Undercover
CISSP Certification Uncertainty
Would I want to belong to a club (ISC2's CISSP certification) that had me as a member? As it turns out, I do.
By Anonymous
I didn't take the seminar, nor did I bother studying. With nearly two decades of experience in information assurance and security, I figured that if I couldn't pass the test cold, then (ISC)2 really was a scam.
I joined another 40 or so people on the day of the test. We were all handed a little notebook with several hundred multiple-choice questions. Some of the questions were "experimental," we were told; that is, they didn't count. If we thought that a question was poorly worded or ambiguous, we should try to answer it as best we could, then write a critique of the question on a piece of scratch paper. It all seemed quite straightforward and professional
In all my years as a student and computer professional, I have never seen an exam as poorly written as the CISSP certification test. Many questions could not be answered accurately because their basic premise was flawed. Some had multiple answers that were correct; others had no correct answers. The exam was filled with acronyms that weren't spelled out
Once you pass, you need to maintain your good standing through (ISC)2's Continuing Professional Education (CPE) requirement
CISSP may be nothing more than a club, but it's a club that I've joined, and I hope it's one that's keeping out the riffraff. When somebody suggests that I hire a "reformed hacker" to do a penetration test of our network, I don't need to launch into an explanation of why such testing won't actually increase network security. All I have to say is, "We don't hire consultants without a CISSP."
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



