{"id":21,"date":"2010-10-08T02:02:00","date_gmt":"2010-10-08T02:02:00","guid":{"rendered":"http:\/\/www.somethingsomethingsecurity.com\/?p=21"},"modified":"2010-10-08T02:02:00","modified_gmt":"2010-10-08T02:02:00","slug":"why-a-cissp","status":"publish","type":"post","link":"https:\/\/www.somethingsomethingsecurity.com\/?p=21","title":{"rendered":"Why a CISSP?"},"content":{"rendered":"<div><strong>\u00a0 Why a CISSP?<\/strong> <\/div>\n<p>The following is just my opinion based on my experiences and readings. I am not an expert in anything, nor will I likely ever be one. My hope is that it might help someone, somewhere, sometime. If nothing else, it might be a good start for discussion. <\/p>\n<p><strong>Preamble <\/strong><br \/>When I changed roles from a server administrator to a security specialist not too long ago, I knew I would <br \/>need to know more to be successful in my new role.\u00a0 <\/p>\n<p><strong>Requirements <\/strong><br \/>I tend to have a bit of an attention problem (imagine\u00a0Homer\u00a0saying, \u201cLook, a dog with a puffy tail\u201d) and have a hard time focusing on just one thing. I blame it on years of being interrupted by clients while juggling dozens of projects. One way I have discovered to overcome this\u00a0problem is to use\u00a0a quest for\u00a0certification to force me to focus. <\/p>\n<p>I\u2019m not going to get into the whole &#8220;is a paper really worth anything&#8221; discussion. A certification is just a certification. It\u00a0does not make someone better then someone that doesn&#8217;t have one.\u00a0I use the process of working towards certification as an opportunity to focus the quest for\u00a0knowledge. <strong>Not<\/strong> knowledge of how to take\u00a0the test, but knowledge of the <strong>skills<\/strong> the test is supposed to be measuring.\u00a0\u00a0 <br \/>\u00a0\u00a0 <br \/>The CISSP track of isc2.org was recommended to me\u00a0as a good way to get a quick dousing in some of the fundamental concepts in Information Security. <br \/>\u00a0 <br \/><strong>Background <\/strong><br \/>There are ten domains that the CISSP exam focuses on. A few big themes became apparent while learning the ten domains for\u00a0the CISSP. <\/p>\n<p>CIA &#8211; Confidentiality, integrity and availability and how those relate to each domain <\/p>\n<p>Executive buy in &#8211; if you don&#8217;t have support from the top, you are going to have very slow forward progress, if at all. <\/p>\n<p>Everyone is a part of security. <\/p>\n<p>You can not prevent security incidents, so you better be able to detect them. <\/p>\n<p><strong>Process<\/strong> <br \/>I picked up a couple of books to prepare on my own. I already held a Security+ certification and a number of years\u00a0of real world experience in the\u00a0realms of desktop, server and network security\u00a0so it was fairly easy to become familiar with the concepts.\u00a0 <\/p>\n<p>As luck would have it, a CISSP boot camp was being offered. I had never taken a bootcamp before, and say what you will about bootcamps and how they may be more focused on teaching\u00a0you how to take the test then to actually learn, but for me, this was perfect way to\u00a0stay focused on something for a week. The instructor was excellent and had great explanations for some of the concepts that were new to me.<\/p>\n<p>\u00a0The day after the bootcamp, we wrote the exam. As I went to hand it in, I thought I did pretty good. By the time I got back to the parking lot, I was less sure, but thinking maybe I could scrounge the 700 points needed to pass. By the next morning, I was sure that I had failed and was checking online to see where I could re-write.\u00a0 <\/p>\n<p><strong>The long wait<\/strong> <\/p>\n<p>A week went by. <br \/>I received an email from isc2. My heart raced as I opened it. Doh! they were just soliciting feedback on the exam process. <\/p>\n<p>Another\u00a0next week went by. <br \/>Another email. This one looked more ominous. I broke into a\u00a0cold sweat while clicking. <\/p>\n<p><strong>Conclusion <\/strong><br \/>I have experience with a number of other testing\/certification organizations. Some of my\u00a0first certifications in the\u00a090&#8217;s seemed ridiculous. The preparation tools and overall knowledge objectives that they state they are testing on are great, but quite often, the questions on the test somehow cheapened the whole experience. Fortunately I think exams have gotten better over time.<\/p>\n<p>The CISSP exam was long and tiring, but the questions for the most part didn&#8217;t try to trick you with the dreaded\u00a0&#8220;select the best answer&#8221;. <\/p>\n<p>Becoming a CISSP <strong>did not<\/strong> make me an all knowing security expert. What it did do was\u00a0introduce me\u00a0to security concepts and paradigms and laid a strong foundation I could build upon. <\/p>\n<p>I am still building\u2026\u2026\u2026\u2026<\/p>\n<p><strong>Next Steps<\/strong><br \/>Sometime&#8230;once my wounds have healed,\u00a0I will recount my quest for the Offensive Security Certified Professional. Now that&#8217;s a test!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0 Why a CISSP? The following is just my opinion based on my experiences and readings. I am not an expert in anything, nor will I likely ever be one. My hope is that it might help someone, somewhere, sometime. If nothing else, it might be a good start for discussion. Preamble When I changed [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-21","post","type-post","status-publish","format-standard","hentry","category-certification"],"_links":{"self":[{"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/posts\/21","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=21"}],"version-history":[{"count":0,"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/posts\/21\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=21"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=21"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=21"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}