The Certified Information Systems Security
Professional (CISSP) is a certification for information security
professionals. This certification is obtained through the International
Information Systems Security Certification Consortium (ISC)2
for the purpose of recognizing individuals who have distinguished themselves
as an experienced, knowledgeable, and proficient information security
practitioner. The CISSP certificate also provides a means of identifying
those persons who subscribe to a rigorous requirement for maintaining their
knowledge and proficiency in the information security profession.
Certification is awarded to those individuals who
achieve a prescribed level of information security experience, comply with a
professional code of ethics, and pass a rigorous examination on the Common
Body of Knowledge of information security. In order to maintain currency in
the field, each CISSP must be recertified every three years by participation
in research or study, attendance at recognized subject-matter training and
professional educational programs, presentation or publication of information
security papers, contributions to the information security Common Body of
Knowledge, and service in professional organizations.
For more information, see the (ISC)2 web site at www.isc2.org.
ISSA endorses the Certified Information Systems
Security Professional (CISSP) certification provided by (ISC)²
as the certification for the Information Security Professional.
SSCP Certification was designed to recognize an
international standard for practitioners of information security [IS] and
understanding of a Common Body of Knowledge (CBK). It focuses on practices,
roles and responsibilities as defined by experts from major
IS industries. Certification can enhance an IS career and provide
added credibility.
Seven SSCP information systems security test
domains are covered in the examination pertaining to the Common Body of
Knowledge:
Access Controls
Administration
Audit and Monitoring
Risk, Response and
Recovery
Cryptography
Data Communications
Malicious Code/Malware
For further detail regarding SSCP Certification,
please refer to the SSCP White Paper posted on this (ISC)2, Inc. web site.
For more information, see the (ISC)2 web site at www.isc2.org.
SANS' GIAC Training and Certification Program is
designed to serve the people who are or will be responsible for managing and
protecting important information systems and networks. GIAC course
specifications were developed through a consensus process that involved more
than a hundred members of SANS' faculty and other experienced security
practitioners. They combine the opinions, knowledge, and expertise of many of
the world's most experienced front-line security and system administrators,
intrusion detection analysts, consultants, auditors, and managers.
The GIAC certification program consists of:
·Information Security KickStart
·LevelOne Security Essentials
·LevelTwo subject area modules
GIAC training and certification is presented in
live training sessions at SANS conferences. Information Security KickStart, LevelOne Security
Essentials, and an increasing selection of LevelTwo
courses are also offered over the web with both online course books and (in
most cases) audio tracks.