Should I go for a CISSP or a BS7799?

Should I go for a CISSP or a BS7799?

I'm working as a network security engineer for two years now. I would like to go for some security management courses. Should I go for a CISSP or BS7799? Also in the BS7799 should I do the implementation or auditor course?

I am WatchGuard-certified -- will a certification on Check Point help?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

The route you take in training should reflect the direction that you want your working life to take. The BS7799/ISO17799 has rather more to do with standard compliance evaluation, planning, and implementation whereas the CISSP is more a credential for working security practitioners who can cover the whole range of security topics and activities.

Thus, if you'd prefer to focus on BS7799/ISO17799 stuff, do the implementation training to make that happen or the auditing stuff to evaluate the work of others in implementing those standards. This seems to lead one into large corporations or government agencies where such efforts would be ongoing and constant, or into consulting work where one would help (or evaluate) customers to come into compliance.

On the other hand, the CISSP appears (at least to me) to offer a broader entry into the field and would support working as a full- or part-time security professional, along with network engineering. It could also permit a move into security management, development work, planning, auditing, risk assessment, and all kinds of other fields.

Though, in the end only you can decide what fits your interests and abilities best.

This was first published in September 2004