Showing posts with label CISSP. Show all posts
Showing posts with label CISSP. Show all posts

Thursday, 12 June 2014

CISSP and CPE Credits...

I know a few colleagues and friends have passed or looking at doing their CISSP (Certified Information Systems Security Professional) from the ISC2 (International Information Systems Security Certification Consortium).  There are two common questions when people find out I'm a CISSP and they are; what books or course did you use? and how easy is it to maintain your CPE (Continuing Professional Education) credits?

I read a few books during my studies, but the ones I would recommend are Eric Conrad's books.  I used the CISSP Study Guide (Second Edition) for my main reading, which I supplemented with the Sybex CISSP Study Guide, when I needed to read about a topic is a different way.  I found Eric Conrad writes is a technically minded way, which I mean it's written for someone with a technical background.  We often don't need the stories and the "fluff" used to pack out study guides making then 1,500 to 1,600 pages!  The Eric Conrad book is just over 500 pages which great when you still have a full time job to do as well.

I used the Exam Cram CISSP Practice Questions to test and validate my newly learnt knowledge.  I also used the questions available from Eric Conrad's companion site.  On the run up to the exam, I used Eric Conrad's Eleventh Hour CISSP: Study Guide.  I hold Eric Conrad in high regard even though I've never met him, without his study guides, I'm not sure I would have passed the exam.

When you have passed the exam, you have to be in good standing and maintain CPEs by continuing your education.  If you work in IT Security, you should been keeping up to date regardless of the CISSP!  I have managed to complete 3 years of required CPE credits in less than six months!

I work in the "channel" which means I have interaction with my vendors regarding security solutions, and have to attend a number of conferences, webcasts, training session, webinars and meetings.  I also read various industry magazines to keep up to date regarding the threat landscape.  Many of these activities count towards your CPE credits.  I read somewhere that you only need to spend an hour a week over the three years to maintain your CPE credits.

There are regular webcasts and InfoSecurity Professional magazine from ISC2, which count towards your CPEs.  Here are other resources that will count towards your CPEs:

Infosecurity Magazine
Infosecurity Europe
SC Magazine UK

Register on these sites and you will receive notifications of webcasts that will keep you up to date as well as count towards your CPEs.

Good luck if you are studying for your exam and happy reading if you are maintaining your CPEs!


Thursday, 19 December 2013

It's been a while... [CISSP]

It's been a while since I've blogged, and for that I'm sorry.  The other thing I haven't done in a while is take an exam, so what better way to get my blog kick started again, but talk about the exam I've recently taken!

I've been working at e92plus for a while and have meant to take my CISSP (Certified Information Systems Security Professional) exam, but was put off by my peers with the old adage that "it's a mile wide and an inch deep" or putting other things first, like my family.

I did mean to take the exam this summer, but other commitments meant I rescheduled it to the end of this year.  September this year was my 7 year anniversary at work, so I decided to go for it, rather than reschedule it to next year.

I did my research and I bought a few books.  I had the following books:

  • The Official (ISC)2 Guide to the CISSP CBK (3rd Edition)
  • All in One CISSP Exam Guide by Shon Harris (6th Edition)
  • CISSP Study Guide by Eric Conrad, Seth Misenar & Joshua Feldman (2nd Edition)
  • CISSP 11th Hour Study Guide by Eric Conrad
  • Exam Cram CISSP Practice Questions by Michael Gregg (3rd Edition)

Before I tell you how I found these books, I have to give some of my background. I've worked in IT for 19 years, starting from a more generalist IT support role, to a more focused security role.  I have been an MCP since 1998, as well as hold an MCSE for NT4 and Windows 2003.  I have had roles where I was part of the DR/BCP planning team as well.  I carry out presales consultancy, installations, some support and training in a number of solutions, but seem to focus on two factor authentication and SSL-VPNs.

With that in mind, I'll let you know what I think of the books!

The Official (ISC)2 Guide was a little dry for me, but was starting at too basic a level for me.  I would expect my less experienced engineers to be able to read and understand the topic from this book, but it's a thick book!

The Shon Harris book is recommended by a lot of people, but I found the book too chatty for me.  I wanted my facts and less fluff.

The Eric Conrad books helped me pass my exam!  It was written at the right level for me, and there was a lot less "chat" with these books.  The study guide is around 500 pages, but the 11th Hour book which I read on the train into London is less than 200 pages summarising what I consider the essentials.

The Exam Cram was good for the software to let me test my knowledge after reading the Conrad book.

My experiences may not work for you, but I was using the books above, the supporting Conrad website for podcasts and tests, as well as the TechTarget website.

There is no score, but I was thankful I passed the exam today!

I have been unsociable (more so than normal) for the last month or so, and my Freeview (PVR) box is overfilling with programmes I haven't watched.  My children will see me again, just in time for Christmas!

So Merry Christmas to you all and if you decide to do you CISSP, let me know how you get on.

Friday, 7 August 2009

CISSP - Getting started?

I decided to look at other qualifications after completing a raft of Microsoft qualifications recently, which included:
  • MCSE:Security 2003
  • MCSA:Security 2003
  • MCTS:ISA 2006
Although the product I specialise in are Microsoft based, they do not utilise anywhere near the knowledge you have to learn for an MCSE, so working for a Network Security Distributor, the CISSP seems to fit better than the MCSE!

My current bedtime reading is this: http://www.dummies.com/store/product/CISSP-For-Dummies-2nd-Edition.productCd-0470124261.html

It's only to whet my appetite, until I have the time to read the proper books!