Upon passing either the CISSP, CSSLP, CAP or SSCP exams, which test a candidate’s understanding of the applicable CBK•, (ISC)'s taxonomy of global information security topics, the Associate of (ISC) will gain access to an elite peer network and career development resources offered exclusively to (ISC) members. Additionally, Associates of (ISC) gain access to the same benefits as (ISC)2’s certified members, including a suite of career development and support programs, such as a job search site, career clinics, virtual communities, networking events and continuing education opportunities.
Associates must subscribe to and abide by the (ISC) Code of Ethics, earn continuing education credits annually and pay annual membership fees. To become certified, Associates of (ISC)2 must gain the requisite work experience for the credential they are pursuing within five years for CSSLP and within three years for CAP and be endorsed by an (ISC)-certified professional in good standing.
While open to all interested candidates, the Associate program is also a resource for universities looking to support graduates’ transition into professional life and maps to the Workforce Framework being established by US Government National Initiative for Cybersecurity Education (NICE) Initiative.
“We welcome (ISC)2’s commitment to the advancement of the professionalization of the cybersecurity workforce,” says NICE National Lead, Dr. Ernest McDuffie. “Our Cybersecurity Workforce Framework
“The Associate program is a great way for those early in their careers to assess their knowledge and certification readiness and to show employers they are committed to practicing the highest standards and ethics in the field,” said W. Hord Tipton, CISSP-ISSEP, CAP, executive director of (ISC). “Given the government’s current shortage of information security professionals, we are pleased to offer the Associate program to help increase the number of skilled professionals that our cyber threat landscape requires. This program furthers (ISC)'s commitment to serving the needs of information security professionals at any age and/or stage of their careers as they travel along their career paths.”
The CSSLP, designed for professionals involved in the software lifecycle, requires four years of professional experience in the software development lifecycle (SDLC) in one or more of the seven domains of the (ISC) CSSLP CBK, while the CAP, designed for professionals responsible for formalizing processes used to assess risk and establishing security requirements and documentation, requires two years of work experience in one or more of the seven domains of the (ISC) CAP CBK.
The CSSLP and CAP exams are available to candidates worldwide. For more information on the Associate program, please visit https://www.isc2.org/associates/default.aspx.
About (ISC)2
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
How To Boost Security Via FFIEC Compliance
With just a smartphone, users can conduct nearly all their banking business at any time of the day or night. However, all this flexibility and convenience opens up new avenues for fraud and cybercrime. Guidelines laid out by the FFIEC several years ago predate many of the capabilities-and vulnerabilities-that are in place today. In this report, we examine the latest guidelines and provide advice on how you can extend the work done to comply with FFIEC guidelines to strengthen your organization's overall security posture and keep customers and their data safe.
Keeping Compliance In Check
Configuration mistakes, access control gaffes, poor documentation--it doesn?t take much for a compliance audit to go all wrong. In this special retrospective of recent news coverage, Dark Reading takes a look at the costs, common missteps and best practices for compliance, as well as the day the Internet nearly went dark due to the threat of new regulations.
FISMA Lifts All Compliance Boats
FISMA may not be on your radar now, but it likely will be at some point. Geared specifically toward the federal government and its affiliate agencies and third parties, FISMA is a very specific set of requirements aimed at establishing and maintaining at least a baseline level of computer and network security. FISMA requires unique categorization and classification of information assets, not to mention a boatload of documentation to prove compliance. But once your organization achieves FISMA compliance, it will likely be compliant with just about every security mandate out there.
Other reports from the Compliance Tech Center:
| Sponsored by: |
Log Management in 2012 and Beyond
2012 brings interesting changes to the log management world. Now, more than ever, it is critical to understand the impact to your log infrastructure and the solutions that will better prepare you to manage your security posture.
SANS Log Management Survey Report
Organizations are increasingly dependent on log management to support core business functions, including cost management, service level and line-of-business application monitoring, as well as traditional IT- and security-focused activities.
Cut the Time and Effort of Troubleshooting and Reporting
Organizations generate millions of logs a day and struggle with centralized collection, storage and analysis of those logs. ArcSight Logger is a universal log management solution that unifies searching, reporting, alerting and analysis across any type of IT data. It consolidates silos of logs into a single indexed repository for fast detection and mitigation of operational issues.
Get Turnkey and Automated PCI Compliance
PCI compliance monitoring is seamless with the self-contained ArcSight PCI Logger solution for log collection, storage and analysis. No database administration expertise is required and a web-based interface simplifies deployment and ongoing management.
Swiss Bank Meets Compliance Requirements and Protects Customer Data
Due to long-term data retention requirements, Swiss bank EFG needed a cost-effective way to collect, secure and store audit-quality log data in an easily accessible log repository. ArcSight Logger helps EFG meet key requirements of Switzerland?s banking laws fast and cost-effectively.
MORE NEWSFEED >>>