Fugazi1000 wrote: » Some common themes. CISSP is a shallow level across a broad spectrum of technical InfoSec domains. CISM is more focussed on processes to manage risk in the InfoSec arena. CISA is similar but focusses on the audit aspect. CISSP is good to substantiate other technical skills/certs to show an employer that you are well versed in more than just a single vendor technology stack. CISM is for somebody aiming for, or in a management position (less hands on technically on a day to day basis). Having both can be useful. If you want techie only. CISSP + whatever. If you want an InfoSec management or Risk Management role, then CISM. If you like to check other people are doing their job.... CISA! IMHO.
JDMurray wrote: » Note that the CISA and CISM, like the CISSP, are professional certs that one obtains after gaining years of InfoSec work experience. People tend to misjudge these certs as something to help them break into InfoSec-related auditing or management, but they are not.
JDMurray wrote: » The CISM is specifically for InfoSec managers, while the CISSP is targeted to a much wider variety of InfoSec professionals. I consider the CISSP/CISA/CISM to be complementary to each other rather than exclusive.
Grief_Indoor wrote: » how is CISM different from CRISC though? i just passed CISA and i'm considering either CISM, CRISC, CISSP, or CIA. thanks for any input!
ameetng wrote: » Which exam to take first? CISM or CISSP?