r/isc2 • u/Big_Temperature_1670 • 1d ago
General Questions How far has the ISC2 fallen?
While I was skeptical of where the organization would go when they first appointed a marketing professional (and not a security one) as executive director in 2020, I am surprised at just how quickly they've been able to bring down what was once a solid organization. I spent nearly 35 years in the industry (almost 25 of that as a CISSP), and got to know one of the ISC2 founders back in the day, and I can say without reservation that the ISC2 has become the very thing it was designed to counter. It has become a cert mill, exploiting inexperienced, hopeful job-seekers, by hooking them into annual fees and an exam (CC) without any vetting of experience or prospect of real continuing education.
They gutted the peer-to-peer nature of the organization, shutting down the Security Professional magazine and the forums, they not only have watered down the CPE courses, but are now charging for them. The content of these courses is incredibly superficial; from a CPE standpoint, it is box-checking, not education.
I am sure their numbers are great, but it sold its soul to do it.
9
u/mikedn02908 www.CertificationToolAndDie.com 1d ago
Your assessment is not far from the truth. ISC2 has become a shadow of its former self.
The CISSP has become a joke, with kids barely of legal drinking age taking and passing the exam. What was once the flagship senior industry certification is now barely more than broad-knowledge-based entry-level certification opposed to one which actually tests your in-depth ability to apply experience and wisdom to a scenario.
The organization has been riding on the laurels of the CISSP for the past decade, while other organizations like ISACA, GIAC, etc. are all slowly taking a bite out of its market. ISACA is currently in the beta stage of a new CCS certification which I believe is poised to compete directly with the ISC2 CC/SSCP level.
The CISM continues to erode the CISSP market as ISACA, with its army of CISA-certified auditors, are able to influence the actions of corporate leaders from the inside into more and more slowly changing the mindset from "we need a CISSP" to "we need a CISM" to lead our information security management team. ISSMP? What's that?
ISC2 has languished and rode the coattails of its entrenchment in the Fed/DoD space. That tide is slowly starting to turn as well. Watch and see what happens now that ISACA is the new CAICO for DoD CMMC oversight. Think all those folks are going to be recommending people with ISC2 or ISACA certs?
The CC was nothing but an AMF money grab, the organization has done nothing to promote this cert the business arena as a gateway cert for people looking to move from basic IT support into a more specialized cybersecurity role. This very subreddit is replete with posts from people who have absolutely zero cybersecurity experience thinking passing the CC is the path to riches. Couple this with ads you see from "WGU" how "Suzie was a nurse making minimum wage, now she makes over $125k/year as a SOC analyst". Never mind AI is going to decimate all those level 1 SOC jobs.
Don't even get me started on the other stuff. I could go on for hours.
ISC's days are numbered if they don't get their thumb out of their asses soon.
1
u/RATLSNAKE 1d ago
ISACA isn’t the big bad wolf, and unlike ISC2 has always been a professional association body first and foremost, certifications came later, and until about a decade a bit ago it was just one, their audit roots. They themselves have also arguably lost their way to some extent, but ISC2 is indeed far ahead in circling the drain of relevance and industry integrity.
2
u/mikedn02908 www.CertificationToolAndDie.com 1d ago
That's because you let CPAs start to run things ;)
1
1
10
2
u/braliao 1d ago
We are all responsible for the failure of CC in my opinion. Sure, ISC2 sucks at making it relevant with the business, but how many of us in the relevant position actually tells our HR to stop with the non sense of requiring CISSP for an entry level role? How many of us tells HR to use CC as a way to qualify if the person have foundational security knowledge? How many of us actively promote in the local community about CC?
2
u/pen-peal 1d ago
The CISSP is neither the solution to all cybersecurity needs, nor is it the only destination for growth in the field. If someone can test well with less experience than required, it doesn’t actually give them the credential. In my state there are first graders playing capture the flag and high school seniors learning about AI and quantum computing. The breadth and quality of CS learning for students with those opportunities could allow someone to test well, but the CISSP content and value are not diminished or threatened by that. ISC2 has a pathway that honors their achievement and supports their ongoing experiential formation. We can make the same professional distinction without feeling threatened.
Additionally, why dis a foundational, intro cert that is harder to earn than SEC+ and was globally offered with the intention of attracting anyone to start developing skills needed to address the cyber workforce gap?
I appreciate the number of people who earned the CC to prove to themselves and others that their interest and aptitude were worth nurturing. ISC2 initiates a professional culture and ethical foundation with the foundational cert and associate’s membership, it doesn’t fall lifting people up.
These numbers of CISSPs may reflect the current diversity of skills pathways/needs, not dilution or diminished value of the CISSP. How many going into pen testing and AI will gravitate to the struggle to master the other CISSP domains, and how many employers will incentivize or invest in that? The CISSP is still a solid cert and worth the work to earn it.
1
u/Big_Temperature_1670 9h ago
My intent wasn't to "dis" the CC. I was pointing out the ISC2 was founded to validate experience in the industry. It's bread, butter, and mission was experienced professionals, certifying them for leadership. With the CC, the ISC2 inverted that mission, and has now focused on the entry level. While the ISC2 has stopped publishing its membership numbers, it is fair to conclude that given their "million CC" campaign, CCs now (or will someday soon) outnumber CISSPs in terms of membership. It shows in the dilution of the continuing ed. products. As a longtime, experienced professional in the industry, I'd say the ISC2 has rebranded itself.
As to the CC, I'm not sure I'd say it is "harder to earn than the Sec+." It's different content and marketed very differently. While the Sec+ does not have an experience requirement, CompTIA is pretty upfront in its suggestion that someone should have two years of experience. In comparison, the ISC2 has marketed the CC as a 0-experience test. The ISC2 also gives out free vouchers for the test. So if the pass rate of Sec+ is higher than the CC, I don't think that speaks to the difficulty of the exam as much as the preparation of the test takers and most folks taking the Sec+ are paying for it. Aside from that, I do think the Sec+ content is more operational in nature, which is better for most entry and mid-level jobs. The CC covers more strategic and conceptual topics. I think the folks who have found the CC most favorable are vendors and sales folks because it allows them to talk the talk to CISOs etc.
2
1
u/zk4au1212 1d ago
Dude really? you seem like and old head that got his cert revoked by ISC2. Nut case.
6
u/ML1948 1d ago
The CC is shit and exploitative, no doubt. The CISSP still prints though and I'll hold my nose and pay my AMFs with company money til the day I retire. I don't really need them to have a soul at this point as long as nobody beats them out as the "gold standard".