<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CAP Certification in Exams</title>
    <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45437#M1583</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1256042205"&gt;@scasc&lt;/a&gt;&amp;nbsp;- The CAP is relevant for anyone.&amp;nbsp; The current outline has more about the RMF but the risk management practices can be applied to any organization.&amp;nbsp; In fact, we have seen many non-DoD people take and pass the CAP and they let us know that it is helpful to manage risk following a framework for any organization.&amp;nbsp; The recent JTA last fall modified the outline which takes effect August 15, 2021 (as Ddrake mentioned above) to include various risk frameworks (such as ISO, COBIT and more) and to make it a more international certification.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From our website:&lt;BR /&gt;"&lt;SPAN&gt;The CAP shows employers you have the advanced technical skills and knowledge to understand Governance, Risk and Compliance (GRC) and can authorize and maintain information systems utilizing various risk management frameworks, as well as best practices, policies and procedures established by the cybersecurity experts at (ISC)²."&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 May 2021 18:31:58 GMT</pubDate>
    <dc:creator>ToniHahn</dc:creator>
    <dc:date>2021-05-12T18:31:58Z</dc:date>
    <item>
      <title>CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45379#M1569</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am new to this board so please bear with me :). I am interested in pursuing the CAP certificate as I do a lot of work in Cyber risk, security auditing of controls etc. However, the question I have is that is the CAP only suitable for people working in US Government/DOD?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am from the UK myself and wanted to pursue to learn and grow but if it is more catered towards US market then I can reconsider.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 12:03:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45379#M1569</guid>
      <dc:creator>scasc</dc:creator>
      <dc:date>2021-05-11T12:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45389#M1572</link>
      <description>&lt;P&gt;Hi and welcome!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Correct, the CAP really only has any relevance inside the US federal space, which is probably why there are relatively few people who hold it from outside the US:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/About/Member-Counts#accordion-20cdd133bc6a464890f28cc7fc4ec5bb" target="_blank"&gt;https://www.isc2.org/About/Member-Counts#accordion-20cdd133bc6a464890f28cc7fc4ec5bb&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The CAP is tied to a process called Assessment &amp;amp; Authorization which is part of the Risk Management Framework (RMF) mandated for use within US federal organisations, but used almost nowhere else - not even within the US commercial space.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you've ever been to a security industry event in the UK where ISC2 had a booth, you would see ISC2 EMEA don't even mention the CAP at all in any of the literature they hand out there. (They also don't mention the CISSP-ISSEP which also has links to the RMF, but the CISSP-ISSEP does at least cover other valuable areas including systems security engineering fundamentals, and technical project management.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's not to say there's no value in studying for the CAP if you're not looking to work in the US federal space. You'll learn a lot about the RMF which will obviously teach you a lot about risk management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to study for a certification to help you learn and grow as a security professional, seeing as you already have CISSP and CCSP, then I would highly recommend one of the CISSP Concentrations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck with whatever you choose!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 16:29:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45389#M1572</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2021-05-11T16:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45390#M1573</link>
      <description>&lt;P&gt;Many thanks for the response and letting me know. Pretty much thought so, just had the inkling that as the syllabus is being updated in August this might change too.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for pointing me in the direction of the concentrations. My next question was going to be finding a bootcamp class for the ISSAP. Any recommendations on providers will be greatly appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have heard that one has to read all the reference material/recommended sources but I am looking to get a head start by attending a training course for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am doing a lot more in the architecture space and am going for Sabsa training this year too (already have Togaf). I mainly do training with SANS and did the GDSA which was a mind blowing course. It will be great to get the ISSAP to solidify my credentials in this space.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 16:57:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45390#M1573</guid>
      <dc:creator>scasc</dc:creator>
      <dc:date>2021-05-11T16:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45398#M1574</link>
      <description>&lt;P&gt;I self-studied for the ISSAP using the suggested reference list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/certifications/References#accordion-204b5a1dc3534ba2b24f703df5e067ea" target="_blank"&gt;https://www.isc2.org/certifications/References#accordion-204b5a1dc3534ba2b24f703df5e067ea&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISC2 have their own online self-paced courses, although having never done any of them I can't really give a recommendation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/Training/Online-Self-Paced" target="_blank"&gt;https://www.isc2.org/Training/Online-Self-Paced&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to use a 3rd party, as long as they're listed as official training providers you should be fine:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/Training/Partners#accordion-654fa166cecf442b86de627cf392c6f3" target="_blank"&gt;https://www.isc2.org/Training/Partners#accordion-654fa166cecf442b86de627cf392c6f3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 17:40:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45398#M1574</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2021-05-11T17:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45399#M1575</link>
      <description>Thanks for your help and posting the links. Will check these out.&lt;BR /&gt;&lt;BR /&gt;How long did it take you to go through all self study reference list?</description>
      <pubDate>Tue, 11 May 2021 18:05:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45399#M1575</guid>
      <dc:creator>scasc</dc:creator>
      <dc:date>2021-05-11T18:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45400#M1576</link>
      <description>&lt;P&gt;I spent over 100 hours studying for the ISSAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I made a couple of posts about my ISSAP studies in this thread which is well worth a read:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Exam-Preparation/ISSAP-Passed-Study-Sharing/m-p/13660" target="_blank"&gt;https://community.isc2.org/t5/Exam-Preparation/ISSAP-Passed-Study-Sharing/m-p/13660&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My specific posts are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Exam-Preparation/ISSAP-Passed-Study-Sharing/m-p/21249/highlight/true#M1710" target="_blank"&gt;https://community.isc2.org/t5/Exam-Preparation/ISSAP-Passed-Study-Sharing/m-p/21249/highlight/true#M1710&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Exam-Preparation/ISSAP-Passed-Study-Sharing/m-p/21249/highlight/true#M1713" target="_blank"&gt;https://community.isc2.org/t5/Exam-Preparation/ISSAP-Passed-Study-Sharing/m-p/21249/highlight/true#M1713&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might find the last one interesting with reference to SABSA and TOGAF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 18:33:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45400#M1576</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2021-05-11T18:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45401#M1577</link>
      <description>Thanks again for all your help. Will check everything out.</description>
      <pubDate>Tue, 11 May 2021 18:54:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45401#M1577</guid>
      <dc:creator>scasc</dc:creator>
      <dc:date>2021-05-11T18:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45428#M1579</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Historically, the CAP has been US-centric.&amp;nbsp; However, the recently revised blueprint goes into effect August 15, 2021, and it is focused on risk management as a whole, and no longer focused on the US federal audience.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The new blueprint can be found at:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/-/media/ISC2/Certifications/Exam-Outlines/CAP-Exam-Outline.ashx" target="_blank"&gt;https://www.isc2.org/-/media/ISC2/Certifications/Exam-Outlines/CAP-Exam-Outline.ashx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let us know if you have any further questions!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Damon&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 14:59:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45428#M1579</guid>
      <dc:creator>ddrake</dc:creator>
      <dc:date>2021-05-12T14:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45430#M1580</link>
      <description>&lt;P&gt;Hi - thanks for letting me know. That is great news. Syllabus seems to have had a face lift to look at cyber risk holistically.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 15:38:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45430#M1580</guid>
      <dc:creator>scasc</dc:creator>
      <dc:date>2021-05-12T15:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45437#M1583</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1256042205"&gt;@scasc&lt;/a&gt;&amp;nbsp;- The CAP is relevant for anyone.&amp;nbsp; The current outline has more about the RMF but the risk management practices can be applied to any organization.&amp;nbsp; In fact, we have seen many non-DoD people take and pass the CAP and they let us know that it is helpful to manage risk following a framework for any organization.&amp;nbsp; The recent JTA last fall modified the outline which takes effect August 15, 2021 (as Ddrake mentioned above) to include various risk frameworks (such as ISO, COBIT and more) and to make it a more international certification.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From our website:&lt;BR /&gt;"&lt;SPAN&gt;The CAP shows employers you have the advanced technical skills and knowledge to understand Governance, Risk and Compliance (GRC) and can authorize and maintain information systems utilizing various risk management frameworks, as well as best practices, policies and procedures established by the cybersecurity experts at (ISC)²."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 18:31:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45437#M1583</guid>
      <dc:creator>ToniHahn</dc:creator>
      <dc:date>2021-05-12T18:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45457#M1589</link>
      <description>&lt;P&gt;Thanks - that's great to know. Does the CAP go deeply into the intricacies of these other frameworks or mention them as an alternative to manage risk whilst still mainly focusing on RMF?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I have seen a module on security auditing/assessment of controls so wanted to find out if this is derived mainly from the workings of the framework or can it cover more technical risk items?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 08:00:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45457#M1589</guid>
      <dc:creator>scasc</dc:creator>
      <dc:date>2021-05-13T08:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: CAP Certification</title>
      <link>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45458#M1590</link>
      <description>&lt;P&gt;I can't tell you what is on the exam. However, depending on when you are going to take the exam, download the right outline and it will give you what is covered on the exam.&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 12:05:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CAP-Certification/m-p/45458#M1590</guid>
      <dc:creator>ToniHahn</dc:creator>
      <dc:date>2021-05-13T12:05:25Z</dc:date>
    </item>
  </channel>
</rss>

