CIT 694 Introduction. CISSP Certified Information Systems Security Professional “The credential for professionals who develop policies and procedures.

Slides:



Advertisements
Similar presentations
Reasons to Become CISSP Certified Keith A. Watson, CISSP CERIAS.
Advertisements

Introduction to the CGFM Program
Information Technology as a Profession
Professional Certification Programs from the National Contract Management Association.
Elevate Your BC Career Presented by: Cheyene Haase of BC Management, Inc. The Skills, Experience and Credentials in Demand for Business Continuity Professionals.
CMA Awareness Stacie Hughes, CMA, CFM, CPA, CFE Athens State University Student Chapter IMA.
Security and Personnel
1 CMAA Student Chapter | | 12 Pages Washington DC ‘11 RISING CONSTRUCTION MANAGER CONFERENCE November 5-6 Grand Hyatt Texas A&M Department of Construction.
American College of Healthcare Executives Your Partner in Career Success.
UMBC TRAINING CENTERS © 2010, Paladin Group, LLC Certified Information System Security Professional (CISSP)
Regional Competitiveness Initiative: 4 th Annual Regional Conference on Competitiveness and Economic Growth International Standards and Certifications.
CMP, CGMP – Are these the designations your were looking for? Jim Cacabelos, CMP, CGMP.
Practice for the CISSP Exam Steve Santy, MBA, CISSP IT Security Project Manager IT Networks and Security.
Australian Computer Society Helping Students Launch a Successful Career.
Chapter 15 Information Technology Careers.
Security Certification
1 DRI International’s Certification Process Professional certification for leaders in continuity management.
Software Quality Certifications CSQA and CSTE By: Laura Widder, CSQA.
IT Project Management, Third Edition Appendix B1 Appendix B: Advice for the Project Management Professional (PMP) Exam and Related Certifications.
Copyright Course Technology Appendix B: Advice for the PMP Exam and Related Certifications.
ISACA Wellington: 2014 Strategy. Background ISACA’s vision: Trust in, and value from, information and information systems ISACA’s mission: For professionals.
BUILDING FUTURES Presentation by Mr _____________ (Kaplan Financial Country Head)
What is CISSP Anyway? A Presentation by: George L. McMullin II, CISSP COO, CorpNet Security, Inc. Executive Director, NEbraskaCERT.
Certified Information System Security Professional (CISSP)
Certification Executive Overview Vision: CSTD Professionals enable the success of the Canadian workforce.
HRPA INFORMATION SESSION. Presentation Agenda Who is HRPA? What is the Certified Human Resources Professional (CHRP) designation? Why join HRPA? How to.
SoCRA The Society of Clinical Research Associates Kimberly B. Bradley, CCRP.
Certified Software Tester V2.0 CSTE Certification Process.
Certification and Training Presented by Sam Jeyandran.
The Standard of Excellence in Employee Benefits Presented by: Wayne Murphy, CEBS (The PBAS Group) ISCEBS, Toronto Chapter - Fundamentals May, 2011.
© Paradigm Publishing Inc Chapter 15 Information Technology Careers.
PROJECT MANAGEMENT PROFESSIONAL (PMP ® ) CERTIFICATION BRIEFING 19 MAY 2010 Society of American Military Engineers 19 May SAME- PMP Certification.
Copyright Course Technology Appendix B: Advice for the PMP Exam.
Data and Applications Security Developments and Directions Dr. Bhavani Thuraisingham The University of Texas at Dallas CISSP Certification and GIAC/GCFA.
APICS Certification: Why How Maintenance Karen Schiebout, CPIM, CSCP.
“Putting the pieces together – as a community” December, 2014.
I.S.P. Value Proposition Societal Transition Committee Saturday, October 19, 2002.
Career Opportunities in Information Technology There are four main categories of IT jobs, grouped by the main focus of the job: Sales and support Software.
The Value of AGA Membership. Are You Connected?  AGA CONNECTS YOU WITH  Networking Opportunities  Education and Training  Professional Certification.
1 Chapter Nine Engineering Your Career. 2 Engineering Careers  Electrical and computer engineers find employment in: 1.Private industry. 2.Government.
CISSP Thomas Moore. Thomas Moore, Ph.D., EMBA BCSA BCSP LCNAD CISM CISSP LMNOP (Licensed Microsoft Network Operations Professional) B.S. No, really, in.
Q What’s New at SHRM. 2 Keep Up with Healthcare Reform News With SHRM’s Toolkit  To avoid penalties under the Patient Protection and Affordable.
CISSP Best Practices Guide to the Basics of Certified Information Systems Security Professional 1 The Certified Information System Security Professional.
Information Systems Audit and Control Association ( ISACA ) – Certified Information Security Manager (CISM ) ITEC 6324 Instructor: Dr. E. Crowley Name:
NPMA Certification Program Panel Presentation by: Rosanne (Beth) Green, CPPM, CF Tara Miller, VP of Eastern Region Cathy Seltzer, VP of Professional Development.
The Certified Private Equity Professional (CPEP) Designation
Certified Information System Security Professional (CISSP)
Certified Software Tester CSTE Certification Process.
Introduction to the CGFM Program AGA’S OFFICE OF PROFESSIONAL CERTIFICATION.
Center for Cybersecurity Research and Education (CCRE)
2 Information System Security Association ISSA Buffalo Niagara Introduction to CISSP Study Sessions.
McGraw-Hill ©2009 The McGraw-Hill Companies, Inc. All rights reserved. Insert cover image so horizontal lines in cover design line up with gold horizontal.
CSODP Certified Senior Organization Development Professional September 2015.
A Roadmap to PMI PMP Certification PMI Kentucky Bluegrass Professional Development Workshop.
ACMP: Advancing the discipline of change management Page: 1 CCMP Comes Alive! April 20, 2016.
Information Security Principles and Practices by Mark Merkow and Jim Breithaupt Chapter 3: Certification Programs and the Common Body of Knowledge.
Certified Government Auditing Professional® (CGAP®)
HFMA Certification Programs Presented By the ___________Chapter.
ASQ Recertification with Ease… 2016 Tips and Pointers Merle Goddard, Recertification Chair Don Gatza, Recertification Chair Assistant.
CPP PIHRA Meeting - 2/28/17 - Presented by Cheryl Wyrick, Ph.D.
ISA 400 Management Information Security
CISSP TRAINING IN.
Delivering structured project solutions with a flexible methodology
PMP certification maintenance
The Institute of Certified Managers (ICRM)
The Institute of Certified Records Managers
Certified Information Technology Professional (CITP) Credential
Data and Applications Security Developments and Directions
Welcome to Special programs night!
What is it and why should I have it?
Presentation transcript:

CIT 694 Introduction

CISSP Certified Information Systems Security Professional “The credential for professionals who develop policies and procedures in information security.” The CISSP is a very popular among information security professionals. – >94,000

(ISC)2 Certification from (ISC) 2 – International Information Systems Security Certification Consortium “the global, not-for-profit leader in educating and certifying information security professionals throughout their careers. We are recognized for Gold Standard certifications and world class education programs.”

Obtaining CISSP Certification Four years of professional experience with a college degree. Pass examination. Agree to a code of ethics. Submit your résumé with an endorsement by someone who has a CISSP certification and is familiar with your work.

Charles Frank, CISSP Passed the CISSP examination in November 2010 Obtained the CISSP in March Renewed in March 2014.

CISSP Ten Domains 1.Access Control 2.Business Continuity and Disaster Recovery 3.Cryptography 4.Information Security Governance and Risk Management 5.Legal, Regulations, Investigations and Compliance 6.Operations Security 7.Physical and Environmental Security 8.Security Architecture and Design 9.Software Development Security 10.Telecommunications and Network Security

Textbook

Shon Harris Book Chapter 2-11 cover the 10 domains Study Guide for the CISSP exam

We’re Specialized Information security professionals are specialized. Professors are strong in the domains related to their discipline. – Computer Science: Application Security – Computer Information Technology: Network Security – Information systems : Information Security Governance and Risk Management

Me Computer science professor – Teach Computer Security – Research Secure Software Engineering Background emphasized technology as the way to address security. Develop a broader view and a deeper understanding of information security.

Preparation Read Shon Harris’ CISSP All-in-One Exam Guide (1,160 pages – now 1383) (ISC)2 ten week online course – $1,995 – Good review – Insufficient to pass the exam – Insights into CISSP test gamesmanship

CISSP Exam $599 Six hours Challenging Exam. Tests applying knowledge rather than memorization of terms or facts 250 multiple choice questions – All four selectable answers might have some degree of correctness – Need to pick the best answer. Average 86 seconds per question. >= 70% to pass

Test Taking Approach 1.Read each question carefully, underlining key words. 2.Review the question, focusing on the key words. 3.Select the best answer 4.Move on

Recertification Required every three years. Earn 120 continuing professional education (CPE) hours Minimum of 20 CPEs each year Annual maintenance fee of $85.

CPEs Professional association chapter meeting – OWASP – ISSA – InfraGard Listen to webcast or podcast – Gary McGraw’s Silver Bullet – OWASP Podcasts – Vendor webcasts

CPEs Publish a security paper – Thank you InfoSecCD Attend a security conference – DerbyCon – Louisville 16 hours of participation – InfoSecCD

CPEs Read information security book (5 CPEs) – It takes more than 5 hours to read a book – Do you always want to read the whole book? Read an information security magazine – IEEE Security and Privacy – ISSA Journal – Do you always want to read the whole magazine?

CPEs Recording CPEs are easily done on the (ISC)²® website Rare random audit – documentation Six months, earned 140 CPEs 120 CPEs over three years minimal indicator of keeping up-to-date in the dynamic field of information security.

Critique: (ISC)2 Revenue Cost – (ISC)2 Training course $1,995 (to $2,495) – (ISC)2 CISSP Study Book $69.95 – Test $599 – Annual Maintenance Fee $85 (ISC)2 is generating revenue from this certification (ISC)2 regularly sends me marketing CISSP preparation materials.

(ISC)2 Defense All revenue and expenses are balanced and invested for the benefit of our membership. It is important to note that (ISC)2 is a highly successful organization that has not raised the costs to membership since our inception, while continually increasing member benefits.”

Cost Issue An employer should consider whether the CISSP certification is cost effective in educating key employees in information security. If an employer does not pay, this places a significant financial burden on the applicant employee.

Knowledge not Credentials “What you know and can do is more important than a certification.” Is a college degree important? – Bill Gates

DerbyCon Penetration Testers, Social Engineers, Hackers They do their penetration tests for CISSPs We are the Ninjas. They are the bureaucrats. Do you know more than a CISSP?

Gary McGraw Information security “leaves plenty of room for hacks and hucksters.” “A CISSP certification is an indicator that someone has mastered a common body of practical security knowledge”.

Reality In a highly competitive job market, certifications can make a professional more marketable. CISSP has become a fairly standard requirement for getting one’s résumé to be looked at.

Salary (ISC)2 sponsored survey found the average salary for a professional with an (ISC)² certification is $106,900. DerbyCon speaker. – CISSP in corner office driving a BMW

Personal Benefits Broadened my security prospective in areas such as governance. Obtaining CPEs required me to spend time on professional development. CBK provided curriculum guidance to educate my students. Credibility within the local information security community.

Conclusion CISSP does not guarantee that you will be a quality professional. A Ph.D. does not guarantee you will be a quality professor. CISSP certification validates that you have broad security knowledge. Maintaining the CISSP requires professional development.