, 2002-03-13
In which your intrepid columnist hands over $450 to sit for the CISSP exam, only to conclude that it measures little of value.
Expand all |
Post comment
A Certified Waste of Time
2002-03-13
Anonymous CISSP (2 replies)
Anonymous CISSP (2 replies)
Pass it and respect it. Do not pass it and blame the test.
2002-03-14
From someone who doesn't know anything but it is a CISSP
From someone who doesn't know anything but it is a CISSP
A Certified Waste of Time - How closed minded can you get
2002-03-14
Eric, CISSP CCIE CNE MCSE ACE CCSE (3 replies)
Eric, CISSP CCIE CNE MCSE ACE CCSE (3 replies)
It's so easy to criticize, Isn't it?
2002-03-14
Dr. Mike Ewing (2 replies)
Dr. Mike Ewing (2 replies)
A Certified Bunch of Crybabies...
2002-03-16
Mr. Andre Robitaille, I wonder how many acronyms I can put after my name? (1 replies)
Mr. Andre Robitaille, I wonder how many acronyms I can put after my name? (1 replies)
A Certified Bunch of Crybabies...AND Talk about Anally Retentive!!
2002-03-25
Dr. E. W. c.r.t.f.q., c.b.o.h.i.c.a, c.w.g.a.s., cv43, LEO
Dr. E. W. c.r.t.f.q., c.b.o.h.i.c.a, c.w.g.a.s., cv43, LEO
Beware Of Consultant LIke Jon Lasser
2002-03-19
Scott Sattler (4 replies)
Scott Sattler (4 replies)

I could not agree more. How many certifications out there truly measure someone's talent and occupational ability versus simply their test taking ability - aside from Cisco? I have conducted security assessments and such for over 4 years now and have yet to take the exam - though I do plan on doing so in the near future. While I lack the exam as part of my credentials, I have known many others with a CISSP certification who would have a difficult time spelling "security" let alone being able to competently practice it. These certifications, for the most part, are a fantastic marketing ploy whereas whoever comes up with the coolest buzzword and a test makes the most money - boy, I wish I could think of one.
But, on the flipside, what else is there to gauge a person's credentials? While I may consider it a marketing ploy, there has to be some way to "verify" security professionals just as you would be able to "verify" the credentials of a doctor, lawyer, engineer, etc. SANS is doing a good job from what I've seen but, aside from that, ISC2 is the next closest.
Thus, the CISSP exam is a necessary evil. If you want to be in the game, you've got to play by the rules...i.e. pay your $450 and live with it. Maybe someday I'll actually do the same.
Good article.
Christopher H. Ray
Director, Information Security
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/67/11003#11003