<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PCIP (PCI-DSS) in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22233#M2028</link>
    <description>&lt;P&gt;PCI certs.&amp;nbsp; As noted, ISA isn't transferable between employers, and the QSA is limited to if your company does it.&amp;nbsp; It's a big investment in getting that.&amp;nbsp; Better to team up with a QSA to do PCI assessments at this point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CEH is a mixed bag.&amp;nbsp; It's more a technical cert, seems more hands-on, but there are many who aren't impressed by it or EC-Council.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Privacy certs are useful only if you're really getting into privacy work.&amp;nbsp; I do some doing HIPAA work, but not focused enough to pursue on.&amp;nbsp; If I did, not sure if I'd go for the CIPT or one of the CIPP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would recommend taking a look at ISACA's CRISC or CISA cert.&amp;nbsp; And I'd really recommend the SANS/GIAC certs based on what areas you want to specialize in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 May 2019 14:14:07 GMT</pubDate>
    <dc:creator>emb021</dc:creator>
    <dc:date>2019-05-13T14:14:07Z</dc:date>
    <item>
      <title>PCIP (PCI-DSS)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22212#M2024</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Im looking for the next step from CISSP.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;what does everyone here think about the PCIP or ISA? Will they add value to the CISSP?&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;What about the CEH cert?&lt;/LI&gt;&lt;LI&gt;The CIPP data privacy professional is something im also considering.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;basically, trying to find out as much adding to skill sets to enhance a consulting career&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2019 23:16:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22212#M2024</guid>
      <dc:creator>oradba888</dc:creator>
      <dc:date>2019-05-11T23:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: PCIP (PCI-DSS)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22221#M2025</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/150369275"&gt;@oradba888&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Im looking for the next step from CISSP.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;what does everyone here think about the PCIP or ISA? Will they add value to the CISSP?&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;What about the CEH cert?&lt;/LI&gt;&lt;LI&gt;The CIPP data privacy professional is something im also considering.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;basically, trying to find out as much adding to skill sets to enhance a consulting career&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;In order to give meaningful answers to your questions, you first need to answer a few more for yourself:&lt;/P&gt;&lt;P&gt;1. What jobs do you want in your future?&lt;/P&gt;&lt;P&gt;2. What skill sets are called for in those jobs?&lt;/P&gt;&lt;P&gt;3. What companies or organizations do you want to work with and for: commercial, non-profit, government?&lt;/P&gt;&lt;P&gt;4. What certifications are you seeing in job ads from the companies you want to work for?&lt;/P&gt;&lt;P&gt;5. What cybersec or infosec tasks do you find engaging and really enjoy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remember, cybersecurity is not a single field, it is a mishmash of quite a few very different areas. Which of those fields do you want to become a specialist in?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 14:45:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22221#M2025</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2019-05-12T14:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: PCIP (PCI-DSS)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22223#M2026</link>
      <description>&lt;P&gt;Dr, Shelton,&lt;/P&gt;&lt;P&gt;Ideally, no government work, in cases where I can do consulting is probably worth it, meaning I have my own time/work schedule. Quality of life is more important to me, that being said, i'd hate to be in an arena where I sit on a desk for 8 hours..:) sorry to sound weird or spoiled...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That being said, I'd like to be in a role where I perform outbound consulting to several companies, that would be the long term target&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sounds more like a data privacy consulting or security consulting role would be ideal/practical for what I am looking for.&lt;/P&gt;&lt;P&gt;So that translates into:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1). Maybe a CIPP/CIPT IAPP certification and gain experience on the ever-blossoming data security/privacy arena.&lt;/P&gt;&lt;P&gt;2).&amp;nbsp; I thought about a CEH cert and that would also tie into data security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like you said, Security is such a broad term and one arena cannot exist without the other.&lt;/P&gt;&lt;P&gt;Meaning, to protect data, you have to know:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the technical controls: ( CEH, CISSP knowledge)&lt;/LI&gt;&lt;LI&gt;Admin controls (&amp;nbsp; Data privacy policies, executive management roles/controls, classifying data)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So no one thing,,,) heck, might as well get all of them..:)&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 17:25:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22223#M2026</guid>
      <dc:creator>oradba888</dc:creator>
      <dc:date>2019-05-12T17:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: PCIP (PCI-DSS)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22230#M2027</link>
      <description>&lt;P&gt;You have to think it through in terms of what job roles you're looking to move into next rather than just bag certifications and hope.&amp;nbsp; There are fairly clear career tracks in InfoSec; Pen Testing, Forensics, Incident Response, Audit, Training and Awareness, AppSec and more general GRC.&amp;nbsp; Thinking through what you'd be looking to do in the next couple of years as a next step.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may want to consider the CISSP concentrations, as they're not too specialised.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep in mind the ISA isn't transferrable between employers.&amp;nbsp;&amp;nbsp;Unless you're seeking to become a QSA, then specific PCI related qualifications are essentially.&amp;nbsp; You can pick up everything you need from general PCI course, reading the SSC documents and working practically on a compliance program.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're considering an audit focused career you may want to consider an ISACA CISA or a ISO 27001 LA qualification, but even with these you'd ben starting at the junior end of the spectrum, unless you already have audit experience.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The IAPP CIPP is a more specialised privacy related qualification, more typically held by Data Protection personnel.&amp;nbsp; It would balance out the more techncial focus of a CISSP, but you may find specialisation is more common in larger companies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 07:24:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22230#M2027</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-05-13T07:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: PCIP (PCI-DSS)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22233#M2028</link>
      <description>&lt;P&gt;PCI certs.&amp;nbsp; As noted, ISA isn't transferable between employers, and the QSA is limited to if your company does it.&amp;nbsp; It's a big investment in getting that.&amp;nbsp; Better to team up with a QSA to do PCI assessments at this point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CEH is a mixed bag.&amp;nbsp; It's more a technical cert, seems more hands-on, but there are many who aren't impressed by it or EC-Council.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Privacy certs are useful only if you're really getting into privacy work.&amp;nbsp; I do some doing HIPAA work, but not focused enough to pursue on.&amp;nbsp; If I did, not sure if I'd go for the CIPT or one of the CIPP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would recommend taking a look at ISACA's CRISC or CISA cert.&amp;nbsp; And I'd really recommend the SANS/GIAC certs based on what areas you want to specialize in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 14:14:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22233#M2028</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-05-13T14:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: PCIP (PCI-DSS)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22235#M2029</link>
      <description>Thanks&lt;BR /&gt;I took a look at CCSK last night and also based on my experience , this may be the path I will look at next.&lt;BR /&gt;And then the CISA would be nice&lt;BR /&gt;&lt;BR /&gt;Eventually I’m hoping ,using the CISSP route to get into privacy law&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from myMail for iOS</description>
      <pubDate>Mon, 13 May 2019 14:59:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22235#M2029</guid>
      <dc:creator>oradba888</dc:creator>
      <dc:date>2019-05-13T14:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: PCIP (PCI-DSS)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22237#M2030</link>
      <description>&lt;P&gt;The CISSP CBK does include privacy, so don't expect to much to change there. Could there be a new CISSP Privacy Engineering specialization that would be different then what the IAPP does with its CIPT? There is always room grow, but that is a business decision for (ISC)2. I would strongly support its development. The value in such a proposition is aligning it to security controls and privacy engineering concepts rather than legal prepositions. There is a lot of good work coming out from NIST along the lines of Privacy Engineering that CISSPs can reference in terms of building privacy-preserving Cloud services and applications.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 15:23:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22237#M2030</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2019-05-13T15:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: PCIP (PCI-DSS)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22238#M2031</link>
      <description>&lt;P&gt;With the advent of so many legal changes, i think we are in a splendid position to stay in the forefront. CISSP backgrounds are diverse that we can "plug and play" into any position and hit the ground running.&lt;/P&gt;&lt;P&gt;of course, having a specialty will onyl enhance, like the data privacy.&lt;/P&gt;&lt;P&gt;Seems more leaning towards legal counsel, but still , we have the technology edge to implement such a program.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 15:32:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/22238#M2031</guid>
      <dc:creator>oradba888</dc:creator>
      <dc:date>2019-05-13T15:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: PCIP (PCI-DSS)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/66203#M3603</link>
      <description>.inho I would suggest ( depending where you are I'm the journey: follow chronology this path consultant:&lt;BR /&gt;&lt;BR /&gt;CISSP, CCKS, CISA, PCIP, PCI-QSA&lt;BR /&gt;&lt;BR /&gt;Note: depending where's your on the journey as laid out above.&lt;BR /&gt;</description>
      <pubDate>Sat, 13 Jan 2024 03:12:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/66203#M3603</guid>
      <dc:creator>CyberMa8</dc:creator>
      <dc:date>2024-01-13T03:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: PCIP (PCI-DSS)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/69486#M3660</link>
      <description>&lt;P&gt;the issueis finding a QSA cert org that can take me on as an auditor&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 05:49:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/PCIP-PCI-DSS/m-p/69486#M3660</guid>
      <dc:creator>oradba888</dc:creator>
      <dc:date>2024-04-15T05:49:02Z</dc:date>
    </item>
  </channel>
</rss>

