Figuring Out ISACA Certifications for Cybersecurity Careers: ③ CRISC

E. S. Nurcan
Technopolitics and Asia
3 min readApr 27, 2022

In this third piece of the “Figuring Out ISACA Certifications for Cybersecurity Careers”, I’m introducing the certificate titled Certified in Risk and Information Systems Control (CRISC). You can skip towards the end for more information on prerequisites and salaries you can earn with CRISC.

ISACA (Information Systems Audit and Control Association®) is one of the world’s leading education and certification center for IT professions including cybersecurity. Started in 1967 by a small group of individuals, ISACA has become a “… centralized source of information and guidance in computer systems as well as an education foundation to undertake large-scale research efforts to expand the knowledge and value of the IT governance and control field.” Accepted widely across sectors, ISACA offers a myriad of education programs in addition to powerful certificates.

A meeting room full of US military officers and civilians in front of a desk with computers and cables
A career level-up in cybersecurity is worth pursuing, but how? Image source: Creative Commons

Here are eight cybersecurity certificates offered by ISACA, with some of the certifications being cumulative ‘composites’ of several certificates:

  1. Information Technology Certified Associate (ITCA) (Read about it here)
  2. Certified Information Systems Auditor (CISA) (Read about it here)
  3. Certified in Risk and Information Systems Control (CRISC)
  4. Certified Information Security Manager (CISM) (Read about it here)
  5. Certified Data Privacy Solutions Engineer (CDPSE) (Read about it here)
  6. Certified in Governance of Enterprise IT (CGEIT)
  7. CSX Cybersecurity Practicioner (CSX-P)
  8. Certified in Emerging Technology (CET)

Let’s take a look at the third certificate on the list: Certified in Risk and Information Systems Control (CRISC). According to the information provided by ISACA, the CRISC is mostly for mid-level IT/IS audit, risk and security professionals looking for career growth in IT risk-related areas. Overall, CRISC is very useful for showcasing expertise in governance best practices and continuous risk monitoring and reporting. This type of expertise is currently in high demand as corporations look to enhance their business resilience and improve stakeholder value, not to mention achieve smoother regulation compliance.

Having CRISC in your CV will grant immense credibility in your interactions with internal stakeholders, regulators, external auditors, and customers. However, there is an experience requirement for taking up CRISC unlike ITCA. The applicant is expected to have 1–3 years of experience in IT risk and/or security and audit. Also, early career candidates are required to obtain IT Risk Fundamentals certificate. Having the CISA certification before starting is considered a plus. Making the effort to get the CRISC is meaningful if you are aiming to become either of these below:

The training for the certificate is completely knowledge-based without any hands-on lab-based training, so the process can be done entirely online. Since mid-career IT professionals can easily get a nice bump up in annual salaries with potential career switches, CRISC is worth pursuing for many of us interested in cybersecurity careers.

Source: History of ISACA, ISACA Credentialing, Glassdoor, Payscale, Indeed

Note: You can read more on ITCA here, CISA here as well as CISM.

--

--

E. S. Nurcan
Technopolitics and Asia

A hungry learner for cybersec, tech, and everything political. Öğreniyorum ve yazıyorum, teknoloji, siyaset ve biraz da Asya üzerine.政治、技術、アジア国際関係等について書く。