CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingWhich ISACA certification fits your security role? We rank CISM, CRISC, CISA, CDPSE and the AI credentials by cybersecurity career value.

For most cybersecurity professionals, the best ISACA certification is the Certified Information Security Manager (CISM) — it is the only ISACA credential built squarely around running a security programme, and it is the natural target for anyone moving from hands-on security work into leadership. But "most" is doing a lot of work in that sentence. A risk analyst gets more from CRISC, a security auditor from CISA, and a privacy engineer from CDPSE. This article ranks ISACA's credentials by cybersecurity career value and then matches them to specific roles, so you can stop comparing acronyms and pick one.
Short answer: choose CISM if you lead (or want to lead) security teams and programmes; CRISC if your work centres on IT risk; CISA if you audit or assess security controls; CDPSE if you build privacy into systems. ISACA's newer AI credentials — AAIA and AAISM — are add-ons for people who already hold a qualifying certification, not starting points.
One framing point before the ranking. ISACA is a governance, risk, audit and security association, so its certifications reward management judgement rather than packet-level technical skill. If you want a credential that tests hands-on defence techniques, ISACA is not the obvious first stop — its performance-based CSX-P certification is retired and no longer available to new candidates. What ISACA does exceptionally well is certify the people who govern, measure and manage security, and those are the roles where its credentials carry serious weight. For a neutral map of every ISACA credential without a recommendation attached, see ISACA Certifications Explained.
This ranking weighs role alignment (how directly the credential maps to security jobs), seniority signal, breadth of demand, and accessibility. All four core certifications discussed here cost the same to attempt — as of 2026, US$575 for ISACA members or US$760 for non-members, plus a US$50 application fee after passing (confirm current fees on isaca.org) — so price does not separate them.
The Certified Information Security Manager is ISACA's flagship for security careers, and the fit is obvious from its domains: information security governance, security risk management, the security programme itself, and incident management. That is the job description of a security manager, a head of information security, or a CISO-track lead. Skillsoft's 2025 IT Skills and Salary research placed CISM among the highest-paying certifications, with a US average in the region of US$155,000 — pay varies substantially by location, sector and experience, and you should verify the current figure on Skillsoft's site, but the direction of the signal is consistent: organisations pay for certified security leadership.
Certification requires five or more years of information security management experience (waivers cover up to two years), which is precisely what makes it valuable — it cannot be shortcut by a strong exam performance alone, though you can sit the exam with no experience and apply within five years of passing.
One timing note: ISACA is updating the CISM exam content outline effective 3 November 2026, so check which outline you would sit before booking. The full domain, eligibility and application detail lives in our CISM Certification Guide, and if you are weighing the investment itself, Is CISM Worth It? gives the verdict.
Certified in Risk and Information Systems Control is the strongest pick when your security work is really risk work: risk assessments, control design, reporting to risk committees, third-party risk. Its four domains — governance, risk assessment, risk response and reporting, and technology and security — sit exactly where security functions meet enterprise risk management, a seam that keeps widening as boards demand quantified cyber risk.
CRISC is also slightly more accessible on paper than CISM or CISA: certification requires three years of relevant experience rather than five. The trade-off is that ISACA grants no experience waivers for CRISC at all. If you are torn specifically between the risk track and the security-management track, that decision has its own article: CRISC vs CISM. For everything the credential covers, see the CRISC Certification Guide.
The Certified Information Systems Auditor is ISACA's oldest and most widely held credential — the organisation reports more than 151,000 holders and cites an average salary above US$149,000 on its CISA page (ISACA's own figure, as of August 2026). For cybersecurity specifically, CISA ranks third not because it is weaker but because it is aimed at a different chair at the table: the person assessing security controls rather than operating them. Its 2024 exam content outline gives 26% weight to protection of information assets and another 26% to operations and business resilience, so a large share of the exam is security subject matter viewed through an assurance lens.
CISA is the right first ISACA certification for security consultants, third-party assessors, compliance-heavy roles, and anyone whose deliverable is an audit report or a controls opinion. Certification requires five years of IS audit, control, assurance or security experience, with waivers available for up to three years. The CISA Certification Guide covers the domains and process in full, and Is CISA Worth It? handles the cost-benefit question.
Certified Data Privacy Solutions Engineer is narrower, and that is the point. Its domains — privacy governance, privacy risk management and compliance, data lifecycle management, and privacy engineering (the largest at 39%) — target people who implement privacy by design rather than just write privacy policy. ISACA lists over 16,000 CDPSE holders and cites an average salary above US$150,000 (again ISACA's own figure, August 2026), which reflects a small, in-demand specialism.
For a security professional whose work touches data protection, DPIAs, or building compliant data pipelines, CDPSE is a strong differentiator. For everyone else it is a second certification, not a first. Note its exam differs from the core four: 120 questions in 3.5 hours, currently offered in English only. Certification needs three years of relevant experience with no waivers.
ISACA's two newest credentials are deliberately excluded from the main ranking because neither is open-entry. Advanced in AI Audit (AAIA), launched in May 2025, requires an active CISA or a listed audit/accountancy credential such as CIA or CPA. Advanced in AI Security Management (AAISM) requires an active CISM or CISSP. Both cost US$459 for members / US$599 for non-members — cheaper than the core exams — and AAIA runs 90 questions in 2.5 hours (AAISM's format is reported to match, but confirm against ISACA's own candidate guide).
If you already hold CISM and manage AI-related security risk, AAISM is arguably the most forward-looking stack ISACA offers right now: in ISACA's own May 2025 research, 85% of digital trust professionals said they would need to increase their AI skills within two years. Treat these as tier-two moves that amplify a core credential you have already earned.
Certified in the Governance of Enterprise IT is a genuine ISACA credential but a poor primary pick for cybersecurity: its domains centre on enterprise IT governance, benefits realisation and resource management, with security appearing only inside broader risk optimisation. It suits CIO-track and governance-office careers. Security professionals should reach it, if ever, after CISM.
Rankings are averages; roles are specific. Here is the match-up.
| Your role | Best ISACA pick | Why |
|---|---|---|
| SOC analyst / security engineer | CISM (as a mid-career target) | ISACA has no hands-on defence cert since CSX-P retired; CISM is the credential to grow into as you move towards team lead |
| Security manager, deputy CISO, CISO-track | CISM | Direct domain match: governance, programme, incident management |
| IT risk analyst / cyber risk manager | CRISC | Purpose-built for risk identification, response and reporting |
| IT auditor, security assessor, GRC consultant | CISA | The assurance profession's default credential |
| Privacy engineer / data protection specialist | CDPSE | Only major cert focused on engineering privacy into systems |
| AI governance or AI security lead | AAISM (after CISM/CISSP) or AAIA (after CISA) | Stacks AI-specific depth on a core credential |
Two clarifications that trip people up. First, CISM is not "CISA level two" — they are parallel tracks for different professions, and neither requires the other. If you are choosing between exactly those two, CISA vs CISM takes that head-to-head in depth. Second, every core ISACA exam can be sat with zero experience; the experience requirements gate the certification, which you can apply for up to five years after passing. That means an ambitious SOC analyst can pass CISM early and bank it while accumulating management experience.
If the table above did not settle it, answer these in order:
A realistic scenario: a security analyst with four years in a bank's second-line risk team wants to move up. CISM looks tempting because it is the "best" ISACA cert, but she has risk experience, not security-management experience — CRISC certifies her now, strengthens the promotion case for a risk-manager post, and leaves CISM as the follow-on once she is managing. Ranking by career value always bends to what your CV can actually support.
All the core certifications share ISACA's exam machinery: 150 multiple-choice questions in four hours (CDPSE excepted), a passing score of 450 on a 200–800 scale, year-round scheduling at PSI test centres or via remote proctoring, and a six-month eligibility window from registration. Maintenance follows ISACA's continuing-education model — a minimum of 20 CPE hours a year and 120 over each three-year cycle, plus an annual fee (US$45/US$85 verified for CISA; confirm your certification's figure on its ISACA maintenance page). ISACA membership usually merits a look before you register, since members pay US$185 less per exam attempt — check current dues on isaca.org to run that maths.
Whichever exam you pick, the scenario-style questions reward practising judgement, not memorising facts. Working through free sample questions for your chosen exam early tells you which domains need real study, and a timed practice-test simulation closer to exam day shows whether your pacing survives a four-hour paper. ExamPractice's CISM practice questions are a sensible benchmarking point if CISM is your target.
Book CISM if security leadership is where you are heading and you can evidence (or will soon evidence) management experience. Book CRISC if risk is your trade — it certifies faster and fits the role better than a "higher-ranked" credential you cannot yet support. Book CISA if assurance work pays your salary, and CDPSE if privacy engineering does. Skip ISACA altogether — for now — if what you need certified is hands-on technical defence skill; come back when your career turns towards governing security rather than executing it. The best ISACA certification is not the one at the top of anyone's list. It is the one whose domains describe the job you want next.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading