, 2002-03-13
In which your intrepid columnist hands over $450 to sit for the CISSP exam, only to conclude that it measures little of value.
Expand all |
Post comment
A Certified Waste of Time
2002-03-13
Anonymous CISSP (2 replies)
Anonymous CISSP (2 replies)
A Certified Waste of Time
2002-03-13
cray@ttlunlimited.com (1 replies)
cray@ttlunlimited.com (1 replies)
CCIE-Security & Cisco Security Specialist 1
2002-03-16
teLi, CCNP (5 replies)
teLi, CCNP (5 replies)
Pass it and respect it. Do not pass it and blame the test.
2002-03-14
From someone who doesn't know anything but it is a CISSP
From someone who doesn't know anything but it is a CISSP
A Certified Waste of Time - How closed minded can you get
2002-03-14
Eric, CISSP CCIE CNE MCSE ACE CCSE (3 replies)
Eric, CISSP CCIE CNE MCSE ACE CCSE (3 replies)
It's so easy to criticize, Isn't it?
2002-03-14
Dr. Mike Ewing (2 replies)
Dr. Mike Ewing (2 replies)
A Certified Bunch of Crybabies...
2002-03-16
Mr. Andre Robitaille, I wonder how many acronyms I can put after my name? (1 replies)
Mr. Andre Robitaille, I wonder how many acronyms I can put after my name? (1 replies)
A Certified Bunch of Crybabies...AND Talk about Anally Retentive!!
2002-03-25
Dr. E. W. c.r.t.f.q., c.b.o.h.i.c.a, c.w.g.a.s., cv43, LEO
Dr. E. W. c.r.t.f.q., c.b.o.h.i.c.a, c.w.g.a.s., cv43, LEO
Beware Of Consultant LIke Jon Lasser
2002-03-19
Scott Sattler (4 replies)
Scott Sattler (4 replies)

But the test didn't really cover security understanding, but knowledge of conventions and conventional wisdom.
I agree with John that a CISSP does not really differentiate security savvy people from good test takes.
The SANS GIAC courses on the other hand do require in-depth analysis of real problems to acquire. So does the Cisco CICE. Multiple choice test can never reveal ingenuity, resourcefulness, creativity since they, by definition, test already known answers.
It is a bit like the study of NP problems in Computer Science. If you know an answer, it is pretty easy to prove it correct. But finding that answer in the first place is hard.
ISC2 has revised the qualifications for CISSP a bit for next year, now requiring a B.A or better. But this still doesn't test whether somebody "gets it" in security, it just restricts the test takes to a smaller set.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/67/11140#11140