<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do they understand..? in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9260#M2834</link>
    <description>&lt;P&gt;It is vital for the Hiring Manager(s)/leaders to know about the domain so that they can select right candidate(s). I have seen that often many resources are not up to the mark for the job they are hired to do and they don't have the zeal to learn which leads to a poor team which has a bigger responsibility.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Apr 2018 17:15:03 GMT</pubDate>
    <dc:creator>nagarajan</dc:creator>
    <dc:date>2018-04-11T17:15:03Z</dc:date>
    <item>
      <title>Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9215#M2831</link>
      <description>&lt;P&gt;I recently got interviewed for a security director’s position. It was advertised as Governance, Risk &amp;amp; Compliance. But by the time I got deep into the interview, I felt like what they really needed was a CCNP, MCSE &amp;amp; RHCE – along with the CISSP. Lucky for me, I can traverse a conversation of most any IT area since I have worked in IT for so long. I often wonder though if employers out there have the wrong idea about what a CISSP is and what we do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had to explain and advise more than a few employers interviewing me about their appropriate IT/HR needs. So, when I hear senior management exclaim that industry certifications don’t equate to ‘performance’ which I agree with in principle. But I am now thinking that maybe such leaders are not understanding their&amp;nbsp;technical / security management needs. SMH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2018 21:33:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9215#M2831</guid>
      <dc:creator>Lamont29</dc:creator>
      <dc:date>2018-04-10T21:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9230#M2832</link>
      <description>&lt;P&gt;I have often found that Job Descriptions don't exactly go with what an organization is wanting a security professional to do. Particularly HR and most hiring managers want a CISSP to do everything related to security. In my discussions, I found the reason for this to be due to the number of domains covered in the CISSP exam.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 03:52:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9230#M2832</guid>
      <dc:creator>nagarajan</dc:creator>
      <dc:date>2018-04-11T03:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9239#M2833</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do they understand? Probably not at first, but hopefully after speaking with you they had a better understanding of their gap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IMO, it is a hard question for most managers to figure out. IE what do they actually need for a skill set when it comes to security. I have met plenty of IT-centric managers that had no clue on security. Now, take a non-technical manager who is trying to fill a gap and they are throwing darts in the dark.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my thoughts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 11:42:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9239#M2833</guid>
      <dc:creator>tsutherburg</dc:creator>
      <dc:date>2018-04-11T11:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9260#M2834</link>
      <description>&lt;P&gt;It is vital for the Hiring Manager(s)/leaders to know about the domain so that they can select right candidate(s). I have seen that often many resources are not up to the mark for the job they are hired to do and they don't have the zeal to learn which leads to a poor team which has a bigger responsibility.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 17:15:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9260#M2834</guid>
      <dc:creator>nagarajan</dc:creator>
      <dc:date>2018-04-11T17:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9262#M2835</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/329353505"&gt;@nagarajan&lt;/a&gt;wrote:&lt;BR /&gt;&lt;P&gt;It is vital for the Hiring Manager(s)/leaders to know about the domain so that they can select right candidate(s).&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hell Nagarajan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While I agree the above statement &lt;STRONG&gt;should be&lt;/STRONG&gt; true, the point I was driving at, is that it &lt;STRONG&gt;often not&lt;/STRONG&gt; true, IMO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 17:43:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/9262#M2835</guid>
      <dc:creator>tsutherburg</dc:creator>
      <dc:date>2018-04-11T17:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10009#M2836</link>
      <description>&lt;P&gt;And I'm sure we've all been on the receiving end of looking at a job description that asked for CISSP, CISM, ISO 27K lead auditor, risk management and data protection knowledge to find that the hiring manager really wanted a firewall admin or sysadmin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And if they do want someone, they often want one person to do everything, which in a mid sized company just isn't humanly possible even if you work a 50 hour week every week.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 12:17:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10009#M2836</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2018-05-02T12:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10014#M2837</link>
      <description>Yes. That's exactly what I'm talking about Steve! What I've learned is to get as much out of the phone interview as I can. One recent contract opportunity went wayward because the recruiter had no idea what the requirements were. She was confused as to whether the primary requirement was project management or GRC. I suggested that they were not mutually exclusive, which enraged her and we went no further. But I did not want to formally attend an interview that I had no idea of the requirements. Those interviews rarely goes well in my opinion.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 02 May 2018 14:21:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10014#M2837</guid>
      <dc:creator>Lamont29</dc:creator>
      <dc:date>2018-05-02T14:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10023#M2838</link>
      <description>&lt;P&gt;Not sure business necessarily needs to know what it is we are supposed to be doing as much as they are responsible to keep an open mind and adjust both expectations and requirements as knowledge is gained. That's a bit long but true. Business needs to be open a changing environment and find the best person, if not a number of people to fill a position. Too often we do see these all-in-one roles that no one super-human could fill.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We as security practitioners need to be ready to do one of two things or loose credibility: Educate the ignorant; or be prepared to walk away. Its does no one any good to accept more work than one person could possibly accomplish in a reasonable amount of time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I have had those conversations with prospects whose eyes are bigger than their budgets.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 20:11:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10023#M2838</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2018-05-02T20:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10048#M2839</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/282628003"&gt;@tsutherburg&lt;/a&gt;wrote:&lt;BR /&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do they understand? Probably not at first, but hopefully after speaking with you they had a better understanding of their gap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IMO, it is a hard question for most managers to figure out. IE what do they actually need for a skill set when it comes to security. I have met plenty of IT-centric managers that had no clue on security. Now, take a non-technical manager who is trying to fill a gap and they are throwing darts in the dark.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's a great observation actually.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that ISC2 may want its professionals to be more security-focused in our careers, but I see a lot of lucrative opportunities in SALES..! Because of the dearth of understanding by senior managers in properly addressing their IT Security needs, this area seems to be wide open for certified professionals.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 03 May 2018 17:33:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10048#M2839</guid>
      <dc:creator>Lamont29</dc:creator>
      <dc:date>2018-05-03T17:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10050#M2840</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/783051913"&gt;@Steve-Wilme&lt;/a&gt;wrote:&lt;BR /&gt;&lt;P&gt;And I'm sure we've all been on the receiving end of looking at a job description that asked for CISSP, CISM, ISO 27K lead auditor, risk management and data protection knowledge to find that the hiring manager really wanted a firewall admin or sysadmin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And if they do want someone, they often want one person to do everything, which in a mid sized company just isn't humanly possible even if you work a 50 hour week every week.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;It's nice to know I'm not alone!&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 17:51:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10050#M2840</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-03T17:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10054#M2841</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/783051913"&gt;@Steve-Wilme&lt;/a&gt;wrote:&lt;BR /&gt;&lt;P&gt;And I'm sure we've all been on the receiving end of looking at a job description that asked for CISSP, CISM, ISO 27K lead auditor, risk management and data protection knowledge to find that the hiring manager really wanted a firewall admin or sysadmin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And if they do want someone, they often want one person to do everything, which in a mid sized company just isn't humanly possible even if you work a 50 hour week every week.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This is nearly always the case for small to medium size businesses. They often times have a poor understanding as to the time and energy that's required in these positions. Working more than 50 hours a week causes your good IT security personnel to seek greener pastures elsewhere. One can never negate the value of 'quality of life' in a career position.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 20:00:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10054#M2841</guid>
      <dc:creator>Lamont29</dc:creator>
      <dc:date>2018-05-03T20:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10056#M2842</link>
      <description>&lt;P&gt;This scenario has happened&amp;nbsp;to me.&amp;nbsp; I find a job description that I fit, practice&amp;nbsp;interview based on that description.&amp;nbsp; Then during the&amp;nbsp;interview and instead of a security person, they want a Dev-ops&amp;nbsp;person. It's extremely frustrating.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 20:50:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10056#M2842</guid>
      <dc:creator>Jaesimpson</dc:creator>
      <dc:date>2018-05-03T20:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10058#M2843</link>
      <description>I'm not sure what you mean. All I can say is that if you can't put hands on a keyboard and actually implement any security controls (harden an OS, properly configure a firewall, set up DNSSEC, set up a CA, run an actual pentest, etc), you have no business calling yourself a security professional. You should be clear that you are only a compliance professional. You don't need to be able to do everything - that's insanity. But if you don't have the technical ability and experience to do at least something security-related, and do it well, you simply aren't a security professional.&lt;BR /&gt;&lt;BR /&gt;Employers should understand that "almost" anyone that would claim they could do it all is likely not being honest, and should put them to the test if they truly feel they've found a unicorn during the hiring process.</description>
      <pubDate>Thu, 03 May 2018 23:30:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10058#M2843</guid>
      <dc:creator>billybob</dc:creator>
      <dc:date>2018-05-03T23:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10072#M2844</link>
      <description>&lt;P&gt;James,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve definitely been getting my share of Unicorn hunting calls/emails lately.&amp;nbsp; Specifically, around the buzzword “Insider Threat”.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think what folks here are talking about is an advertisement for one position that turns out to be a different position entirely.&amp;nbsp; An example from recent history is one that I got pitched by a headhunter:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The position of “Network Security Engineer” that requires a CISSP with a CCNA or CCDA, and either a CCNP or CCIE R&amp;amp;S highly desired.&amp;nbsp; The position requires knowledge of the Cisco IOS command line, routing and switching protocols, cable plant design and management, and network security architecture.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think many people, including myself, would see this as a senior level position.&amp;nbsp; Someone possibly doing network planning and design, and able to quality check subordinate’s work by reviewing configuration files or planned command sequences, and approving changes.&amp;nbsp; When I got to the phone interview with the customer, it became apparent that they are looking for a router/switch installation technician.&amp;nbsp; The CCNA/CCDA/Network+ level qualification was wholly appropriate.&amp;nbsp; Possibly even a BICSI qualification as well for the cable plant responsibilities.&amp;nbsp; There is absolutely no need for the CISSP, and a CCNP/CCIE would be severely overqualified.&amp;nbsp; Not only that but the salary range pitch is about 50% of what I expected and was more in line with an entry level person.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 16:00:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10072#M2844</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-04T16:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10091#M2845</link>
      <description>Yeah, understood. I believe employers are now looking at the CISSP as a basic requirement for any job with a security component. Which shouldn't be the case.&lt;BR /&gt;&lt;BR /&gt;In all honesty, I have yet to meet a CISSP with much practical/technical security experience...most I've met are solely policy/compliance people. I personally sat for it because of exactly what you are describing - a requirement for a job application. Which is stupid - but unfortunately necessary.</description>
      <pubDate>Sat, 05 May 2018 02:37:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10091#M2845</guid>
      <dc:creator>billybob</dc:creator>
      <dc:date>2018-05-05T02:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10137#M2846</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/188229057"&gt;@billybob&lt;/a&gt;wrote:&lt;BR /&gt;Yeah, understood. I believe employers are now looking at the CISSP as a basic requirement for any job with a security component. Which shouldn't be the case.&lt;BR /&gt;&lt;BR /&gt;In all honesty, I have yet to meet a CISSP with much practical/technical security experience...most I've met are solely policy/compliance people. I personally sat for it because of exactly what you are describing - a requirement for a job application. Which is stupid - but unfortunately necessary.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yeah,&lt;/P&gt;&lt;P&gt;That why I proposed the very rhetorical question of "Do They Understand..?" I am arriving at the conclusion: "Of course they don't!" Yet, I see opportunity in the gap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 19:15:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10137#M2846</guid>
      <dc:creator>Lamont29</dc:creator>
      <dc:date>2018-05-07T19:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10139#M2847</link>
      <description>&lt;P&gt;James,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/188229057"&gt;@billybob&lt;/a&gt;wrote:&lt;BR /&gt;Yeah, understood. I believe employers are now looking at the CISSP as a basic requirement for any job with a security component. Which shouldn't be the case.&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I agree.&amp;nbsp; That is unfortunate, but it is also an opportunity for those of us with the CISSP to take leadership roles and fix the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/188229057"&gt;@billybob&lt;/a&gt;wrote:&lt;BR /&gt;In all honesty, I have yet to meet a CISSP with much practical/technical security experience...most I've met are solely policy/compliance people. I personally sat for it because of exactly what you are describing - a requirement for a job application. Which is stupid - but unfortunately necessary.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;That hasn’t been my experience.&amp;nbsp; I have to admit that I am one of your stereotypical non-technical CISSPs.&amp;nbsp; I am somewhat intimidated and simultaneously bored by new technology.&amp;nbsp; I was formerly in a hands-on role in network and business systems consulting… about 20 years ago.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my professional travels, I have met two archetypes of CISSPs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first is your stereotype.&amp;nbsp; My very first professional engagement was an IT Audit contract circa 1998.&amp;nbsp; I will even admit to having come full circle by currently undertaking an Accounting degree rather than something in Tech.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second, though are amazing specialists!&amp;nbsp; These are folks that are Network Engineers, Systems Engineers, Programmers and DevOps.&amp;nbsp; With the CISSP these careers normally functioning in their silos and stovepipes began to speak a common language and understand the impacts their security constraints had in other business units.&amp;nbsp; They interfaced with facilities and security and were able to articulate protection needs.&amp;nbsp; They interfaced with human resources and line managers and got feedback on access requirements.&amp;nbsp; They jived with management accountants and budget analysts that wanted to know if a repair contract or on-hand spares for their gear were a better value.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you haven’t seen much of this second breed of CISSP, then man… you’re missing out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 21:17:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/10139#M2847</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-07T21:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Do they understand..?</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/13803#M2848</link>
      <description>&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Career/Finding-your-Unicorn/m-p/13800/highlight/true#M1306" target="_blank"&gt;See also&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 19:16:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Do-they-understand/m-p/13803#M2848</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-08-17T19:16:25Z</dc:date>
    </item>
  </channel>
</rss>

