cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
abulfoej
Viewer

What would be the best Certification Course for Cybersecurity Audit

I am very interested in auditing and wondering which course would be best to start from beginning. Your suggestion will be greatly appreciated.

4 Replies
emb021
Advocate I

@abulfoej wrote: "What would be the best Certification Course for Cybersecurity Audit"

You need to take a look at the following courses/certifications.

From ISACA, take a look at the CISA (Certified Information Systems Auditor).  Its not specifically cybersecurity, but pretty much anyone doing IT auditing as a career will have this. Be advised you must have 5 years of experience to get the cert.

 

ISACA also has their Cybersecurity Audit Certificate (NOT a certification) as well.  They have training materials. 

From SANS/GIAC, take a look at their course AUD507: Auditing Systems, Applications, and the Cloud, which will lead to the GIAC Systems and Network Auditor (GSNA) cert.  This class is very hands on, btw, as its about technical auditing of IT.

You might also want to look at their course SEC566: Implementing and Auditing CIS Controls, which leads to the GIAC Critical Controls Certification (GCCC) cert.  This course does look at other standards like PCI-DSS, NIST CSF and ISO 27001 and others.

Hope this helps.

---
Michael Brown, CISSP, HCISPP, CISA, CISM, CGEIT, CRISC, CDPSE, GSLC, GSTRT, GLEG, GSNA, CIST, CIGE, ISSA Fellow
riffjim4069
Newcomer III

What Michael said...I think the CRISC pairs very well with the CISA for those pursuing an audit track because of the importance of cyber risk and risk reporting.  Top if off with the CISSP and you're good-to-go IMO.  Cheers! 

emb021
Advocate I

I agree with @riffjim4069  comment.

CRISC is another good cert, but its about IT Risk and Controls, tho it is a good add-on to the CISA.  And certainly having the CISSP with the CISA is also good and shows employers or clients (if you work as a consultant) that you know IT audit AND security.

 

Which is why I have several of these.  I just don't yet have the GCCC one.

---
Michael Brown, CISSP, HCISPP, CISA, CISM, CGEIT, CRISC, CDPSE, GSLC, GSTRT, GLEG, GSNA, CIST, CIGE, ISSA Fellow

Audit