February 9, 2021 By Kim Walsh Cybersecurity Certifications, Industry News

The SolarWinds breach dominated security conversations throughout the end of 2020 and into 2021, and for good reason. It was not just a sophisticated attack on a single organization. It was a supply chain compromise that gave attackers access to the networks of thousands of SolarWinds customers, including a significant number of US government agencies and Fortune 500 companies, by embedding malicious code into a legitimate software update that those organizations trusted and installed without knowing it was compromised.

The implications for how we think about enterprise security and IT risk are substantial, and I want to talk about them through the lens of the CISA certification because I think the SolarWinds incident illustrates exactly why the Certified Information Systems Auditor exam covers what it covers.

Software supply chain risk is a topic that the CISA exam has addressed in its domain on information systems acquisition, development, and implementation for years. The principle that organizations need to evaluate and manage the security of third-party software and services they rely on is not a new concept in the audit and governance world. What SolarWinds demonstrated is what the consequences look like when that risk management is inadequate at scale. Automated update mechanisms that bypass normal change control processes created the exact attack vector that was exploited. The audit questions that should have been asked about those update mechanisms and the integrity verification controls around them were questions that CISA-trained auditors are specifically prepared to ask.

Change management controls are another CISA domain that SolarWinds makes directly relevant. The compromised update package passed through software distribution mechanisms that were supposed to represent a controlled process. The failure was not purely technical. It was a failure of the governance and control frameworks that should have provided assurance about the integrity of that process. Understanding how to evaluate change management controls, what evidence to examine, and where the gaps are likely to appear is core CISA material.

Third-party risk management appears throughout the CISA content in multiple domains. The SolarWinds situation is essentially a graduate-level case study in third-party risk. The organizations that were affected had accepted a level of implicit trust in their software vendors that the breach demonstrated was not warranted. Audit programs that were not systematically evaluating software supply chain risk were missing a meaningful category of organizational exposure.

I am not suggesting that passing the CISA would have prevented SolarWinds. That is not how it works. What I am saying is that the audit discipline the CISA represents, the systematic evaluation of controls, the identification of gaps between policy and practice, the assessment of third-party risk, is exactly the kind of rigorous oversight that organizations needed more of, not less. The CISA credential from ISACA is built around that discipline and incidents like SolarWinds are a reminder of why it matters.

There is also a practical lesson here for anyone preparing for the CISA exam right now. Third-party risk, supply chain considerations, and software acquisition controls are not obscure corners of the domain content that you can skim over. They are topics that real-world events have placed at the center of enterprise security conversations. Study them carefully, understand them in depth, and expect questions that require you to apply the concepts rather than just recall them.

The CISA has always been a serious credential for serious practitioners. The events of the past several months have made the case for that seriousness harder to dismiss.

Kim Walsh

Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.