ISACA

Organization dossier Founded 1969 Status: the industry standard

A 50-year professional body with 185,000 members that certifies people to govern IT — and whose flagship framework, on its own account, has never been shown by an independent study to make anything harder to breach. This is the mild one. No fraud, no lawsuit, no scandal: just the gap between "compliant" and "secure," and a stack of member complaints about the renewal invoice.

Empower our members throughout their careers by providing comprehensive knowledge, skills, credentials and access to a global community—ensuring they are well-prepared to meet today's challenges and drive tomorrow's innovations.

ISACA's stated mission, in its own words, on its About Us page

Discover why COBIT is still the premier framework for the governance and management of enterprise IT.

ISACA describing COBIT in its own words, on its COBIT resource page

ENTITY
ISACA (formerly the Information Systems Audit and Control Association; originally the EDP Auditors Association), Schaumburg, Illinois — a 501(c)(6) professional association, founded 1969 FACT
PRODUCT
The CISA (1978), CISM (2002), and CRISC certifications, and the COBIT IT-governance framework FACT
SCALE
~185,000 members across 188 countries and 225 chapters; ~$100M revenue (2022, per its Form 990 as summarized on Wikipedia) FACT
THE CRITIQUE
Structural, not criminal: certifies compliance, which is not the same thing as security; and COBIT's security benefit has never been demonstrated by an independent study. Plus a minority of member/consumer complaints about renewals and revocations ATTRIBUTED
RECORD
No fraud, no regulator action, no adjudication — and no credible allegation of financial misconduct at the organizational level. The research file is explicit: the "kickbacks" frame has no support and is not asserted here FACT
STATUS
THE INDUSTRY STANDARD — CISA/CISM sit on job requisitions worldwide; COBIT is taught, audited, and re-certified on schedule

A word before we start: this is a mild entry, and honesty requires saying so up front. Most files in this archive document a fraud, a breach, a lawsuit, or a conviction. This one documents none of those. ISACA is a real, large, old professional body whose certifications are genuinely recognized and whose framework is genuinely deployed. It belongs in the ledger not for wrongdoing but for a single stubborn question the field keeps asking and the paper keeps not answering.

The question is whether any of it makes you safer, or merely compliant. Those are different words. Every beat below carries its receipt. Both sides get the microphone — and the defense here is strong. You decide who wins.

the drama timeline

ACT I — THE FRAMEWORK (1969–PRESENT)

Every institution begins by naming a need and then filling it. ISACA named the governance of computer systems before most organizations had many, and it has been selling the map ever since. Watch what the map does and does not promise.

  1. 1969

    The auditors organize

    A group of computer-systems auditors incorporates as the EDP Auditors Association. It later becomes the Information Systems Audit and Control Association, and later still just ISACA. It launches the Certified Information Systems Auditor (CISA) credential in 1978 and the Certified Information Security Manager (CISM) in 2002. The premise, from the start, is that information systems need governance and oversight — a premise nobody in the field disputes.

  2. ONGOING

    COBIT, the “premier framework”

    ISACA publishes and re-publishes COBIT (Control Objectives for Information and Related Technologies), which it calls "the premier framework for the governance and management of enterprise IT" and "an important driver of innovation and business transformation." The framework is guidance for structuring oversight — process objectives, control mappings, maturity models — and ISACA is careful to describe it as a governance solution to be "right-sized," not a security guarantee.

    Note the register. It is the language of governance, transformation, and ROI — not the language of stopping an attacker. That is not a trick; it is what the product is.

ACT II — THE GAP NOBODY HAS CLOSED

Here is the whole case against, and it is a quiet one. It is not that the framework fails. It is that, after decades, nobody has published proof that it succeeds at the one thing its buyers are most anxious about.

  1. THE EFFICACY QUESTION

    No independent study links COBIT to fewer breaches

    The framework for IT governance is deployed the world over in compliance contexts. Yet no independent study has demonstrated a causal relationship between COBIT adoption and improved security outcomes. This is a statement about the evidence base — an absence — not a claim that the framework is harmful. Three decades of well-credentialed governance professionals have staffed organizations that got breached anyway, because governance documentation and breach resistance are different disciplines.

    "COBIT-certified" and "not breached" are two independent variables. The archive has never found the study that ties them together. If it exists, this file will add it.

  2. STRUCTURAL

    Compliance is not security

    ISACA's certifications — CISA, CISM, the COBIT certificates — are primarily valued by compliance and audit teams, not by the people running security operations. The distinction is load-bearing: compliance means meeting documented requirements; security means resisting actual attacks. An organization can be fully COBIT-aligned and thoroughly compromised. This is not a scandal ISACA is hiding; it is inherent in what a governance framework is, and ISACA does not pretend otherwise.

ACT III — THE RENEWAL DESK (MEMBER COMPLAINTS)

Every membership body eventually meets the members who feel the invoice arrived faster than the benefit. ISACA's complaint file is real, sourced, and — this matters — a minority. It is included at its true weight, no heavier.

  1. CONSUMER REVIEWS

    Revocations, renewals, and a 3.1-star ledger

    On the consumer-review platform PissedConsumer, ISACA carries a roughly 3.1-star aggregate, with recurring complaints about maintenance and cancellation policy. Reviewers describe "a very rigid and unforgiving approach when it comes to certification maintenance requirements," say certifications have been revoked without prior warning, and one member's review states the organization "felt like they were more focused on making money than supporting their members." These are individual reviews, attributed to their authors, and they are a minority of a 185,000-member body — weight them accordingly.

    A neutral-to-negative rating on a complaint-aggregation site is a low rung on the evidence ladder, and it sits on a low rung here. It is included because it is sourced, not because it is damning.

both sides, on the record

The efficacy gap (the load-bearing point): no independent study has demonstrated a causal relationship between COBIT adoption and improved security outcomes. The framework's value proposition is governance and audit readiness; the field's central anxiety is not getting breached; the paper connecting the two has not been produced [1] [5].

The compliance-vs-security distinction: ISACA's certifications are principally instruments of compliance and audit, not of operational defense. An organization can be COBIT-aligned and thoroughly compromised — a structural feature, not a hidden one [1].

The member complaints: a minority of members, on the public record of a review platform, describe rigid maintenance rules, revocations without prior warning, and a sense that revenue outranked support — a ~3.1-star aggregate [3].

The scale and the standing: ISACA is a 50-plus-year professional association with roughly 185,000 members across 188 countries and 225 chapters, and, in its own description, is "recognized around the world for its guidance, credentials, education, training and community" [2] [4]. CISA and CISM are among the most widely required credentials on the market; ISACA administers them under formal, accredited certification programs [5].

A framework is guidance, not a guarantee: the "no study proves it stops breaches" critique applies to essentially every governance framework ever written — COBIT, ITIL, NIST CSF, ISO 27001 — because governance frameworks structure oversight; they do not patch servers. Faulting COBIT for not being an EDR agent is a category error, and ISACA describes it as a right-sizable governance solution, never as breach insurance [1].

Scope of the record: there is no fraud finding, no regulatory action, and no adjudication against ISACA, and — per the research file itself — no credible allegation of financial misconduct at the organizational level; the "kickbacks" frame has no support and is not asserted here. The complaints are consumer reviews and a structural argument, not a court record. The body operates today at full strength [3] [6].

YOU DECIDE

Scoped to the claims, never the institution. The claim "COBIT makes you more secure" is one ISACA does not actually make in those words — and the stronger version a critic might infer has no independent study behind it, in either direction. The claim "ISACA is a charlatan" is not supported and is not made here: there is no fraud, no regulator, no misconduct finding, and a large, accredited, decades-old membership behind the nameplate. What survives is narrower and quieter: a governance body whose product is compliance, sold into a field whose problem is attackers, with the efficacy question politely unanswered and a minority of members unhappy about the renewal desk.

Weigh the costly signals honestly. ISACA has spent 50 years building institutions, chapters, and an accredited exam apparatus — real, expensive, durable work. The case against it costs nothing to state and proves nothing on its own: an absence of evidence is not evidence of absence. This is the mild file. It earns its place by asking the one question the certificate does not answer, and by refusing to pretend the answer is worse than it is.

The archive does not judge. The archive merely keeps the tape running.

evidence locker

SUBJECT'S OWN CHANNELS — ISACA, UNEDITED

  1. ISACA — COBIT resource page SELF-PUBLISHED — "the premier framework for the governance and management of enterprise IT," in ISACA's own words; the value proposition being weighed. isaca.org/resources/cobit
  2. ISACA — About Us (mission, scale, recognition) SELF-PUBLISHED — the mission statement, the 185,000-member/188-country figures, and the "recognized around the world" language, verbatim. isaca.org/about-us

COMPLAINT RECORD

  1. PissedConsumer — ISACA reviews (~3.1 stars) ATTRIBUTED — the rigid-maintenance, revocation-without-warning, and "more focused on making money than supporting their members" reviews; individual reviewers' words, minority sentiment. pissedconsumer.com/isaca/RT-F.html

CONTEXT & REFERENCE

  1. Wikipedia — ISACA (sourced overview) REFERENCE — founding (1969, as the EDP Auditors Association), the CISA (1978)/CISM (2002) launch dates, the certification portfolio, and the Form 990 revenue figures. en.wikipedia.org/wiki/ISACA
  2. ISACA — Credentialing (CISA) SELF-PUBLISHED — the formal certification program behind the CISA credential; the accreditation-and-recognition defense. isaca.org/credentialing/cisa
  3. Infosecurity Magazine — "Security Certifications are Useless, Right?" ATTRIBUTED — the broader industry debate on whether security certifications, ISACA's included, measure defense or compliance. infosecurity-magazine.com/news-features/security-certifications-useless/
The standard. Everything above is sourced to ISACA's own publications, a consumer-review platform, a sourced encyclopedic overview, and named industry commentary. Facts are stated as facts; the efficacy critique is stated as a documented absence of evidence, not as proof of failure; consumer complaints wear their reviewers and are marked as the minority sentiment they are. This is a mild entry and is presented as one: no fraud, no regulator, no adjudication, and no credible allegation of financial misconduct is asserted, because none is supported. The defense — the body's scale, accreditation, recognition, and the guidance-not-guarantee nature of any governance framework — is presented at full strength, and it is the stronger side. No motive is asserted, no private character diagnosed. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.