Showing posts with label CISSP. Show all posts
Showing posts with label CISSP. Show all posts

CISSP and Its Features

The Certified Information Technology Security Systems Professional (CISSP) examination is administered by the International Information Systems Security Certification Consortium or (ISC) 2, a worldwide nonprofit organization devoted to education and credentialing in information technology security. The examination process has been in operation since 1994, and makes use of a 6-hour test that consisted of multiple choice questions until 2014. In the 2014 examination, "advanced innovative" questions were introduced, which may have more than one correct answer. The examination is 6 hours in duration and has 250 questions yielding 1000 possible points, on which a score of 700 or greater is needed to pass.

Certified Information Systems Security Professional
The exam is given at numerous Pearson VUE testing centers and can be taken in Korean, Japanese, Spanish, Portuguese, French, German and Simplified Chinese as well as English. The examination fee is $599 US or its equivalent as of 2015. The examination seeks to test knowledge of 8 domains of the Common Body of Knowledge (CBK) which have been codified since 1992. These are software development security, security operations, assessment and testing of security, identity and access management, communication security, security engineering, asset security and risk management. This was done with the traditional multiple choice questions prior to 2014, but the present and future examinations also include "drag and drop" questions, in which the candidate is asked to select answers from one column and drag them to another column, as well as "hot spot" questions, such as those in which the candidate indicates a particular place in a schematic or diagram as the answer.

These new questions are intended to cover wider areas than can be done with standard examination questions, measure a broader range of IT security abilities, test more than the traditional cognitive processes and more accurate replicate the in-the-field experience of IT security. The (ISC)2 has suggested that appropriate candidates for the examination include network architects, security architects and auditors, security directors, IT managers and corporate information security officers, security systems engineers and managers and analysts and consultants working in the field of IT security. The CBK tested in the examination is described in a number of publications and websites, and a revise of the CBK can be obtained from the (ISC) 2. This organization also publishes an outline of the examination, and operates an official training seminar.

Many books and websites offer information useful for CISSP preparation, "boot camps" are available for intensive review prior to the examination and courses are offered by educational institutions and at meetings related to IT security.

CISSP and Your Paycheck

The SANS Institute estimated in 2005 that IT professionals with CISSP certification were not only paid more than those with only a bachelor's degree but also earned more than IT professionals with other certifications. Certification magazine has estimated from survey data that achievement of CISSP certification results in a pay increase of 5 to 30 per cent.

CISSP® - Certified Information Systems Security Professional
CISSP® - Certified Information Systems Security Professional
PayScale.com has reported on the basis of a survey of some 4000 individuals in the IT field in 2015 that the salary range for an information security analyst was $59,000-117,000.00, while information security managers made between $79,000 and $139,000.00. The range for security architects was $91,000-154,000.00, and for information security officers $68,000-142,000.00. Salaries ranged from $68,000-132,000.00 for security engineers.

The same survey suggested that the average salary for web designers was $28,000-73,000.00. Base salaries ranged from $30,000-68,000.00, and bonuses from zero to approximately $5,000.00. Profit-sharing also varied widely with company of employment, from a low of $493.16 to a high just under $10,000.00. Commissions varied from zero to almost $5,000.00. Individuals with CISSP certification in architecture averaged $136,000.00 a year in 2009, according to Certification, while the average salary for those with the CISSP-ISM credential in management was $134,000.00 a year.

Network administrators have a wide range of responsibility and seniority, and work in a variety of business and institutional settings; consequently their annual compensation has a wide range. The Infosec Institute estimates that the median salary for network administrators is approximately $85,000.00 per year, although starting out in desktop support may bring as little as $30,000.00 per year. This same institution estimates that lead network administrators with wide-ranging responsibilities can make up to $120,000.00 annually, and that specialists in specific operating systems start at higher salaries and are likely to be better paid. Linux network administrators were estimated to earn $73,000.00, while Cisco network administrators commanded $85,000.00 and network administrators with EMC2 earned around $92,000.00 annually.

CISSP-credentialed network architects can look forward to a six-figure income, averaging $108,000.00 according to Pay-Scale. Salaries in 2014-2015 were estimated at $77,000 to approximately $153,000.00 a year, with bonuses as high as $20,000.00 and a profit-sharing range of $1,500.00-22,000.00. Nearly all network architects reported generous medical, dental and other benefits, and not surprisingly, network architects surveyed by Pay-Scale were highly satisfied with their compensation.

In all these surveys of CISSP professionals, major determinants of salary and benefits were experience, seniority and location. IT professionals in major metropolitan areas or places with high concentrations of businesses and institutions with substantial IT security requirements were more readily employed and generously compensated, and expertise in multiple operating systems or CISSP certification in sub-specialty areas as well as longer duration of experience and employment did much better in salary. It is generally agreed that a CISSP credential can result in better compensation at work, and it may well also contribute to greater job security.

*CISSP® - Certified Information Systems Security Professional

BTBY

Popular Posts