<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Very interesting certification heat map (nationwide and state specific) in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7821#M621</link>
    <description>&lt;P&gt;While trying to determine my next certification pursuit, I found a useful (in my opinion) data site. It shows a breakout of a collection of popular certs (Security+, CIPP, GIAC, CISSP, CISA, CISM), the number of certification holders for each, and the number of job openings requesting that particular certification:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A title="Cyberseek Certification Heat Map" href="http://cyberseek.org/heatmap.html" target="_blank"&gt;http://cyberseek.org/heatmap.html&lt;BR /&gt;&lt;BR /&gt;&lt;/A&gt;For instance, at the national level it shows 76,413 CISSP certificate holders and 72,700 job openings requesting that certification. To me, that would indicate that the certification rate is keeping pace with the industry demand.&lt;BR /&gt;&lt;BR /&gt;For CISM however, it shows 12,428 certificate holders and 23,932 job openings requesting that certification. In my mind, that would seem to indicate that if one is pursuing certifications to remain marketable and employable (such as myself), the CISM would be a wise investment as demand seems to outpace supply.&lt;BR /&gt;&lt;BR /&gt;What do you think? Filtering the results to just my state showed a similar pattern.&lt;BR /&gt;&lt;BR /&gt;P.S. For my fellow grizzled and cynical IT veterans, I would like to mention the fact that I have no affiliation, vested interest, or benefit from the site mentioned above. Prior to 9:00 a.m. EST on 2/26/18, I had never heard of the above site.&lt;BR /&gt;&lt;BR /&gt;(Edited: Title changed during editing and I didn't catch it until now).&lt;/P&gt;</description>
    <pubDate>Mon, 26 Feb 2018 18:12:40 GMT</pubDate>
    <dc:creator>tryan</dc:creator>
    <dc:date>2018-02-26T18:12:40Z</dc:date>
    <item>
      <title>Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7821#M621</link>
      <description>&lt;P&gt;While trying to determine my next certification pursuit, I found a useful (in my opinion) data site. It shows a breakout of a collection of popular certs (Security+, CIPP, GIAC, CISSP, CISA, CISM), the number of certification holders for each, and the number of job openings requesting that particular certification:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A title="Cyberseek Certification Heat Map" href="http://cyberseek.org/heatmap.html" target="_blank"&gt;http://cyberseek.org/heatmap.html&lt;BR /&gt;&lt;BR /&gt;&lt;/A&gt;For instance, at the national level it shows 76,413 CISSP certificate holders and 72,700 job openings requesting that certification. To me, that would indicate that the certification rate is keeping pace with the industry demand.&lt;BR /&gt;&lt;BR /&gt;For CISM however, it shows 12,428 certificate holders and 23,932 job openings requesting that certification. In my mind, that would seem to indicate that if one is pursuing certifications to remain marketable and employable (such as myself), the CISM would be a wise investment as demand seems to outpace supply.&lt;BR /&gt;&lt;BR /&gt;What do you think? Filtering the results to just my state showed a similar pattern.&lt;BR /&gt;&lt;BR /&gt;P.S. For my fellow grizzled and cynical IT veterans, I would like to mention the fact that I have no affiliation, vested interest, or benefit from the site mentioned above. Prior to 9:00 a.m. EST on 2/26/18, I had never heard of the above site.&lt;BR /&gt;&lt;BR /&gt;(Edited: Title changed during editing and I didn't catch it until now).&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 18:12:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7821#M621</guid>
      <dc:creator>tryan</dc:creator>
      <dc:date>2018-02-26T18:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and Certification are NOT Synonymous Terms</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7836#M622</link>
      <description>I would think the ratio of Certificate holders verses Job openings doesn't take into consideration that many of those Certified CISSP's are already in the work force. So I would still think they would be in demand. And the competition for jobs just improves the work force.</description>
      <pubDate>Mon, 26 Feb 2018 18:06:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7836#M622</guid>
      <dc:creator>Irishsam</dc:creator>
      <dc:date>2018-02-26T18:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7846#M681</link>
      <description>&lt;P&gt;Thanks for the heatmap link! Really cool site that I had never heard of either...&lt;BR /&gt;&lt;BR /&gt;I'm currently seeking work with my CISSP out of state (Florida- I'm located in Indiana currently) and this really helps to see what the market is like where I'm looking (and where I'm at). It pretty much validates that I should be looking to move to a different state as Indiana doesn't have much of a demand for cybersecurity compared to other states.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 15:46:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7846#M681</guid>
      <dc:creator>MDCole9761</dc:creator>
      <dc:date>2018-03-09T15:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7847#M625</link>
      <description>&lt;P&gt;Thanks for the heat map link! Really cool site that I had never heard of either...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently seeking work with my CISSP out of state (Florida- I'm located in Indiana currently) and this really helps to see what the market is like where I'm looking (and where I'm at). It pretty much validates that I should be looking to relocate to a different state as Indiana doesn't have much of a demand for cyber-security compared to other states.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 19:50:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7847#M625</guid>
      <dc:creator>MDCole9761</dc:creator>
      <dc:date>2018-02-26T19:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7862#M628</link>
      <description>&lt;P&gt;Very cool resource. Thanks for sharing.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 02:26:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7862#M628</guid>
      <dc:creator>jordanpw</dc:creator>
      <dc:date>2018-02-27T02:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7980#M641</link>
      <description>&lt;P&gt;It is a very interesting page, thank you.&amp;nbsp; One question I have in reading the stats they present is: Does the 76K job openings only represent the job openings?&amp;nbsp; Meaning, of the 72K CISSP holders, I would think that the vast majority of them is employed (as I am).&amp;nbsp; Most in a position that requires CISSP.&amp;nbsp; So are they saying that there is another 76K positions vacant that need to be filled?&amp;nbsp; If so, then CISSP is clearly the way to go with many more vacancies.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 07:05:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7980#M641</guid>
      <dc:creator>Bertikus</dc:creator>
      <dc:date>2018-03-01T07:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7987#M642</link>
      <description>As Irishsam speculated above, I would concur that it's likely the stats are showing the total number of cert holders (in this example, CISSP) vs the vacant jobs requiring a CISSP cert.&lt;BR /&gt;&lt;BR /&gt;When you think about it, knowing how many certs are in an area is easy to extrapolate from certificate registration information (such as (ISC)2) and job posts by location are relatively easy to pull from job boards. What would be difficult, is knowing how many of those cert holders are employed without a lot of work and/or conducting surveys. So I would venture to say that, assuming most CISSP cert holders are employed, the # of jobs in that area reflects the true "unfilled demand" for that area.</description>
      <pubDate>Thu, 01 Mar 2018 13:39:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7987#M642</guid>
      <dc:creator>MDCole9761</dc:creator>
      <dc:date>2018-03-01T13:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7993#M643</link>
      <description>&lt;P&gt;That is correct. I think the only&amp;nbsp;group that could have any level of success finding out how many certificate holders were gainfully employed would be the certification groups (i.e. ISC2). I'm not aware of any surveys they've done, but that would be great information to have.&lt;BR /&gt;&lt;BR /&gt;I used this information to try and find out what certs would improve my marketability (hopefully) based on unmet demand. My logic may be flawed, but my thought process was that if there are a large number of unfilled positions looking for a certain cert, that would be a good cert to focus on.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 14:17:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/7993#M643</guid>
      <dc:creator>tryan</dc:creator>
      <dc:date>2018-03-01T14:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8052#M656</link>
      <description>&lt;P&gt;That's a very interesting resource. In my state, it looks like the CompTIA Security+ is way over-subscribed, but it could be that it's an entry level certificate with many holders moving on to other certifications afterwards.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 22:42:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8052#M656</guid>
      <dc:creator>Mcadit</dc:creator>
      <dc:date>2018-03-02T22:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8098#M664</link>
      <description>&lt;P&gt;Thank you for sharing this link! It would be interesting to know how the data was collected. Sometimes job posting would mention certification as "preferred" and not explicitly required. Sometimes certification could also be mentioned along with other certifications (ie "must have one or more of the following: CISSP, CISM, PMP "(yes I've seen postings like that)). So the holder/opening ratio may not be indicative of market saturation but rather it would hint at brand awareness of employers and job seekers. If a lot of organizations recognize, respect and have demand for professionals with given certification, then they will advertise for it via job opening (thus increasing job market for cert). If professionals are aware and respect certain industry certification,they will attempt to earn it and then include it within their job hunting profile (thus becoming part of potential candidate pool). So, from provided data I would say that CISM is less known than CISSP and so less companies ask for it (24k vs 72k). From professional side it may be valued less than CISSP (only about 12k candidates chose to pursue it vs 76k that hold CISSP certification. And some of those people might have both!). Security+ is considered to be great entry-level certification and is relatively easy to achieve (that's probably why there are 164k Security+ certified professionals).&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 08:20:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8098#M664</guid>
      <dc:creator>yevgeng</dc:creator>
      <dc:date>2018-03-05T08:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8172#M676</link>
      <description>&lt;P&gt;I feel the only thing indicated by this heatmap is a tremendous skillset gap that we are facing in the market, where it comes to managerial-level security and risk capabilities. Cool visualization, anyway - would love to see something similar for Europe&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 09:15:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8172#M676</guid>
      <dc:creator>MarcinJkt</dc:creator>
      <dc:date>2018-03-07T09:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8262#M679</link>
      <description>&lt;P&gt;I was certified CISM and CISA prior to the CISSP. I found the testing experience for the CISSP anticlimactic because of my prior preparation and knowledge. The CISM &amp;amp; CISSP will largely cover the same knowledge areas. The CISM seems to be a condensed version of the CISSP in my opinion.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 01:24:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8262#M679</guid>
      <dc:creator>Lamont29</dc:creator>
      <dc:date>2018-03-09T01:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8618#M708</link>
      <description>&lt;P&gt;Very interesting information.&amp;nbsp; I do not see any certification about Cyber Security Risk Management though.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 13:50:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8618#M708</guid>
      <dc:creator>marcosrrc</dc:creator>
      <dc:date>2018-03-25T13:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8662#M711</link>
      <description>&lt;P&gt;While the numbers you cite do indicate a greater shortage of CISMs than CISSPs, I interpret them as showing both certifications are in exceptionally high demand.&amp;nbsp; Think about it.&amp;nbsp; If there are 76K CISSPs, and 77K CISSP job openings, the majority of CISSPs probably already have jobs and aren't looking to fill those openings.&amp;nbsp; There are probably a dozen openings for each available candidate.&amp;nbsp; Them CISMs have it even better.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 19:38:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8662#M711</guid>
      <dc:creator>EdmundDantes</dc:creator>
      <dc:date>2018-03-25T19:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8778#M725</link>
      <description>&lt;P&gt;I understood the stats exactly as you did, with the job openings referring to additional positions to be filled.&lt;/P&gt;&lt;P&gt;And makes sense that the CISSP is the most requested certification.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 18:26:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8778#M725</guid>
      <dc:creator>jbetancourth</dc:creator>
      <dc:date>2018-03-26T18:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8788#M727</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/277179537"&gt;@MDCole9761&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I'm currently seeking work with my&lt;BR /&gt;&amp;gt; CISSP out of state&lt;BR /&gt;&lt;BR /&gt;Just curious...some of my colleagues and I have been curious about this for a while...&lt;BR /&gt;&lt;BR /&gt;In your experience, the jobs your applying to, what's the breakdown for CISSPs required for private v. public sector?&amp;nbsp; Are you looking for commercial work or are you looking for gov't work?&lt;BR /&gt;&lt;BR /&gt;In my travels, and I'm arguably in the 2nd hottest IT market in the country, we only see having a CISSP being needed in about 3% of the private sector openings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The public and private sector buttons on that heat map back our personal observations up.&lt;BR /&gt;&lt;BR /&gt;In the public sector though, darn near everyone wants a CISSP candidate.&lt;BR /&gt;&lt;BR /&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 21:04:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8788#M727</guid>
      <dc:creator>mgoblue93</dc:creator>
      <dc:date>2018-03-26T21:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8790#M729</link>
      <description>&lt;P&gt;I think that's a valid observation. The Department of Defense does require a certification for sensitive positions, and the CISSP is one of the qualifying certifications (link to PDF &lt;A href="https://www.sans.org/giac_dod_8140.pdf" target="_blank"&gt;here&lt;/A&gt;). In my CISSP certification class, at least 50% were DoD employees or contractors that had to pass the test by a certain date or they would lose their position.&lt;BR /&gt;&lt;BR /&gt;As a result, it's not difficult to imagine that would fuel a lot of interest in the CISSP and equivalent SANS certifications (i.e. GSLC/GCED).&lt;BR /&gt;&lt;BR /&gt;I have seen a few job postings with a preference for a CISSP, or a requirement for a CISSP or similar certifications, but outside of federal contracting gigs nothing that required a CISSP.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 21:40:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8790#M729</guid>
      <dc:creator>tryan</dc:creator>
      <dc:date>2018-03-26T21:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8831#M731</link>
      <description>&lt;P&gt;Here's my take in the public/private certification requirement:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Soft skills are favored for IT leaders who interact in the C-Suite over technical skills.&amp;nbsp; In either public or private spaces, there is likely few technically certified professionals in the C-Suite and they're more likely to have degrees in business management than computer science.&amp;nbsp; These leaders then turn around and hire more technical subordinates or issue contracts.&amp;nbsp; This is where you begin to find more certifications.&amp;nbsp; In larger organizations these decisions are guided by both Human Resources and Management Accountants.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Management Accountants evaluate the Cost of Quality ("CoQ") that involves assessing four areas, (a) Preventative Costs; (b) Appraisal Costs; (c) Internal Failure Costs; and (d) External Failure Costs.&amp;nbsp; When we're talking about certifications we're talking about mostly (a) Preventative Costs and possibly (b) Appraisal Costs.&amp;nbsp; In either the case of public or private sector organizations, the name of the game here is controlling costs.&amp;nbsp; The fact of the matter is that certified professionals cost more than non-certified professionals.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's look at providing an opportunity for an existing employee to become certified, and support that in a continued way.&amp;nbsp; A Preventative Cost includes the increased salary and benefits to retain a now-certified employee.&amp;nbsp; Another Preventative Cost now also includes initial or CPE-required training costs (tuition, travel, and non-productive salary; or increases in salary to offset training costs along with increased leave to attend training).&amp;nbsp; An Appraisal Cost is the cost of the examination (one or multiple attempts).&amp;nbsp; Finally this is offset by the savings from reduced Internal and External Failures.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Private space this is notoriously hard to get people to quantify.&amp;nbsp; As long as people can get to their email, business files, and the Internet then there is nothing perceptively to improve.&amp;nbsp; It's not until there is a catastrophe that the Private sector actually valuates the cost of either Internal (inability to transact business) or External Failures (loss of business from poor reputation, or damages from the result of litigation).&amp;nbsp; Effectively this is $0 because the perception is there is nothing wrong.&amp;nbsp; So, from the Management Accountant's perspective, you are adding overhead cost for no benefit.&amp;nbsp; You'll typically find someone looking for certifications in the private sector space when you have senior leaders that have been severely burned by IT failures before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Public space, especially the Department of Defense, the Internal and External Failure Costs are very much quantified - sometimes quantified by loss of life and in most other cases leading to the policy that mandates baseline certification, through lost incumbent votes.&amp;nbsp; Comparatively, the costs of Prevention (through initial and continuous training, and the increased costs of salary and benefits to retain that investment) and Assessment (Paying for government personnel to attend certification exams) is offset by the Internal and External Failure savings values that are very well quantified (because the law requires the government to account for expected and actual losses).&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 15:53:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8831#M731</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-03-27T15:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8835#M732</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Just referencing my previous posts, when I bring up the difference between public and private, it's from the notion of&amp;nbsp;how the CISSP is viewed?&amp;nbsp; What does having the CISSP in a job req really truly mean for an organization?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It's NOT to suggest that only the public sector believes in having&amp;nbsp;qualified people on staff.&amp;nbsp; Quite the contrary as both sectors consider cyber a priority equally.&amp;nbsp; Let's not get hung up on jargon either.&amp;nbsp; You can have a private&amp;nbsp;sector&amp;nbsp;employee without a cert who is just as qualified as a public sector employee who got their cert solely as a condition of employment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My personal opinion, the private sector doesn't care about CISSP certifications because that piece of paper hasn't shown a direct benefit (meaning $$$ -- business are in the business of making money first and foremost) to the bottom line.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;In the Private space this is notoriously hard to get people to quantify.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; In the Public space, especially the Department of Defense, the Internal &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; and External Failure Costs are very much quantified&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Where does that information come from?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think Sony, Target, Equifax would like to have a word with you about the impact, publicly, about their breaches.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 17:06:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8835#M732</guid>
      <dc:creator>mgoblue93</dc:creator>
      <dc:date>2018-03-27T17:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Very interesting certification heat map (nationwide and state specific)</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8841#M733</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/754920891"&gt;@mgoblue93&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I apologize if I didn't communicate this well.&amp;nbsp; I was attempting to establish why you don't see such a high number of job postings requiring or requesting certain IT certifications when compared to government.&amp;nbsp; I will address each of your points below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;Just referencing my previous posts, when I bring up the difference between public and private, it's from the notion of&amp;nbsp;how the CISSP is viewed?&amp;nbsp; What does having the CISSP in a job req really truly mean for an organization?&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The CISSP and any other certification, degree, or diploma is an Appraisal Cost for an organization of its service capability.&amp;nbsp; It serves as a method of examining the service provider (employee or contractor) and determining if they posses a baseline set of knowledge.or aptitude.&amp;nbsp; It then permits an organization to decide, as a result of that baseline if additional Preventative Costs are required by training existing service providers, or replacing them with more capable service providers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;&lt;SPAN&gt;It's NOT to suggest that only the public sector believes in having&amp;nbsp;qualified people on staff.&amp;nbsp; Quite the contrary as both sectors consider cyber a priority equally.&amp;nbsp; Let's not get hung up on jargon either.&amp;nbsp; You can have a private&amp;nbsp;sector&amp;nbsp;employee without a cert who is just as qualified as a public sector employee who got their cert solely as a condition of employment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I apologize if I stated somewhere that a certification causes someone to be qualified.&amp;nbsp; What I was trying to convey was that&amp;nbsp;a certification program is a way&amp;nbsp;for an organization to appraise if their service providers meet basic training and knowledge requirements.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;My personal opinion, the private sector doesn't care about CISSP certifications because that piece of paper hasn't shown a direct benefit (meaning $$$ -- business are in the business of making money first and foremost) to the bottom line.&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I agree with you.&amp;nbsp; When an organization wants to make a change, hopefully they do it using real information.&amp;nbsp; Typically this is done with the assistance of a Management Accountant who conducts a Cost of Quality ("CoQ") assessment.&amp;nbsp; The question to be answered here is, "Does requiring our service providers to be certified increase retained earnings?"&amp;nbsp; The problem in many organizations is that the estimated savings from a reduction in Internal and External Failures is hard (or takes too much time and effort) to assess -&amp;nbsp;or the estimate is that the impact to the brand will be minimal or temporary enough to outweigh the cost of adding additional controls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;In the Private space this is notoriously hard to get people to quantify.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; In the Public space, especially the Department of Defense, the Internal &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; and External Failure Costs are very much quantified&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Where does that information come from?&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am talking about estimating the savings in preventing Internal or External Failures before they happen, rather than quantifying the loss after it happens.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The difference between the public and private arenas are, that the public space has an&amp;nbsp;entire (Intelligence) community that assesses and reports on their threats, and has had a regulatory or administrative requirement to appraise their capabilities to defend against them for ages.&amp;nbsp; The private sector is only just catching up with the requirement in certain specific sectors such as the introduction of regulations that impact baseline computer security such as HIPAA.&amp;nbsp; In the case of an organization subject to HIPAA for example, t&amp;nbsp;is entirely reasonable to assume obtaining the services of a certified specialist in healthcare IT security has a return on investment in reducing Internal/External Failure Cost such as through avoiding litigation and civil penalties.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The concepts that I'm referring to here are part of the Common Body of Knowledge for the Institute of Management Accountants ("IMA"), blended with the Risk Management portion of the CBK for the CISSP under (ISC)^2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;&lt;SPAN&gt;I think Sony, Target, Equifax would like to have a word with you about the impact, publicly, about their breaches.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;You are kind of making my point.&amp;nbsp; There is an interest in increasing security after the costs are established from a realized security incident.&amp;nbsp; What was the certification and training requirement for their IT and Security staff, and what was their estimated savings from Internal/External Failure Costs from implementation of certification prorgams before they calculated the losses from their breeches?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 18:26:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Very-interesting-certification-heat-map-nationwide-and-state/m-p/8841#M733</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-03-27T18:26:15Z</dc:date>
    </item>
  </channel>
</rss>

