<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISSEP vs ISSAP in Exams</title>
    <link>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35437#M675</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1099977225"&gt;@AlecTrevelyan&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Why do you have to decide between them? Why not do both like I did?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISC2 have a sale on online learning materials + exam bundles for CISSP Concentrations at the moment:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/Training/Online-Self-Paced/concentrations-bundle-promo" target="_blank" rel="noopener"&gt;https://www.isc2.org/Training/Online-Self-Paced/concentrations-bundle-promo&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively, you can use the suggested reference lists to find study material:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/issap-cbk-references" target="_blank" rel="noopener"&gt;https://www.isc2.org/issap-cbk-references&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.isc2.org/issep-cbk-references" target="_blank" rel="noopener"&gt;https://www.isc2.org/issep-cbk-references&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Both? What a novel idea!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caveat Emptor. The ISSEP reference list unfortunately misses the mark on the body of knowledge for systems security engineering, except for the reference to NIST SP 800-161, which you can think of as the new improved IATF. Even if you can find the ITAF document out there on the Internet, don't use it. Also, don't use the Official ISSEP CBK, the content in that book is longer valid.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 May 2020 18:09:34 GMT</pubDate>
    <dc:creator>AppDefects</dc:creator>
    <dc:date>2020-05-07T18:09:34Z</dc:date>
    <item>
      <title>ISSEP vs ISSAP</title>
      <link>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35384#M670</link>
      <description>&lt;P&gt;I have both the HCISPP and the CISSP. I am extremely pleased with the (ISC)2 in terms of their reputation, integrity, and contribution to the field. My certifications have opened many doors for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The training offered, the opportunities to gain knowledge, the free CPEs and variety of courses are outstanding. For these reasons mentioned, and for the purpose of deepening my knowledge, I want to pursue a CISSP concentration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am still trying to decide between the ISSEP and the ISSAP. There seem to be the same number of job opportunities and one isn't necessarily more "prestigious" than the other one. From my analysis, it seems that the ISSEP concentrates more on the federal government approaches and frameworks, and the ISSAP is more technical and geared towards private industry.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since my entire career has been in private industry with some consulting experience with defense contractors, I am leaning towards the ISSEP in order to round out my skills. I like the ISSAP in that it is technical and comprehensive, but it just seems to be the CISSP on steroids. I have plenty of technical experience and I think that the ISSAP is more likely to become obsolete due to the rapid changes in technology. I already have cloud certifications in AWS to prove my technical knowledge.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ISSEP seems to be more based on methodology which is less likely to experience rapid change and become obsolete. Methodologies endure for a longer time, especially when tied to the federal government. Additionally, I am attracted to the fact that the NSA helped develop the ISSEP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is my reasoning sound?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feedback is welcome. Wishing you all health and safety.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 19:25:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35384#M670</guid>
      <dc:creator>grayfox</dc:creator>
      <dc:date>2020-05-06T19:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISSEP vs ISSAP</title>
      <link>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35396#M671</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/565623015"&gt;@grayfox&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am still trying to decide between the ISSEP and the ISSAP. There seem to be the same number of job opportunities and one isn't necessarily more "prestigious" than the other one. From my analysis, it seems that the ISSEP concentrates more on the federal government approaches and frameworks, and the ISSAP is more technical and geared towards private industry.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;You are right, the NSA did originally sponsor the ISSEP, so it does have that pedigree going for it. The CBK though has shifted away from being US government centric to now being more applicable globally. The primary focus now is ensuring that qualified candidates are well versed in system security engineering principles, risk management, and technical program management. The domains may look a little different then that in the CBK, but those principles remain at its foundational core. If you choose the ISSEP you'll be one of the few, the proud, and an elite security professional that gets the job done. Combine that with your AWS certs and you'll go far. Maybe even land a position as a Chief Security Architect or a Director. Good luck!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 23:13:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35396#M671</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2020-05-06T23:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISSEP vs ISSAP</title>
      <link>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35398#M672</link>
      <description>&lt;P&gt;Thank you for your reply! Very helpful.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 23:31:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35398#M672</guid>
      <dc:creator>grayfox</dc:creator>
      <dc:date>2020-05-06T23:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISSEP vs ISSAP</title>
      <link>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35404#M673</link>
      <description>&lt;P&gt;Why do you have to decide between them? Why not do both like I did?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISC2 have a sale on online learning materials + exam bundles for CISSP Concentrations at the moment:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/Training/Online-Self-Paced/concentrations-bundle-promo" target="_blank" rel="noopener"&gt;https://www.isc2.org/Training/Online-Self-Paced/concentrations-bundle-promo&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively, you can use the suggested reference lists to find study material:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/issap-cbk-references" target="_blank" rel="noopener"&gt;https://www.isc2.org/issap-cbk-references&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.isc2.org/issep-cbk-references" target="_blank" rel="noopener"&gt;https://www.isc2.org/issep-cbk-references&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As to your comments about the ISSAP becoming obsolete, all ISC2 certifications are updated roughly every 3 years through a rigorous process known as the job task analysis (JTA), where certification holders get together and say what should be in the curriculum to reflect current practices based on what they do day in, day out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due to this, it is fair to say the ISSAP is more prone to greater changes in its curriculum than the ISSEP, but it won't ever be obsolete!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check out my reviews of the forthcoming ISSAP and ISSEP updates to get an idea of the scope of the changes for each:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Certifications/ISSAP-Exam-Changes-Announced/m-p/32793" target="_blank" rel="noopener"&gt;https://community.isc2.org/t5/Certifications/ISSAP-Exam-Changes-Announced/m-p/32793&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.isc2.org/t5/Certifications/ISSEP-Exam-Changes-Announced/m-p/34690" target="_blank" rel="noopener"&gt;https://community.isc2.org/t5/Certifications/ISSEP-Exam-Changes-Announced/m-p/34690&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW - both of those exam updates are set to take effect Q4 2020 so that's something for you to bear in mind depending on how long you think it will take you to study.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While the JTA keeps the exams up to date, you keep your own knowledge and skills up to date through continuous professional education (CPE) - when you hold a Concentration one sixth of your CISSP CPEs need to be related to the domains of your Concentration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Judging by what you have written it seems you've decided on the ISSEP already, which is a fine choice, but you shouldn't just write off the ISSAP as being a technical certification. While I think it is ISC2's most technical certification, it's actually a really nice blend between technical architecture and Enterprise Security Architecture concepts (i.e. alignment of IT/Security with Business goals/strategies).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Studying for either (or both) will be an excellent learning experience, so I wish you good luck with whatever you choose!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 10:38:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35404#M673</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2020-05-07T10:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISSEP vs ISSAP</title>
      <link>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35432#M674</link>
      <description>&lt;P&gt;Thank you for your reply. Great information and very helpful advice.&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 17:02:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35432#M674</guid>
      <dc:creator>grayfox</dc:creator>
      <dc:date>2020-05-07T17:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISSEP vs ISSAP</title>
      <link>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35437#M675</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1099977225"&gt;@AlecTrevelyan&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Why do you have to decide between them? Why not do both like I did?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISC2 have a sale on online learning materials + exam bundles for CISSP Concentrations at the moment:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/Training/Online-Self-Paced/concentrations-bundle-promo" target="_blank" rel="noopener"&gt;https://www.isc2.org/Training/Online-Self-Paced/concentrations-bundle-promo&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively, you can use the suggested reference lists to find study material:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/issap-cbk-references" target="_blank" rel="noopener"&gt;https://www.isc2.org/issap-cbk-references&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.isc2.org/issep-cbk-references" target="_blank" rel="noopener"&gt;https://www.isc2.org/issep-cbk-references&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Both? What a novel idea!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caveat Emptor. The ISSEP reference list unfortunately misses the mark on the body of knowledge for systems security engineering, except for the reference to NIST SP 800-161, which you can think of as the new improved IATF. Even if you can find the ITAF document out there on the Internet, don't use it. Also, don't use the Official ISSEP CBK, the content in that book is longer valid.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 18:09:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35437#M675</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2020-05-07T18:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISSEP vs ISSAP</title>
      <link>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35457#M676</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;&amp;nbsp;wrote:&lt;P class="1588929415331"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both? What a novel idea!&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;Advisable only for those of us who have the requisite breadth of skill, knowledge and experience, and who like to walk the walk and not just talk the talk&lt;/FONT&gt;&amp;nbsp;&lt;img id="smileytongue" class="emoticon emoticon-smileytongue" src="https://community.isc2.org/i/smilies/16x16_smiley-tongue.png" alt="Smiley Tongue" title="Smiley Tongue" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;&lt;SPAN&gt;Caveat Emptor. The ISSEP reference list unfortunately misses the mark on the body of knowledge for systems security engineering, except for the reference to NIST SP 800-161, which you can think of as the new improved IATF. Even if you can find the ITAF document out there on the Internet, don't use it. Also, don't use the Official ISSEP CBK, the content in that book is longer valid.&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;Yeah, I don't know why they added the IATF back in.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;Here's the list of study materials I used which was derived from this post:&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;&lt;A href="https://community.isc2.org/t5/Certifications/New-ISSEP-Official-Guide-and-or-training-for-the-March-14/td-p/8403#M2485" target="_blank" rel="noopener"&gt;https://community.isc2.org/t5/Certifications/New-ISSEP-Official-Guide-and-or-training-for-the-March-14/td-p/8403#M2485&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;I passed the the ISSEP exam in Dec 2018 which means it was the same version as the one available at the moment, so these are known to be good even if some of them have some parts that are now obsolete - it never hurts to understand what came before:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;NIST SP 800-30 Rev 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;NIST SP 800-100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;NIST 800-37 rev 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;NIST SP 800-160&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;NIST SP 800-64&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;FIPS 140-2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;NIST SP 800-115&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;NIAP/CCE Pub v4&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;NIST SP 800-88 Rev 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;NIST SP 800-53 Rev 4&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;Systems Engineering Fundamentals by United States Government US Army&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;SSE-CMM-1999&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;PMBOK Guide v5&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#3366FF"&gt;Official ISC2 Guide to the CISSP-ISSEP CBK&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2020 09:26:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/ISSEP-vs-ISSAP/m-p/35457#M676</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2020-05-08T09:26:22Z</dc:date>
    </item>
  </channel>
</rss>

