CISM/CISA/CISSP

curryudon

Junior Member
Joined
Jul 15, 2008
Messages
63
Reaction score
0
i'm looking to take up one of these certification. my superior suggested CISA but i researched that CISA mostly paired with CPA. I'm hesitant on CPA because it takes 3yrs and lots of $. I'm from IT background and no exp in accountancy.

anyone has any of these certifications and what positions you work in for these certs to be useful?
 

seawyk

Senior Member
Joined
Jan 1, 2000
Messages
590
Reaction score
3
CISA is Certified Information System Auditor. Dun really think it is really that related to CPA (Certified Public Accountant) unless you are referring to something else.

CISA is good if you are doing IT audit work, either as a internal auditor or with a consulting company. It covers areas where companies need to look at from a governance perspective. Passing the exam does not make you a CISA, you then need to apply to be one and for that, you need 5 years of relevant experience.

If you have a CISA without relevant experience to back you up, the certification may not really be helpful as companies looking for CISAs usually want those with relevant experience.

I have CISSP, CISA and CISM because I need it as part of my work. But between the 3, i would feel that CISSP would probably be the most popular and widely accepted certification today.

Hope this helps
 

curryudon

Junior Member
Joined
Jul 15, 2008
Messages
63
Reaction score
0
thanks for replying. i'm intending to do IT auditing in the long run so i'm looking at the various requirements in job descriptions to see if i'm capable of landing myself in the job. From what i've seen, IT auditing and internal auditing is separated by a thin line. anything towards internal auditing requires some sort of accountancy knowledge. This is deterring me from working towards IT auditing because i'm afraid the grey areas will be against me when i don't have any accountancy certificatoins.
 

d24roam

Member
Joined
Nov 1, 2008
Messages
193
Reaction score
0
CISA is Certified Information System Auditor. Dun really think it is really that related to CPA (Certified Public Accountant) unless you are referring to something else.

CISA is good if you are doing IT audit work, either as a internal auditor or with a consulting company. It covers areas where companies need to look at from a governance perspective. Passing the exam does not make you a CISA, you then need to apply to be one and for that, you need 5 years of relevant experience.

If you have a CISA without relevant experience to back you up, the certification may not really be helpful as companies looking for CISAs usually want those with relevant experience.

I have CISSP, CISA and CISM because I need it as part of my work. But between the 3, i would feel that CISSP would probably be the most popular and widely accepted certification today.

Hope this helps

hi,

could you probably advise further how is the path towards CISSP
for a <2yrs Server network IT Experience, with CCNA , MCITP Server Admin, and ITIL FOundation. currently studying RH Linux exterprise admin.

thanks
 

seawyk

Senior Member
Joined
Jan 1, 2000
Messages
590
Reaction score
3
hi,

could you probably advise further how is the path towards CISSP
for a <2yrs Server network IT Experience, with CCNA , MCITP Server Admin, and ITIL FOundation. currently studying RH Linux exterprise admin.

thanks

CISSP also needs 5 years experience although this can be in any of the 10 domains covered by CISSP.

If you have only two years, you can get a exemption if you have a university degree, but this is only for 1 or 2 yrs. Other security certifications like CISA/CISM/CEH will also get you exemptions, but probably not for your current certifications. You would probably need a couple of years more of experience before you can apply to be certified as a CISSP.

But seriously, in terms of practicality, the CISSP course is a very good course to attend as it is very comprehensive in covering all the various areas of security. Even if you may not qualify in terms of experience, you should not let that stop you from learning from it as this will definitely be helpful to you in your job
 

seawyk

Senior Member
Joined
Jan 1, 2000
Messages
590
Reaction score
3
thanks for replying. i'm intending to do IT auditing in the long run so i'm looking at the various requirements in job descriptions to see if i'm capable of landing myself in the job. From what i've seen, IT auditing and internal auditing is separated by a thin line. anything towards internal auditing requires some sort of accountancy knowledge. This is deterring me from working towards IT auditing because i'm afraid the grey areas will be against me when i don't have any accountancy certificatoins.

may not be able to help you much there as I dun touch financial auditing which does require you to have financial background.

Even for Internal Auditors, there are those that specialise in IT audits, and these do not really need CPAs to be one

For example, ISO20000 and ISO27000 auditors are definitely more IT then Finance/Accounting
 

d24roam

Member
Joined
Nov 1, 2008
Messages
193
Reaction score
0
CISSP also needs 5 years experience although this can be in any of the 10 domains covered by CISSP.

If you have only two years, you can get a exemption if you have a university degree, but this is only for 1 or 2 yrs. Other security certifications like CISA/CISM/CEH will also get you exemptions, but probably not for your current certifications. You would probably need a couple of years more of experience before you can apply to be certified as a CISSP.

But seriously, in terms of practicality, the CISSP course is a very good course to attend as it is very comprehensive in covering all the various areas of security. Even if you may not qualify in terms of experience, you should not let that stop you from learning from it as this will definitely be helpful to you in your job

hi seawyk

thanks very much for your advise,

so, while working towards gaining more experience, if i were to get a security cert prior to cissp, is the CEH Best recommended? or what kind of security cert i am qualify to take up now and its good towards cissp?

sorry for trouble
 

raynor21

Member
Joined
Jun 13, 2002
Messages
346
Reaction score
0
hi seawyk

thanks very much for your advise,

so, while working towards gaining more experience, if i were to get a security cert prior to cissp, is the CEH Best recommended? or what kind of security cert i am qualify to take up now and its good towards cissp?

sorry for trouble

Not so much as to focus on which cert to attain before CISSP but which areas of IT security to learn and understand. There's a lot of reading for CISSP (10 domains). You should try to get familiar with each domain by reading up on them.

* Access Control
* Application Development Security
* Business Continuity and Disaster Recovery Planning
* Cryptography
* Information Security Governance and Risk Management
* Legal, Regulations, Investigations and Compliance
* Operations Security
* Physical (Environmental) Security
* Security Architecture and Design
* Telecommunications and Network Security
 

bakasa2002

Supremacy Member
Joined
Jul 26, 2006
Messages
6,308
Reaction score
3
If you have only two years, you can get a exemption if you have a university degree, but this is only for 1 or 2 yrs. Other security certifications like CISA/CISM/CEH will also get you exemptions, but probably not for your current certifications. You would probably need a couple of years more of experience before you can apply to be certified as a CISSP.

Max waiver of the 5 years needed for CISSP is 1 year, either using a degree, or professional certification like CISA, so technically you will still need 4 yrs of experience and another CISSP to endorse you.

Hope this helps. ;)
 

seawyk

Senior Member
Joined
Jan 1, 2000
Messages
590
Reaction score
3
Not so much as to focus on which cert to attain before CISSP but which areas of IT security to learn and understand. There's a lot of reading for CISSP (10 domains). You should try to get familiar with each domain by reading up on them.

* Access Control
* Application Development Security
* Business Continuity and Disaster Recovery Planning
* Cryptography
* Information Security Governance and Risk Management
* Legal, Regulations, Investigations and Compliance
* Operations Security
* Physical (Environmental) Security
* Security Architecture and Design
* Telecommunications and Network Security
Yes, Raynor21 is absolutely right... certifications are simply a validation of what you know.. and that is more important for your work

Focusing on the domains would be mush more useful than just focusing on the certifications
 

curryudon

Junior Member
Joined
Jul 15, 2008
Messages
63
Reaction score
0
may not be able to help you much there as I dun touch financial auditing which does require you to have financial background.

Even for Internal Auditors, there are those that specialise in IT audits, and these do not really need CPAs to be one

For example, ISO20000 and ISO27000 auditors are definitely more IT then Finance/Accounting


So far, i can't seem to find job openings related to IT audits. Usually the positions branch off from Internal auditing (thus require financial background). And this is so depressing, I don't know if i should continue searching in this direction.
 

seawyk

Senior Member
Joined
Jan 1, 2000
Messages
590
Reaction score
3
So far, i can't seem to find job openings related to IT audits. Usually the positions branch off from Internal auditing (thus require financial background). And this is so depressing, I don't know if i should continue searching in this direction.
start off with doing the regular IT work first... you really can't do auditing based on theoratical knowledge on stuff you have never touched on
 

raynor21

Member
Joined
Jun 13, 2002
Messages
346
Reaction score
0
So far, i can't seem to find job openings related to IT audits. Usually the positions branch off from Internal auditing (thus require financial background). And this is so depressing, I don't know if i should continue searching in this direction.

I don't know where you hunt for jobs but I think you are probably looking at the wrong places. It took me less than 5 mins to find the job openings (from www.jobsdb.com.sg) below that are related to IT audit. Maybe you can widen your search and I'm sure you can find what you want.

(http://www.jobsdb.com/SG/EN/Search/...ta=null&Webflow=MainPage&popupChildWindowId=1)

(http://www.jobsdb.com/SG/EN/Search/...ta=null&Webflow=MainPage&popupChildWindowId=2)
 

curryudon

Junior Member
Joined
Jul 15, 2008
Messages
63
Reaction score
0
I'm now doing admin and i wanna switch to doing IT audit because i feel that i want to do something related to my IT degree yet not too technical like creating apps or troubleshooting.

I consulted some people in this area and most started doing IT security or financial auditing in big4 before they actually branch out to IT auditing. Most of the IT security position require alot of technical skills and auditing in big4 requires finance degree. I don't mind taking up some finance related courses but the route is going be a long one before I land myself in the job scope I'm interested in.

Thanks raynor21, i guess the 2nd link may be useful for me.
 

aynneo

Senior Member
Joined
Jan 21, 2008
Messages
801
Reaction score
0
But CISSP credential is valid for only 3 years and after that have to be renew.
After that you need to retake the exams or submit a total of 120 CPEs by the end of their 3 year certification cycle and pay the Annual Membership Fee.
 

Leeson

Senior Member
Joined
Jan 1, 2000
Messages
1,680
Reaction score
0
But CISSP credential is valid for only 3 years and after that have to be renew.
After that you need to retake the exams or submit a total of 120 CPEs by the end of their 3 year certification cycle and pay the Annual Membership Fee.

fyi, almost all certifications based out of US has this clause and its not unique to CISSP. they are conforming to US education regulations. :)
 

werew01f

Member
Joined
Jul 17, 2007
Messages
123
Reaction score
0
But CISSP credential is valid for only 3 years and after that have to be renew.
After that you need to retake the exams or submit a total of 120 CPEs by the end of their 3 year certification cycle and pay the Annual Membership Fee.

They concern more on you paying the Annual Membership fee then earning the CPE points... As there are so many ways to earn those points.... even watching a Security webcast can earn you points.
 

rAcEr

Supremacy Member
Joined
Jan 1, 2000
Messages
5,792
Reaction score
7
curryudon,

dun be discouraged if you do not have any accountancy knowledge. i started off as a unix admin in a local SI, joined a big 4 accountancy firm in an IT audit role and am now an internal IT auditor for a US MNC.

IT audit can actually be divided into two main categories:
1) Hardcore technology / infrastructure / network security / penetration testing
2) IT general controls + application controls in support of integrated financial audits

consider joining any of the big 4 accountancy firms in an IT audit role because that is where you really get your hands and feet wet, learn as much as you can for a couple of years before making a decision whether you want to continue your career in the big 4 or to join commercial companies (MNCs, banks) in an IT audit / security role. typically big 4 is willing to accept people from both accountancy / IT backgrounds for their technology risk / IT advisory practices.

btw i think your superior may be mistaken about CISA being paired with CPA. It is far more common for CISA + CISSP or CISA + CIA. There are some CPAs that take CISA in the later parts of their career though.
 

curryudon

Junior Member
Joined
Jul 15, 2008
Messages
63
Reaction score
0
curryudon,

dun be discouraged if you do not have any accountancy knowledge. i started off as a unix admin in a local SI, joined a big 4 accountancy firm in an IT audit role and am now an internal IT auditor for a US MNC.

IT audit can actually be divided into two main categories:
1) Hardcore technology / infrastructure / network security / penetration testing
2) IT general controls + application controls in support of integrated financial audits

consider joining any of the big 4 accountancy firms in an IT audit role because that is where you really get your hands and feet wet, learn as much as you can for a couple of years before making a decision whether you want to continue your career in the big 4 or to join commercial companies (MNCs, banks) in an IT audit / security role. typically big 4 is willing to accept people from both accountancy / IT backgrounds for their technology risk / IT advisory practices.

btw i think your superior may be mistaken about CISA being paired with CPA. It is far more common for CISA + CISSP or CISA + CIA. There are some CPAs that take CISA in the later parts of their career though.

thanks everyone for the valuable inputs. just to update again, in case anyone else is in the same dilemma as i am... after some drama and merry-go-round, I've joined big4 to do IT audit. for a person like me who do not have any experience in this area, i find that the experience is rather rewarding at this point of time. It provides an insight on what this line is all about. I'm glad rAcEr replied and reassured me that my decision is not a dumb one.

However, some people have advised me against doing IT audit in big4. They have raised issues like whether my role in big4 will touch on any security components and be eventually eligible for CISSP/CISM. like what you mentioned abt the 2 categories, i'm not sure if i'll be covering both. Am i worrying too much? I do have some doubts abt doing audit in big4 versus techie firms (e.g. HP, IBM, singtel etc) :(
 
Last edited:

rAcEr

Supremacy Member
Joined
Jan 1, 2000
Messages
5,792
Reaction score
7
whether u are focusing on technical IT security or IT audit in the big 4, either paths will ensure u have no issues obtaining a CISSP certification. CISM might be slightly more tricky though...

If you decide to join a techie firm eventually after spending some time in the big 4, the big 4 experience is certainly helpful and i can guarantee that commercial firms view big 4 experience very favourably.

dun worry too much and make full use of this opportunity to learn as much as u can!
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top