<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSCP or CGRC after CC?????? in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75861#M1246</link>
    <description>&lt;P&gt;I believe that this would depend on your experience.&amp;nbsp; The SSCP is the next natural step after the CC and only requires a year of experience in at least one of the domains.&amp;nbsp; The CGRC requires 2 years in at least one of the domains.&amp;nbsp; I found the CGRC (CAP when I took it) tougher because it is non-technical.&amp;nbsp; It was my first ISC2 certification; it was the first automated ISC2 exam when I took it.&amp;nbsp; Fortunately the NIST documents are no cost to study.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Dec 2024 18:35:59 GMT</pubDate>
    <dc:creator>nkeaton</dc:creator>
    <dc:date>2024-12-27T18:35:59Z</dc:date>
    <item>
      <title>SSCP or CGRC after CC??????</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75848#M1245</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want a Career Path in Compliance or as an IT Auditor&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 04:46:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75848#M1245</guid>
      <dc:creator>MoBolajiAkanni</dc:creator>
      <dc:date>2024-12-27T04:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSCP or CGRC after CC??????</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75861#M1246</link>
      <description>&lt;P&gt;I believe that this would depend on your experience.&amp;nbsp; The SSCP is the next natural step after the CC and only requires a year of experience in at least one of the domains.&amp;nbsp; The CGRC requires 2 years in at least one of the domains.&amp;nbsp; I found the CGRC (CAP when I took it) tougher because it is non-technical.&amp;nbsp; It was my first ISC2 certification; it was the first automated ISC2 exam when I took it.&amp;nbsp; Fortunately the NIST documents are no cost to study.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 18:35:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75861#M1246</guid>
      <dc:creator>nkeaton</dc:creator>
      <dc:date>2024-12-27T18:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSCP or CGRC after CC??????</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75872#M1247</link>
      <description>&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/253792811"&gt;@nkeaton&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you for the heads up.&lt;BR /&gt;&lt;BR /&gt;The years of experience involved will restrict .... I think I would go for SSCP.&lt;BR /&gt;&lt;BR /&gt;Thank you once again.&lt;BR /&gt;&lt;BR /&gt;Sent from Outlook for Android&amp;lt;&amp;gt;</description>
      <pubDate>Sat, 28 Dec 2024 14:04:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75872#M1247</guid>
      <dc:creator>MoBolajiAkanni</dc:creator>
      <dc:date>2024-12-28T14:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSCP or CGRC after CC??????</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75895#M1248</link>
      <description>&lt;P&gt;Best thing is CGRC if you as an auditor are required to follow NIST standards.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As an auditor/assessor under NIST SP 800-37, you need to fully understand the RMF workflow if you are to assess organizations since the whole idea of RMF is obtaining an ATO which is what federal organizations are seeking. You can't get that ATO without fully understanding how RMF works.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 01:14:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75895#M1248</guid>
      <dc:creator>Until_then</dc:creator>
      <dc:date>2024-12-30T01:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSCP or CGRC after CC??????</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75902#M1249</link>
      <description>&lt;P&gt;They have added some frameworks but agree is still more NIST based on RMF.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 14:03:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SSCP-or-CGRC-after-CC/m-p/75902#M1249</guid>
      <dc:creator>nkeaton</dc:creator>
      <dc:date>2024-12-30T14:03:45Z</dc:date>
    </item>
  </channel>
</rss>

