I heard recently that there are now more than 30,000 IT pros with CompTIA's Security+ certification. How does the
Security+ certification compare with (ISC)2's CISSP certification, and how much influence does it have in the security community?
I'm a pretty "pragmatic" guy, so I'm not a huge fan of certifications. Put it this way, I think there are a lot of folks that can pass a test, but don't have the experience to effectively do their job. A certification proves that someone has passed a knowledge standard, not much more than that. I don't really think that these specific certifications hold much influence. Some of the smartest security research folks I know are not CISSPs, yet they can break into your network in about 10 minutes.
But if you have your heart set on having some random letters behind your name on a business card, the differences between the certifications are rather minimal. You can compare the certifications across a number of characteristics, like how respected the certification is and whether the certification has a well-known brand. Security+ is often considered a beginner's certification, though it is pretty well-known. The test is fair, though not overly difficult, and it doesn't really require any prior experience in the field – which makes it appropriate for folks just entering it. At $225, it's reasonably priced as far as certifications go.
The CISSP is the granddaddy of security certifications, but as the number of certified practitioners has grown, the value of the CISSP has been watered down a bit.
The test is as much about stamina as anything else. It's not overly technical, but it is extensive. To prepare for the test, many folks take a week-long boot camp, and many pass. Yet in order to get your CISSP, you need to have 4 years of verifiable experience in the space. At $500 (plus an annual renewal), it ain't cheap – but if you've been doing security for a while and you want to get some letters, the CISSP is probably the best known.
Dig deeper on CISSP Certification
Related Q&A from Mike Rothman, Contributor
In the world of security certifications, what is the GISP and how alike is it to the CISSP? In this security management expert response, learn about ...continue reading
Depending on your enterprise, it may or may not be necessary to utilize a QSA. In this security management expert response, learn how to determine ...continue reading
When developing software securely, what role does gap analysis play? In this security management expert response, learn how to implement gap analysis...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.