A question I have been getting more often from people preparing for the CISA is whether the exam content has kept pace with the cloud security landscape. Specifically, whether studying for a credential that was established decades ago in a primarily on-premises world is going to give you relevant knowledge for the environments most organizations actually operate in today.
The concern is understandable. ISACA updates the CISA curriculum on a regular basis, but the exam has a reputation, not entirely undeserved, for being weighted toward traditional IT audit concepts that were developed in an era when the phrase “infrastructure as code” would have gotten a blank stare from most audit professionals.
Having spent time with both the current CISA content and the practical realities of cloud security auditing, my honest assessment is that the CISA gets more right than its critics acknowledge, particularly in a few specific areas, while still having gaps that are worth acknowledging.
What the CISA gets genuinely right for cloud environments is the foundational framework for evaluating controls regardless of where those controls are implemented. The logical access controls domain, for instance, covers the concepts of identity management, authorization, authentication, and access reviews in ways that apply directly to cloud IAM systems even though the specific technology implementations are different from what the original exam authors were thinking about. The auditor who understands what adequate access controls look like, what evidence to request, and how to evaluate whether the controls in place match the policy is going to be effective whether the environment is an on-premises Active Directory implementation or an AWS IAM configuration. The framework knowledge transfers even when the specific technology does not.
Shared responsibility is a cloud security concept that the CISA curriculum handles reasonably well given that it maps to the longstanding audit principle of clearly defining control responsibilities between an organization and its third-party service providers. The cloud shared responsibility model, where the cloud provider handles security of the underlying infrastructure and the customer handles security in the configuration they deploy on top of it, is a specific instance of a more general third-party responsibility question that IT audit has always needed to address. CISA-trained auditors who understand the general principle are well-positioned to apply it to cloud-specific scenarios.
Where the CISA content is less complete is in the technical specifics of cloud-native security architecture, the nuances of different cloud service models and their control implications, and the audit procedures specific to cloud provider environments. These gaps are real and they reflect the pace of cloud adoption outrunning the certification update cycle. Supplementing CISA preparation with cloud security-specific resources, including the CSA Security Guidance and the cloud provider security documentation available from AWS and through Microsoft’s compliance documentation, fills those gaps meaningfully.
The practical recommendation for CISA candidates who work in cloud-heavy environments is to treat the CISA as providing the governance and audit methodology foundation and to build cloud-specific knowledge on top of that foundation through supplemental study. The credential validates the methodology. Your cloud-specific knowledge demonstrates that you can apply it in the environment your employer actually operates.
Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.
