-

Three ISACA Credentials Rank Among 10 Highest-Paying Tech Certifications

CISM, CRISC and CISA earn top spots in Global Knowledge’s 2020 IT Skills and Salary Survey

SCHAUMBURG, Ill.--(BUSINESS WIRE)--Three ISACA credentials are among the IT industry’s top-paying certifications, according to recently released data from the Global Knowledge 2020 IT Skills and Salary Survey.

Three ISACA credentials rank among 10 highest-paying tech certifications. #CISM #CRISC #CISA bit.ly/31SqZTN

Share

Each of the three ISACA credentials recognized—Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC) and Certified Information Systems Auditor (CISA)—landed in the top half of Global Knowledge’s 2020 list of top-paying certifications.

CISM ranks third on the list, which tracks the highest-paying certifications in the United States. CISM, the top-paying enterprise security management and cybersecurity certification on the list, provides professionals with a credential that allows them to transition from security technologist roles to enterprise information security management. As information security has become an enterprise-wide imperative—with high visibility at the board level—CISM addresses an urgent need for security practitioners to develop the management skills needed to connect IT security programs with executive leadership. It carries an average salary of US $148,622, according to Global Knowledge.

CRISC is fourth on the list with an average salary of US $146,480. CRISC is ideal for professionals engaged in enterprise risk management and control who are seeking to connect risk practices to wider enterprise goals and strategy. CRISC-certified professionals can assess, design and implement effective plans and enterprise risk management systems to mitigate risk and establish a common perspective and language about IT risk that builds alignment throughout the enterprise.

ISACA’s CISA credential was seventh on the Global Knowledge list with an average salary of US $132,278. For more than 40 years, CISA has been considered the gold standard of certifications for IT audit, control and assurance professionals. In 2019, the CISA job practice was updated to reflect new areas of emphasis, including the ability for CISA-certified professionals to perform technical security testing to identify potential threats and vulnerabilities, incorporate the use of data analytics tools and evaluate potential opportunities and threats associated with emerging technologies, regulations, and industry practices.

Both the CISA and CISM have reached major milestones within the past year, with the CISA (established in 1978) having surpassed 150,000 certification-holders since inception and the CISM (established in 2002) surpassing 50,000 all-time certification-holders. More than 26,000 people have attained the CRISC, which was introduced in 2010.

“ISACA credentials are a key differentiator for technology professionals because they demonstrate a solid foundation of knowledge and expertise to successfully navigate today’s challenging global environment,” said Ashley Holmes, Governance and Compliance Manager at Delta Air Lines, who holds the CISM, CRISC and CISA certifications. “My ISACA certifications have served me well by providing professional credibility and are an essential investment in my professional development and career.”

The full Global Knowledge 2020 IT Skills and Salary Survey will be released later this year. For more information about ISACA’s credentialing program, visit www.isaca.org/certification.

About ISACA

For more than 50 years, ISACA® (www.isaca.org) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its 145,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide.

Twitter: www.twitter.com/ISACANews
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews

Contacts

Emily Van Camp, evcamp@isaca.org, +1.847.385.7223
Kristen Kessinger, communications@isaca.org, +1.847.660.5512

ISACA


Release Versions

Contacts

Emily Van Camp, evcamp@isaca.org, +1.847.385.7223
Kristen Kessinger, communications@isaca.org, +1.847.660.5512

Social Media Profiles
More News From ISACA

AI Governance, Cyber Resilience and Digital Trust to Take Centre Stage at ISACA Europe Conference 2026 in Munich

MUNICH--(BUSINESS WIRE)--As artificial intelligence transforms organisations faster than governance frameworks can keep pace, professionals across Europe are under growing pressure to ensure AI is not only adopted, but governed, secured and managed responsibly. Against that backdrop, ISACA Europe Conference 2026 will bring more than 50 international speakers to Munich from 7–9 October to examine how organisations can strengthen oversight, manage risk and build resilience in an increasingly comp...

ISACA Introduces 2026-2027 Board of Directors

SCHAUMBURG, Ill.--(BUSINESS WIRE)--ISACA has installed its 2026-2027 Board of Directors during the association’s Annual General Meeting held today in Chicago, Illinois, USA, and virtually. New Board Chair Massimo Migliuolo and returning Board Vice Chair Jamie Norton will lead the global professional association that champions the workforce in fields including IT audit, governance, risk, privacy and cybersecurity.Migliuolo, a past ISACA board director, is a globally experienced technology executi...

New Security Debt Index Model from ISACA Helps Organizations Track Overall Debt Posture

SCHAUMBURG, Ill.--(BUSINESS WIRE)--As businesses accelerate their adoption of cloud technologies and artificial intelligence (AI), security debt— the accumulated risk created by outdated systems, deferred remediation, unpatched vulnerabilities, and under-resourced programs—has become one of the largest threats to enterprise resilience. Unpatched systems, weak identity and access management, siloed monitoring and alerting, and gaps in governance and oversight are just some examples of security d...
Back to Newsroom