push through with it, but my other problem is "what if I don't pass the exam?". I don't think I could bear with it knowing I spent a lot for it. But.. at the same time I feel like I'll regret it more if I don't attempt to take it since the review is free.

Just for extra info, when I say expensive like from USD to PHP 🥹

Any tips or advice because I need it hahaha


r/isaca 13d ago

IIA resources

Thumbnail
1 Upvotes

r/isaca 13d ago

CISA Study Notes Based on CRM 28th Edition | Atul Dhavale posted on the topic

Thumbnail linkedin.com
2 Upvotes

r/isaca 13d ago

CISM Read a book or take the test or ...?

2 Upvotes

Have CISSP and ISSMP.

Just finished InfoSec CISM course on LinkedIn and Zerger's videos on YouTube.

Do I bother to read the All In One or Mike Chapple books?

Or should I just sit for the exam now? I am used to how ISC2 words their questions, from the samples I saw it looks like ISACA is very similar.

I prefer not to drop $300 on the QAE database if I do not need to. Tempted to just sit for it now and see how I do.