CISA Certification
Home > Ask the Security Experts > Security Management Questions & Answers > What's the difference between CompTIA and CISSP certifications?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What's the difference between CompTIA and CISSP certifications?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 23 February 2007
I heard recently that there are now more than 30,000 IT pros with CompTIA's Security+ certification. How does the Security+ certification compare with (ISC)2's CISSP certification, and how much influence does it have in the security community?

>
EXPERT RESPONSE
I'm a pretty "pragmatic" guy, so I'm not a huge fan of certifications. Put it this way, I think there are a lot of folks that can pass a test, but don't have the experience to effectively do their job. A certification proves that someone has passed a knowledge standard, not much more than that. I don't really think that these specific certifications hold much influence. Some of the smartest security research folks I know are not CISSPs, yet they can break into your network in about 10 minutes.

But if you have your heart set on having some random letters behind your name on a business card, the differences between the certifications are rather minimal. You can compare the certifications across a number of characteristics, like how respected the certification is and whether the certification has a well-known brand. Security+ is often considered a beginner's certification, though it is pretty well-known. The test is fair, though not overly difficult, and it doesn't really require any prior experience in the field – which makes it appropriate for folks just entering it. At $225, it's reasonably priced as far as certifications go.

The CISSP is the granddaddy of security certifications, but as the number of certified practitioners has grown, the value of the CISSP has been watered down a bit.

The test is as much about stamina as anything else. It's not overly technical, but it is extensive. To prepare for the test, many folks take a week-long boot camp, and many pass. Yet in order to get your CISSP, you need to have 4 years of verifiable experience in the space. At $500 (plus an annual renewal), it ain't cheap – but if you've been doing security for a while and you want to get some letters, the CISSP is probably the best known.

More information:

  • Visit our CISSP Certification Training School.
  • Did CISSP lose its luster? In a 2006 interview, Senior News Writer Bill Brenner asked (ISC)2 board member Howard Schmidt how the requirements had changed.


  • Sound Off! -   


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    Is it against HIPAA regulations to permanently store sensitive information?
    Two-tier distributed systems vs. three-tier distributed systems
    How to prevent software piracy
    How do ISO 17799 and SAS 70 differ?
    Has FFIEC made any VoIP-specific mandates?
    What is the best way to administer exams to students via computer?
    Should computer exams be transmitted as PDF files or Word files?
    Is it against HIPAA regulations to display client names?
    Getting started on a career in penetration testing
    Are there security management products that can track compliance objectives?

    CISSP Certification
    CISOs Must Innovate to Enable Business
    Information security book excerpts and reviews
    SearchSecurity.com guide to information security certifications
    Guide to vendor-specific information security certifications
    The road from network administrator to information security professional
    Industry experience vs. security certification credentials
    How can I get my CISSP certification?
    Defining your security certification objective
    Rethinking certifications
    Do certifications have credibility?
    CISSP Certification Research

    CISA Certification
    The vendor-neutral information security certification landscape
    Defining your security certification objective
    Rethinking certifications
    Employers to seek more security talent in '07
    Podcast: Security certifications pay could rebound in '07
    Security certification recommendations
    Intermediate-level security certifications
    Microsoft pads security partner competency
    Week 27: Credentials -- To be or not to be certified
    Ability to find employment with a CISA

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Certified Information Systems Security Professional  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts