|
|
|
|
|
by austincheney
1695 days ago
|
|
Have you taken the CISSP exam? Greater than 95% of the complaints I see on HN against certs generally and CISSP especially come from people who have never attempted them. When I took it in 2010 it was 250 very large questions. You had 6 hours to complete the exam and it only had 60% pass rate despite a $700 fee and requiring an approved resume. Also at all my major corporate employers there security teams. Almost never are those people red teams or blue teams. Almost all of them are policy people or operations people. |
|
How many of those 250 questions are related to proper implementation of cryptography? How about side channel attacks? How about the relative effectiveness of mitigations like ASLR? How about SELinux? Seccomp/eBPF? I really doubt it.
I can bet you though that is has about 20 questions on SQL injection and input sanitization issues from the early 2000's. A big section on how firewalls are going to save you and that WAFs are the best things since sliced bread.
CISSP is a certificate for whiteboard warriors that 9 times out of 10 have zero practical experience and even less theoretical understanding of security.
It might help you land a job as a CISO a some random enterprise company but it's not going to help you successfully defend that company from any credible threat and it's -not- a credible certification for a proper security professional.
The only reason why it helps you land that job is they don't know what they are looking for and have zero ways to evaluate your potential effectiveness or measure your performance (unless you get pwned).
(There is some isolated cases of real professionals being forced to obtain such credentials for the sake of ticking boxes, they are excused)