<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Steal This Data &#187; Certified Information Systems Security Professional</title>
	<atom:link href="http://steal-this-data.com/tag/certified-information-systems-security-professional/feed/" rel="self" type="application/rss+xml" />
	<link>http://steal-this-data.com</link>
	<description>A Information Security Guide for Small and Medium Sized Businesses</description>
	<lastBuildDate>Mon, 01 Dec 2008 01:19:31 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Infosec Certification Guide: (ISC)2</title>
		<link>http://steal-this-data.com/2008/11/infosec-certification-guide-isc2/</link>
		<comments>http://steal-this-data.com/2008/11/infosec-certification-guide-isc2/#comments</comments>
		<pubDate>Mon, 24 Nov 2008 13:24:20 +0000</pubDate>
		<dc:creator>earlylit</dc:creator>
				<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[CAP]]></category>
		<category><![CDATA[Certification and Accreditation Professional]]></category>
		<category><![CDATA[Certified Information Systems Security Professional]]></category>
		<category><![CDATA[CISSP]]></category>
		<category><![CDATA[International Information Systems Security Certification Consortium]]></category>
		<category><![CDATA[SSCP]]></category>
		<category><![CDATA[Systems Security Certified Practioner]]></category>

		<guid isPermaLink="false">http://steal-this-data.com/?p=146</guid>
		<description><![CDATA[Whether you&#8217;re interested in becoming an information security professional or in hiring one, it&#8217;s helpful to know what the blizzard of infosec certifications out there are and what they mean. There are several organizations that issue reputable infosec certifications for IT&#160;professionals. In this post, I cover the certifications that can be obtained from the International [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>Whether you&#8217;re interested in becoming an information security professional or in hiring one, it&#8217;s helpful to know what the blizzard of infosec certifications out there are and what they mean. There are several organizations that issue reputable infosec certifications for IT&nbsp;professionals. In this post, I cover the certifications that can be obtained from the International Information Systems Security Certification Consortium, also known as the ISC-squared.</p>
<h4>CISSP</h4>
<p>CISSP stands for Certified Information Systems Security Professional. Considered by many to be the gold standard in infosec certifications, the CISSP measures an individual&#8217;s knowledge as well as their experience, requiring at least 5 years of experience working in information security in two or more of the following areas:</p>
<ul>
<li>Access Control</li>
<li>Application Security</li>
<li>Business Continuity and Disaster Recovery Planning</li>
<li>Cryptography, Information Security and Risk Management</li>
<li>Legal, Regulations, Compliance and Investigations</li>
<li>Operations Security</li>
<li>Physical (Environmental) Security</li>
<li>Security Architecture and Design</li>
<li>Telecommunications and Network Security</li>
</ul>
<p>To obtain a CISSP&nbsp;certification, individuals must go through a four step process that includes passing a CISSP certification exam, pass the exam with a score of 700 or more, and the submit an endorsement by another member of the ISC-squared that can attest to the candidates professional experience. Recertification is required every 3 years.</p>
<p>If you don&#8217;t have the required five years of professional experience, you can have one year waived if you possess <a href="http://www.isc2.org/credential_waiver/default.aspx" target="_blank">another security certification</a> recognized by the ISC-squared. Alternatively, you can take the CISSP certification exam early and obtain an <a target="_blank" href="http://www.isc2.org/associates/default.aspx">associate of ISC-squared certification</a> which will become a CISSP if you obtain the requisite professional experience in the following 6 years.&nbsp; For more information, visit <a href="http://www.isc2.org/cissp-how-to-certify.aspx" target="_blank">CISSP</a>.</p>
<h4>CAP</h4>
<p>CAP stands for Certification and Accreditation Professional and measures measures the skill level of individuals responsible for defining processes used to assess risk and establish security requirements. The CAP credential is aimed at information assurance professionals who have a responsibility for adherence to NIST (National Institute of Standards and Technology) guidelines. It is recognized by civilian, state and local governments in the U.S., as well as commercial markets. It is designed for employees who perform&nbsp; rights authorization, system owners, information owners, information system security officers, and senior system managers.</p>
<p>The CAP requires at least two years of professional experience in the following areas:</p>
<ul>
<li>Understanding the Purpose of Certification</li>
<li>Initiation of the System Authorization Process</li>
<li>Certification Phase</li>
<li>Accreditation Phase</li>
<li>Continuous Monitoring Phase</li>
</ul>
<p>&nbsp;Like the CISSP, CAP candidates need to pass an examination, obtain an endorsement to be certified, and remain in good standing by attending continuing professional education classes. For more information, visit <a target="_blank" href="http://www.isc2.org/cap/default.aspx">CAP</a>.</p>
<h4>SSCP</h4>
<p>SSCP&nbsp;stands for Systems Security Certified Practioner and only requires one year of professional infosec experience to apply for. It is designed for Network Security Engineers, Security Systems Analysts, and Security Administrators or other information technology and software development positions that require an understanding of security but do not have it as a primary part of their job description.</p>
<p>Although the SSCP&nbsp;is not as prestigious as the CISSP it is still a valuable certification to obtain if you are interested in an information security career. Organizations such as the US Department of Defense and the British Ministry of Defense require certifications for their information security personnel and the SSCP is an internationally recognized certification which can differentiate your resume.</p>
<p>For certification, your professional experience has to be in one of the following seven security domains:&nbsp;</p>
<ul>
<li>Access Controls</li>
<li>Analysis and Monitoring</li>
<li>Cryptography&nbsp;</li>
<li>Malicious Code</li>
<li>Networks and Telecommunications</li>
<li>Risk, Response and Recovery</li>
<li>Security Operations and Administration</li>
</ul>
<p>Like the CISSP, SSCP&nbsp;candidates need to pass an examination, obtain an endorsement to be certified, and remain in good standing by attending continuing professional education classes. For more information, visit <a href="http://www.isc2.org/sscp/default.aspx" target="_blank"><span style="text-decoration: underline;">SSCP</span></a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fsteal-this-data.com%2F2008%2F11%2Finfosec-certification-guide-isc2%2F&amp;linkname=Infosec%20Certification%20Guide%3A%20%28ISC%292"><img src="http://steal-this-data.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://steal-this-data.com/2008/11/infosec-certification-guide-isc2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
