Skip to main content

ISACA Information Systems Audit and Control Association.

ISACA is the global association for IT audit, security, risk and governance professionals. Founded 1969, headquartered Schaumburg IL, 165,000+ members in 188 countries. Awards CISA, CISM, CRISC, CGEIT, CDPSE, AAIA, CCOA. Publishes COBIT. Cyber Academy is an ISACA Accredited Premium Partner.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyStandards bodiesAll entries

The Cyber Academy take

ISACA is the global association for IT audit, security, risk and governance professionals. Founded 1969, headquartered Schaumburg IL, 165,000+ members in 188 countries. Awards CISA, CISM, CRISC, CGEIT, CDPSE, AAIA, CCOA. Publishes COBIT. Cyber Academy is an ISACA Accredited Premium Partner.

What ISACA actually is

ISACA started in 1969 as the Information Systems Audit and Control Association, a group of IT auditors who needed a common body of knowledge and a way to certify each other's competence. The full name is now largely historical; the organisation goes by ISACA and serves IT audit, security, risk, governance, and privacy professionals across more than 180 countries. What matters in practice is that ISACA is not a regulator and not a standards body in the ISO sense. It does not write law and it cannot certify a company. It certifies people, and it publishes frameworks that the rest of the profession leans on.

That distinction trips up newcomers. You cannot become "ISACA certified" as a company the way you certify an ISO 27001 management system. ISACA credentials sit on individuals. An auditor earns CISA, a security manager earns CISM, a risk professional earns CRISC. The value of the badge comes from the exam rigour, the documented work-experience requirement, the code of professional ethics, and the continuing professional education that keeps it live. Employers and audit committees treat these as evidence that the person has been independently tested against a defined practice.

The credential family and what each signals

ISACA's certifications are deliberately role-specific rather than one general qualification. Each maps to a distinct job function, which is why practitioners often hold more than one as their career moves from doing the work to governing it.

ISACA certifications by professional role
CredentialAudienceFocus
CISAIS auditorsAuditing, control, and assurance of information systems
CISMSecurity managersGovernance and management of an information security programme
CRISCRisk professionalsIT and enterprise risk identification and response
CGEITGovernance leadersGovernance of enterprise IT at board level
CDPSEPrivacy engineersPrivacy by design in the technology stack
AAIAAI auditorsAuditing artificial intelligence systems and controls
CCOACyber operationsHands-on cybersecurity operations and defence

COBIT and ISACA's place in the standards landscape

Beyond certifying individuals, ISACA publishes COBIT, the framework for the governance and management of enterprise IT. COBIT is where ISACA comes closest to acting like a standards body, but it remains a framework you adopt and tailor rather than a standard you are certified against. Auditors reach for COBIT when an information security standard alone is too narrow, because it covers how IT as a whole is steered toward enterprise objectives. This is why ISACA, NIST, and ISO are usually mentioned together: NIST supplies control catalogues and outcomes, ISO supplies certifiable management standards, and ISACA supplies the audit and governance lens plus the people qualified to apply it.

For a training organisation, ISACA's partner programme matters because exam preparation has to follow an accredited curriculum to carry weight. Cyber Academy is an ISACA Accredited Premium Partner, which is the recognition ISACA grants to training providers that meet its quality bar for delivering official credential preparation. That accreditation is about the provider, not a substitute for the individual passing the ISACA exam and meeting the experience requirement.

Frequently asked questions

01Is ISACA a certification or a standard?

Neither exactly. ISACA is a professional association. It certifies individuals through credentials like CISA, CISM, and CRISC, and it publishes the COBIT framework. It does not write law and does not certify companies.

02What is the difference between ISACA and ISO?

ISO publishes standards that organisations can be certified against, such as ISO 27001. ISACA certifies people, not management systems, and publishes COBIT as a governance framework. Many practitioners use both: ISO for the certifiable system, ISACA credentials for the auditors and managers who run it.

03Which ISACA certification should I start with?

It depends on your role. IS auditors typically start with CISA, security managers with CISM, and risk professionals with CRISC. The certifications are role-specific rather than tiered, so the right one is the one matching your day job.

04Can a company be ISACA certified?

No. ISACA credentials belong to individuals. A company can become a recognised ISACA training partner or have staff who hold ISACA certifications, but the organisation itself is not certified against an ISACA standard.

05What does an ISACA Accredited Premium Partner do?

It is a training provider that ISACA has recognised as meeting its quality requirements for delivering official credential preparation. Cyber Academy holds this status. The partner prepares candidates; the candidate still sits the ISACA exam and meets the experience requirement independently.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.