(ISC)2 offers range of certifications

Opinion
Mar 31, 20053 mins

* Security certifications from the (ISC)2

The International Information Systems Security Certification Consortium offers more than simply the Certified Information Systems Security Specialist designation. In today’s article, I’ll summarize the credentials available to security professionals through this distinguished certifying body.

The Associate of (ISC)2 certification is designed to allow students and others who don’t yet have the years of professional experience in information security to qualify for the CISSP or SSCP (see below) nonetheless demonstrate their competence in the field and receive recognition for their accomplishments. Candidates pass the same examinations as the CISSP or SSCP and can eventually convert to full CISSP or SSCP status once their years of experience are sufficient.

CISSP was the first global certification in information assurance management; the six-hour, 250-question examination covers the 10 areas of the CISSP Common Body of Knowledge (CBK):

* Access Control Systems and Methodology

* Applications and Systems Development Security

* Business Continuity Planning and Disaster Recovery Planning

* Cryptography

* Law, Investigation and Ethics

* Operations Security

* Physical Security

* Security Architecture and Models

* Security Management Practices

* Telecommunications and Network Security

CISSPs must have four years of field experience in information assurance or three years of field experience plus a college degree.

The Systems Security Certified Practitioner (SSCP) certification is designed for practitioners such as network security engineers, security systems analysis and security administrators. The SSCP CBK includes the following seven domains:

* Access Control

* Administration

* Audit and Monitoring

* Cryptography

* Data Communications

* Malicious Code / Malware

* Risk, Response and Recovery

For more experienced information assurance professionals who are already CISSPs, (ISC)2 offers three additional levels of certifications:

* ISSAP: Concentration in Architecture (access control systems and methodology, telecommunications and network security, cryptography, requirements analysis and security standards, guidelines, criteria, technology-related business continuity planning and disaster recovery planning).

* ISSEP: Concentration in Engineering (systems security engineering, certification and accreditation, technical management, and U.S. government information assurance regulations).

* ISSMP: Concentration in Management (enterprise security management practices; enterprise-wide system development security; overseeing compliance of operations security; understanding business continuity planning, disaster recovery planning and continuity of operations planning; and law, investigations, forensics and ethics).

All members of the (ISC)2 must continue their professional education to maintain their credentials; for example, a CISSP requires 120 Continuing Professional Education (CPE) units in each three-year period to remain in good standing. CPE units can be accumulated through attending security lectures and courses, presenting at professional meetings, and through writing security articles or books.

I hope that readers who have not previously investigated the range of certifications offered by the (ISC)2 will visit the organization’s Web site at  https://www.isc2.org and explore the resources available there.