Certified Information Systems Security Professional



CISSP is an independent information security certification granted by the International Information System Security Certification Consortium, also known as ².
As of July 1, 2020 there are 141,607 ² members holding the CISSP certification worldwide, a fall of just over 500 since the start of the year.
In, the CISSP designation was accredited under the ANSI. It is also formally approved by the U.S. Department of Defense in their Information Assurance Technical, Managerial, and System Architect and Engineer categories for their certification requirement.
In May 2020, The UK National Recognition Information Centre assessed the CISSP qualification as a Level 7 award, confirming the certification is comparable to Masters degree standard. The change will enable cyber security professionals to use the CISSP certification towards higher education course credit.

History

In the mid-1980s, a need arose for a standardized, vendor-neutral certification program that provided structure and demonstrated competence. In November 1988, the Special Interest Group for Computer Security, a member of the Data Processing Management Association, brought together several organizations interested in this goal. The International Information Systems Security Certification Consortium or "²" formed in mid-1989 as a non-profit organization.
By 1990, the first working committee to establish a Common Body of Knowledge had been formed. The first version of the CBK was finalized by 1992, and the CISSP credential was launched by 1994.
In 2003 the CISSP was adopted as a baseline for the U.S. National Security Agency's ISSEP program.

Certification subject matter

The CISSP curriculum breaks the subject matter down into a variety of Information Security topics referred to as domains. The CISSP examination is based on what ² terms the Common Body of Knowledge. According to ², "the CISSP CBK is a taxonomy – a collection of topics relevant to information security professionals around the world. The CISSP CBK establishes a common framework of information security terms and principles that allow information security professionals worldwide to discuss, debate and resolve matters pertaining to the profession with a common understanding."
From 15 April 2018, the eight domains covered are :
  1. Security and Risk Management
  2. Asset Security
  3. Security Architecture and Engineering
  4. Communication and Network Security
  5. Identity and Access Management
  6. Security Assessment and Testing
  7. Security Operations
  8. Software Development Security
From 2015 to early 2018, the CISSP curriculum is divided into eight domains similar to the latest curriculum above. The only domain to have changed its name was "Security Engineering," which in the 2018 revision was expanded to "Security Architecture and Engineering."
Before 2015, it covered ten domains :
  1. Operations security
  2. Telecommunications and network security
  3. Information security governance and risk management
  4. Software development security
  5. Cryptography
  6. Security architecture and design
  7. Access control
  8. Business continuity and disaster recovery planning
  9. Legal, regulations, investigations and compliance
  10. Physical security

    Requirements

Number of CISSP members as of July 1st, 2020 is 141,607.
Country Count
United States89,880
United Kingdom7,590
Canada5,937
China2,821
Japan2,758
Netherlands2,755
Australia2,750
India2,534
Germany2,493
Korea, Republic of2,324
Singapore2,280
Hong Kong1,848

Concentrations

Holders of CISSP certifications can earn additional certifications in areas of speciality. There are three possibilities:
  1. Identity and Access Management Architecture
  2. Security Operations Architecture
  3. Infrastructure Security
  4. Architect for Governance, Compliance, and Risk Management
  5. Security Architecture Modeling
  6. Architect for Application Security
As of May 31, 2019, there were 2,003 ² members holding the CISSP-ISSAP certification worldwide.
  1. Security Engineering Principles
  2. Risk Management
  3. Security Planning, Design, and Implementation
  4. Secure Operations, Maintenance, and Disposal
  5. Secure Engineering Technical Management
As of May 31, 2019, there were 1,178 ² members holding the CISSP-ISSEP certification worldwide.
  1. Leadership and Business Management
  2. Systems Lifecycle Management
  3. Risk Management
  4. Threat Intelligence and Incident Management
  5. Contingency Management
  6. Law, Ethics, and Security Compliance Management
As of May 31, 2019, there were 1,216 ² members holding the CISSP-ISSMP certification worldwide.

Initial fees and ongoing certification

The standard exam costs 699 USD or 650 EUR as of 2019. The CISSP credential is valid for three years; most holders renew by submitting Continuing Professional Education credits. There is also a yearly membership fee required to maintain certification, this fee was increased by nearly 50% starting in mid-2019.

Value

In 2005, Certification Magazine surveyed 35,167 IT professionals in 170 countries on compensation and found that CISSPs led their list of certificates ranked by salary. A 2006 Certification Magazine salary survey also ranked the CISSP credential highly, and ranked CISSP concentration certifications as the top best-paid credentials in IT.
In 2008, another study came to the conclusion that IT professionals with CISSP and at least 5 years of experience tend to have salaries around US, about US higher than IT professionals with similar experience levels who do not have such certificates. Note that any actual cause-and-effect relationship between the certificate and salaries remains unproven.
As of 2017, a study by CyberSecurityDegrees.com surveyed some 10,000 current and historical cyber security job listings that preferred candidates holding CISSP certifications. CyberSecurityDegrees found that these job openings offered an average salary of more than the average cyber security salary.
ANSI certifies that CISSP meets the requirements of ANSI/ISO/IEC Standard 17024, a personnel certification accreditation program.