CISM: The Key to Moving From Auditor to Manager

Author: Ferry Haris, CISA, CISM
Date Published: 27 November 2019

In 2015, Ferry Haris, CISA, CISM, IT risk manager at APG Asset Management, decided that he wanted to branch out from his role as an auditor, but also continue to utilize his base of knowledge, so he pursued the Certified Information Security Manager (CISM) certification. When asked about how CISM has benefitted his career, Haris says, “Because of CISM, potential employers and colleagues see me as more than an auditor and as an expert in information security. Some colleagues even have changed their perception of the advice I give because they now think we speak the same language.”

Since becoming a CISM, Haris has found that he derives more satisfaction from his work and enjoys knowing he is positively contributing to his organization and his colleagues. He says the biggest challenge in his job is convincing others that security and risk management are everyone’s responsibility, but it helps that he has the knowledge from his CISM certification to correlate security terminology with business terminology. This knowledge allows him to better illustrate why security and risk management are more than just one function’s responsibility and are important across the organization.

One of Haris’s favorite parts of his job is the frequent travel, which allows him to meet many different people around the world. He says, “I never thought of working and living in several countries. But having both the Certified Information Systems Auditor® (CISA) and CISM certifications under my belt helps open up job opportunities outside of my home country. The global acknowledgement of ISACA certifications has helped me to become a global citizen.”

Overall, Haris has found certification demonstrates a commitment to continuous learning and gives you the opportunity to add value at your organization. He believes certifications help individuals stand out. To grow in your professional and personal lives, learning new things is essential.

To learn more about ISACA certifications, visit the Certification page of the ISACA website.