Welcome Guest. | Log In | Register | Membership Benefits

New Associate of (ISC) Programs For CSSLP And CAP Help Aspiring Professionals Prepare For Careers In Cyber Security

Program expansion part of push to fill the pipeline of qualified cybersecurity professionals

Jan 12, 2012 | 02:37 PM | 


Palm Harbor, Fla., U.S.A., January 12, 2012 – (ISC)' (“ISC-squared”), the world’s largest information security professional body and administrators of the CISSP', today announced the expansion of the Associate of (ISC) program to include the Certified Secure Software Lifecycle Professional (CSSLP') and Certified Authorization Professional (CAP') credentials. Already available for the Certified Information Systems Security Professional (CISSP') and Systems Security Certified Practitioner (SSCP') credentials, the Associate of (ISC) program allows aspiring information security professionals to sit for a credential exam to assess their knowledge and build their professional network while they’re gaining the work experience required to become certified.

Upon passing either the CISSP, CSSLP, CAP or SSCP exams, which test a candidate’s understanding of the applicable CBK•, (ISC)'s taxonomy of global information security topics, the Associate of (ISC) will gain access to an elite peer network and career development resources offered exclusively to (ISC) members. Additionally, Associates of (ISC) gain access to the same benefits as (ISC)2’s certified members, including a suite of career development and support programs, such as a job search site, career clinics, virtual communities, networking events and continuing education opportunities.

Associates must subscribe to and abide by the (ISC) Code of Ethics, earn continuing education credits annually and pay annual membership fees. To become certified, Associates of (ISC)2 must gain the requisite work experience for the credential they are pursuing within five years for CSSLP and within three years for CAP and be endorsed by an (ISC)-certified professional in good standing.

While open to all interested candidates, the Associate program is also a resource for universities looking to support graduates’ transition into professional life and maps to the Workforce Framework being established by US Government National Initiative for Cybersecurity Education (NICE) Initiative. “We welcome (ISC)2’s commitment to the advancement of the professionalization of the cybersecurity workforce,” says NICE National Lead, Dr. Ernest McDuffie. “Our Cybersecurity Workforce Framework document lays a foundation for the various competences that comprise cybersecurity and provides certification companies and academic institutions a common starting point to map course work and certifications to a recognized set of cybersecurity skills. We appreciate the support that (ISC)2 and the certification community has demonstrated in terms of open dialog and several ongoing efforts where certifications and courses are being mapped to the NICE Cybersecurity Workforce Framework.”

“The Associate program is a great way for those early in their careers to assess their knowledge and certification readiness and to show employers they are committed to practicing the highest standards and ethics in the field,” said W. Hord Tipton, CISSP-ISSEP, CAP, executive director of (ISC). “Given the government’s current shortage of information security professionals, we are pleased to offer the Associate program to help increase the number of skilled professionals that our cyber threat landscape requires. This program furthers (ISC)'s commitment to serving the needs of information security professionals at any age and/or stage of their careers as they travel along their career paths.”

The CSSLP, designed for professionals involved in the software lifecycle, requires four years of professional experience in the software development lifecycle (SDLC) in one or more of the seven domains of the (ISC) CSSLP CBK, while the CAP, designed for professionals responsible for formalizing processes used to assess risk and establishing security requirements and documentation, requires two years of work experience in one or more of the seven domains of the (ISC) CAP CBK.

The CSSLP and CAP exams are available to candidates worldwide. For more information on the Associate program, please visit https://www.isc2.org/associates/default.aspx.

About (ISC)2 (ISC) is the largest not-for-profit membership body of certified information security professionals worldwide, with over 80,000 members in more than 135 countries. Globally recognized as the Gold Standard, (ISC) issues the Certified Information Systems Security Professional (CISSP•) and related concentrations, as well as the Certified Secure Software Lifecycle Professional (CSSLP•), Certified Authorization Professional (CAP•), and Systems Security Certified Practitioner (SSCP•) credentials to qualifying candidates. (ISC)’s certifications are among the first information technology credentials to meet the stringent requirements of ISO/IEC Standard 17024, a global benchmark for assessing and certifying personnel. (ISC) also offers education programs and services based on its CBK', a compendium of information security topics. More information is available at www.isc2.org



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Compliance Reports

report How To Boost Security Via FFIEC Compliance
With just a smartphone, users can conduct nearly all their banking business at any time of the day or night. However, all this flexibility and convenience opens up new avenues for fraud and cybercrime. Guidelines laid out by the FFIEC several years ago predate many of the capabilities-and vulnerabilities-that are in place today. In this report, we examine the latest guidelines and provide advice on how you can extend the work done to comply with FFIEC guidelines to strengthen your organization's overall security posture and keep customers and their data safe.

report Keeping Compliance In Check
Configuration mistakes, access control gaffes, poor documentation--it doesn?t take much for a compliance audit to go all wrong. In this special retrospective of recent news coverage, Dark Reading takes a look at the costs, common missteps and best practices for compliance, as well as the day the Internet nearly went dark due to the threat of new regulations.

report FISMA Lifts All Compliance Boats
FISMA may not be on your radar now, but it likely will be at some point. Geared specifically toward the federal government and its affiliate agencies and third parties, FISMA is a very specific set of requirements aimed at establishing and maintaining at least a baseline level of computer and network security. FISMA requires unique categorization and classification of information assets, not to mention a boatload of documentation to prove compliance. But once your organization achieves FISMA compliance, it will likely be compliant with just about every security mandate out there.

Other reports from the Compliance Tech Center:

Related Content

Log Management in 2012 and Beyond
2012 brings interesting changes to the log management world. Now, more than ever, it is critical to understand the impact to your log infrastructure and the solutions that will better prepare you to manage your security posture.

SANS Log Management Survey Report
Organizations are increasingly dependent on log management to support core business functions, including cost management, service level and line-of-business application monitoring, as well as traditional IT- and security-focused activities.

Cut the Time and Effort of Troubleshooting and Reporting
Organizations generate millions of logs a day and struggle with centralized collection, storage and analysis of those logs. ArcSight Logger is a universal log management solution that unifies searching, reporting, alerting and analysis across any type of IT data. It consolidates silos of logs into a single indexed repository for fast detection and mitigation of operational issues.

Get Turnkey and Automated PCI Compliance
PCI compliance monitoring is seamless with the self-contained ArcSight PCI Logger solution for log collection, storage and analysis. No database administration expertise is required and a web-based interface simplifies deployment and ongoing management.

Swiss Bank Meets Compliance Requirements and Protects Customer Data
Due to long-term data retention requirements, Swiss bank EFG needed a cost-effective way to collect, secure and store audit-quality log data in an easily accessible log repository. ArcSight Logger helps EFG meet key requirements of Switzerland?s banking laws fast and cost-effectively.




Featured Webcasts
Featured Whitepapers
Featured Reports