The AAISM is ISACA’s Advanced in AI Security Management
credential, and new is the word that explains most of what follows. New exam, new training materials, new subject matter that is changing faster than any of them can keep up with. I passed it in July 2026. The credential is worth holding and the training was worth buying – but all of it still has the rough edges of a first edition, and the honest way to review it is as one.
This eight-week CyberLeadership program
from the CyberLeadership Institute guides experienced security professionals to operate at executive level, ending with a practical board‑facing capstone project that simulates the presentation of a 2-year plan by an incoming CISO to the board. Each week focuses on a distinct leadership domain, and includes practical action items and templates to be incorporated into the capstone. The course offers 40 CPE towards renewing my CISSP
.
Week 1 – The role of a CISO
Week 1 orients participants to the program and the cyber resilience mindset, and introduces the CISO role through lived experience and practical lessons. Participants explore the many variants of the CISO position, clarify their ideal role, and begin building a personal brand and interview readiness. The week covers essential first‑100‑day priorities, ways to engage the C‑suite, and personal resilience practices.
I recently took and passed the GCFA certification exam
for forensic analysis. It was an interesting and educational experience, touching on logfile analysis, memory forensics, deep filesystem analysis, and timeline generation. Most of the content focused on Windows (event logs, NTFS filesystem formats, etc); I’m looking forward to finding a matching course with a Linux focus.
I recently took and passed the ISC2CISSP
. The certification covered a broad range of topics, most of which I was already familiar with from experience as a software engineer. Those areas I was less familiar with included legal and procedural requirements around risk assessment, physical security, and the theory behind encryption and permissions management.
I recently took and passed the GCIH Certification
. It’s primarily focused on understanding how attackers behave, the tools they use, and why those tools do the things they do.