Should I get CISSP Certified?

CISSP's reputation as a certification is for being 'a mile wide and an inch deep'.
That's a limitation too - CISSP means you understand something, but not that you know how to do it.
But the exam is a six-hour marathon consisting of a vast array of intentionally confusing questions covering everything from the obvious to the extremely obscure.
For some the biggest reason not to do it is the sheer length of the exam, for others the breadth of the syllabus.
ISC2 really should look at splitting the syllabus into several shorter hour exams to do it justice.
The exam is not impossible or unreasonable - if you know the material you could even say it's not particularly difficult - it just requires you to understand what you're doing, as well as know what you're doing.
Whilst it's a 6 hour exam, you don't need to use all the time and I did it in just over 3 hours, including checking over my work.
The experience is easier, if it takes a little longer - 5 years experience in information security, with 1 year off for a degree.
There are no extra years off for other qualifications, but really don't do CISSP unless you've been doing something relevant for the last five years as you probably won't pass the exam anyway.
Unless you're supremely confident or just enjoy resitting exams, it's definitely worth investing in a training course.
Don't accept anything under 5 days, and be sure to do the homework - a course that long can't possibly teach you everything you need to know, so see it as a revision course and read around the syllabus in your weaker areas beforehand.
Be prepared also for travel costs unless you live in a major city, and keep an eye on exam dates as they often get booked up well in advance.
If you have information security or IT audit experience, good IT knowledge and a strong background in business, a one week training course followed by the exam may be enough.
You will want to take relevant courses, read up in weak areas, and spend a few months preparing for the exam.
If you've done a six hour exam once, you definitely won't want to do it three times.
However as the alternative is to resit the exam, I recommend the CPD option - strongly.
CISSP is the one 'must have' IT security qualification from a recruitment perspective, and everyone will learn something be doing it.
If you're new to Information Security or IT audit or looking to move in that direction from a relevant IT or operational field, maybe pass on CISSP for now and look at CISA or CISM as a qualification with a slightly narrower remit that will be easier to grasp, then follow up - CISSP just doesn't make much sense without supporting real life experience.
A good one is to do a one week boot camp course that leads up to the exam on the final day.
Find out about my experience of CISSP training here.


This Cyber News was published on securityboulevard.com. Publication date: Mon, 12 Feb 2024 01:13:04 +0000


Cyber News related to Should I get CISSP Certified?

Develop Valuable Security and Risk Management Skills for Just $30 - With cyberthreats and cyberattacks always on the rise, developing security and risk management skills could be one of the best moves for your business or career. We may be compensated by vendors who appear on this page through methods such as ...
10 months ago Techrepublic.com
Should I get CISSP Certified? - CISSP's reputation as a certification is for being 'a mile wide and an inch deep'. That's a limitation too - CISSP means you understand something, but not that you know how to do it. But the exam is a six-hour marathon consisting of a vast array of ...
9 months ago Securityboulevard.com
A personal experience of CISSP boot camp - You can spend your whole life trying to gain the width or depth of knowledge necessary to do the job competently, and every day feel you know a little less than the day before. It's often unclear whether it is a technical field or a management one, ...
9 months ago Securityboulevard.com
So You Want to be a Leader in Cybersecurity? Follow this Path - Effective cybersecurity leadership is vital for organizations worldwide. Cybersecurity leaders embed security across operations, rapidly respond to threats and advise senior leaders. They stay in front of cybersecurity trends from a technical ...
10 months ago Cybersecurity-insiders.com
Top 10 CISSP Stress-Busting Study Tips & Tricks - A little stress can actually help you focus and do better. Don't let it stop you from registering and sitting for your CISSP exam. CISSP certification is a smart investment in your future. As cybersecurity's premier credential, it consistently ranks ...
11 months ago Cybersecurity-insiders.com
REVIEW: ISC2 CERTIFIED CLOUD SECURITY PROFESSIONAL CERTIFICATION - The Certified Cloud Security Professional is a highly respected cybersecurity certification that addresses the needs of professionals and employers for robust and adaptable cloud security expertise. As cyber threats continue to escalate, the demand ...
10 months ago Cybersecurity-insiders.com
Week in review: Veeam fixes RCE flaw in backup management platform, Patch Tuesday forecast - Veeam fixes RCE flaw in backup management platformVeeam has patched a high-severity vulnerability in Veeam Service Provider Console and is urging customers to implement the patch. May 2024 Patch Tuesday forecast: A reminder of recent threats and ...
6 months ago Helpnetsecurity.com
Week in review: New Black Basta's social engineering campaign, passing the CISSP exam in 6 weeks - Black Basta target orgs with new social engineering campaignBlack Basta, one of the most prolific ransomware-as-a-service operators, is trying out a combination of email DDoS and vishing to get employees to download remote access tools. Cybersecurity ...
6 months ago Helpnetsecurity.com
Invitation to All CISSPISSMP and CISSP Certificate Owners Read the Blog - The cybersecurity industry is constantly evolving, so it is important to make sure certifications are up to date and relevant. To do this, we need the help of cybersecurity professionals who hold certifications in the field. We are looking into ...
1 year ago Blog.isc2.org
How To Improve Security Capacities of The Internet of Things? - The security of the Internet of Things is one of the main challenges of today. Many IoT assets could get an easy target to cyber attacks and it's highly recommended to somehow cope with these requirements. The best practice is something that would ...
9 months ago Cyberdefensemagazine.com
The First 10 Days of a vCISO’S Journey with a New Client - Cyber Defense Magazine - During this period, the vCISO conducts a comprehensive assessment to identify vulnerabilities, engages with key stakeholders to align security efforts with business objectives, and develops a strategic roadmap to prioritize actions and resources. If ...
1 month ago Cyberdefensemagazine.com
Embrace the Multicloud Era with Cisco Learning and Certifications at Cisco Live Amsterdam - It's time to come together with experts and thousands of your peers to connect, learn, and advance your career with the Learning & Certifications team at Cisco Live Amsterdam, February 5-9, 2024. Let's dive into how you can make the most of your ...
9 months ago Feedpress.me
Wi-Fi Alliance Announces Wi-Fi 7 to Boost performance - Wi-Fi Alliance unleashes the next generation of connectivity with Wi-Fi CERTIFIED 7™. This revolutionary technology promises to turbocharge wireless connectivity, pushing the boundaries of speed, reliability, and efficiency. Imagine downloading ...
10 months ago Cybersecuritynews.com
Should I get CISA Certified? - CISA is possibly the one 'pure' Information systems audit qualification that is recognised anywhere. It has lovely exam questions - and I should know, as I wrote some of them. There are other IT audit certifications - from the IIA's aborted QiCA to ...
9 months ago Securityboulevard.com
Thinking about a Career in Cloud Security? Follow this Path - As more critical data and assets move to the cloud, they've become prime targets for cybercriminals. Organizations worldwide need cloud security professionals who understand the evolving complexities to identify and mitigate security risks. Most are ...
11 months ago Cybersecurity-insiders.com
How to Get a VAPT Certificate? - That is why organizations need to obtain a VAPT certificate for their organization. A VAPT Certificate provided by a premium cybersecurity company is a document issued to a company after they've undergone a Vulnerability Assessment and Penetration ...
6 months ago Securityboulevard.com
Encouraging Ethical Hacking Skills in Students - This article delves into the significance of encouraging ethical hacking skills in students and the numerous benefits it offers to individuals and society as a whole. Possessing ethical hacking skills can provide students with a competitive advantage ...
11 months ago Securityzap.com
The Case Study: The Exploitation of Business Assets - The role of this case study is to explain how it's feasible to exploit some business assets using the IoT search engines and some hacking tools. In this chapter, we would apply the Censys searching tool for crawling the web in a quite wide context, ...
10 months ago Cyberdefensemagazine.com
How to become a cybersecurity architect - Cybersecurity architects implement and maintain a comprehensive cybersecurity framework to protect their company's digital assets. The cybersecurity architect position is a fundamental role that all organizations need, said Lester Nichols, director ...
4 months ago Techtarget.com
What is the qualification to become a Cybersecurity Analyst - Becoming a cybersecurity analyst typically requires a combination of education, skills, and practical experience. Bachelor's Degree: Many employers prefer candidates with a bachelor's degree in a related field such as computer science, information ...
10 months ago Cybersecurity-insiders.com
Being PCI DSS certified - As detailed in a previous blog post, Sekoia has been certified PCI-DSS level 1. We started two years ago when we were discussing an extension of our coverage with a customer. This customer was processing card data and consequently had to be ...
10 months ago Blog.sekoia.io
Coming Soon to Wi-SUN Field Area Network: Versatility to connect sensors with low power and high throughput capabilities - The Catalyst IR8140 Heavy Duty Series Router will be Cisco's first router to support new Capabilities for FAN 1.1. In 2019 the Wi-SUN Alliance introduced the first certified products implementing Field Area Network 1.0, which is a secure, ...
8 months ago Feedpress.me
5 Tips for Pi Day Savings at the Cisco Learning Network Store - Save 25% on select training products from the Cisco Learning Network Store for 24 hours only. Two new multicloud training courses are now available in the Cisco Learning Network Store-and they're included in the Pi Day Sale. If you are an active ...
8 months ago Feedpress.me
ISC2 Collaborates With IBM to Launch Entry-Level Cybersecurity Certificate - PRESS RELEASE. ALEXANDRIA, Va., Feb. 13, 2024 /PRNewswire/ - ISC2 - the world's leading nonprofit member organization for cybersecurity professionals - announced a partnership with IBM to launch the IBM and ISC2 Cybersecurity Specialist Professional ...
9 months ago Darkreading.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)