<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISSP Dilution in Member Support</title>
    <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/7434#M1292</link>
    <description>&lt;P&gt;I just passed it Wednesday and it was pretty tough...&amp;nbsp; &amp;nbsp;I wouldn't want to do it again.&amp;nbsp; I memorized the Conrad book and could probably write it from scratch.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Feb 2018 14:05:12 GMT</pubDate>
    <dc:creator>Brady</dc:creator>
    <dc:date>2018-02-16T14:05:12Z</dc:date>
    <item>
      <title>CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5116#M625</link>
      <description>&lt;P&gt;n/a&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 17:13:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5116#M625</guid>
      <dc:creator>SunnyDee</dc:creator>
      <dc:date>2025-05-30T17:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5123#M627</link>
      <description>Hi Sunny!&lt;BR /&gt;&lt;BR /&gt;The change in format to the CISSP exam (from linear to CAT) has had no impact on the pass rate. We are excited to see so many people posting here and elsewhere about passing the exam, but this is because we are seeing unprecedented demand for the CISSP exam, which means a larger number of people are succeeding. &lt;BR /&gt;&lt;BR /&gt;Also, since there’s been a change to the exam format, I think more people are interested in sharing their experiences than might have in the past.</description>
      <pubDate>Tue, 09 Jan 2018 21:12:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5123#M627</guid>
      <dc:creator>Kaity</dc:creator>
      <dc:date>2018-01-09T21:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5132#M628</link>
      <description>&lt;P&gt;More data needed I think, but I'd strongly expect that ISC2 put a lot of thought into this and are tracking very closely.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, if you did chose to believe impressions of social media over ISC2s statement, there's always the option of taking solace harumphing about how it was much better in your/our/my day:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=ue7wM0QC5LE" target="_self"&gt;https://www.youtube.com/watch?v=ue7wM0QC5LE&lt;/A&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"And when we got home, our Dad would kill us and dance about on our graves..!"&amp;nbsp;&lt;/P&gt;&lt;P&gt;"But you try telling young people that, they won't believe you..." &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 03:38:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5132#M628</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2018-01-10T03:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5155#M629</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/823548003"&gt;@SunnyDee&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;What used to be, 3 months of hard work studying the entire CBK from head to toe along with thorough, comprehensive practice testing to attain this elite certification, others have been spending just a few weeks to pass the CISSP exam.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;While I share concern about dilution, I think if the CISSP exam measures what it is supposed to, it should not be a labor to pass the exam. It's supposed to measure a broad range of knowledge acquired over several years. Yes, due to the breadth of the CBK, it is doubtful anyone has complete depth in all areas; some study is necessary, but it's not like cramming for a history final.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My concern is the nature of the CAT. We live in an age of constant distraction, and any substantive statement is met with a "TL;DR" response.&amp;nbsp;To me this is the real security threat. I can't think of a single vulnerability or exploit that at some point can't be traced to human error. While I appreciate that sitting for potentially six hours and 250 questions is a chore, have you ever had to read over a month's worth of logs to find the single IP that touched off an incident? Security often is maintaining focus in the face of mind-numbing data. It is about finding the path of quality, not the shortest distance.&amp;nbsp;Part of what needs to be tested is the mental endurance. Even the act of being able to review past questions (double check your work!) is a capability you want to see among security professionals. I find the very nature of CAT contradictory to the skill set necessary to be an adept security professional.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 19:17:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5155#M629</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2018-01-10T19:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5165#M632</link>
      <description>&lt;P&gt;I have the same fear about the cert losing value and prestige.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 03:10:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5165#M632</guid>
      <dc:creator>Dr_Strange</dc:creator>
      <dc:date>2018-01-11T03:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5167#M634</link>
      <description>&lt;P&gt;To that point of dilution of excellence of the CISSP,&amp;nbsp;I think it's important to trust in ICS2's application of high standards of confirmation. We can ask for data on this and perhaps a group could be established.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To the question of the new exam format's difficulty vs the old exam's difficulty - I think that while it may seem 'easier' to have the shorter duration it's not necessarily&amp;nbsp;the case. I've seen cases in training and education where changed standards make things easier and allowing the selective rework of confirmation is one of those.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've sat it twice(lapsed due to not bothering with CPEs) &amp;nbsp;and the old format was actually providing me cribs for the few questions I didn't know confident with - I didn't even need to do a final review just updated on the fly. The CISSP exam did seem to be a good test of my knowledge and application of it, but it also tested my comprehension, English and to some extent my stamina - if we look at the critical few things we want it to confirm, well I'd like it to look at my security knowledge and critical thinking rather than my prowess as a native English speaker and my ability to sit still.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be sure, we could put a cohort of existing CISSPs through the new exam. I'm up for it, I didn't have any real problem with either exam I wrote(paper and CBT), but I'd figure CAT would be a little harder or more accurate test, I do wonder would I have to retake if I failed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that if you spent time, money and effort in professional&amp;nbsp;differentiation it's natural to defend it. But I think that some commoditization of the CISSP is inevitable as Cyber Security professionalizes and ranks grow. There will just be more candidates with the requisite knowledge and expereince. Concentrations help somewhat to further differentiate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I fully expect to be eclipsed by those coming into the industry, and I'd rather a dynamic exam that keeps up with the state of the art - I'd rather have more minds of sufficient calibre and trust the adaptive mechanisms in place to ensure the quality level is met. I've&amp;nbsp;seen 'prestige ghettos' where there are attempts to select out, and they don't end well. &amp;nbsp;Ultimately I'd say the best safeguard anyone could make is to volunteer&amp;nbsp;for exam writing workshops.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 06:57:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5167#M634</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2018-01-11T06:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5475#M721</link>
      <description>&lt;P&gt;I agree with KaityEagle here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On ISC2 website there are multiple links to the Certification Magazine website where they post the average salary of the top 75 certifications in IT. The ISC2 family of certs have been listed and the CISSP and it's concentrations have been top 20 each time. This list gives an easy view of what certificate to earn to make the most money, so of course it will create more demand for the more popular certs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 18:01:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5475#M721</guid>
      <dc:creator>LArchinal</dc:creator>
      <dc:date>2018-01-23T18:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5635#M750</link>
      <description>&lt;P&gt;Hum.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is an interesting comment, however only ISC2 can answer the question with accuracy.&amp;nbsp; They can tell us what is the current pass rate since 18th of December compared to what they were the previous months.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CAT testing has been used by other certification bodies very successfully for technical topics that were nowhere as wide as the 8 domains of the CISSP CBK.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 8 domains contain multiple hundreds of topics.&amp;nbsp; &amp;nbsp;Multiple test&amp;nbsp;takers have reported having received only 100 questions before getting a pass rate,&amp;nbsp; &amp;nbsp;So let's take a worst case scenario and pretend the student got the maximum of 150 questions and then received a passing grade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This means that about 1 out of 4 topics or even less are being evaluated.&amp;nbsp; That does not sound right to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am still having a hard to time to believe that answering 100 to 150 questions prove to anyone that you are dealing with what is called an Information Systems Security professional.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems to me we have regressed and some value is lost in the process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Was the decision motivated by cost cutting&amp;nbsp;or a true will to better the evaluation process and validate true skills?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my two cents&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Clement&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2018 20:00:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5635#M750</guid>
      <dc:creator>clementdupuis</dc:creator>
      <dc:date>2018-01-28T20:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5736#M757</link>
      <description>&lt;P&gt;It will be hard to make any guess or estimate or conclusion about dilution of a cert based on anecdotal postings in multiple social network sites and forums. I would hope and a posting by ISC2 seems to confirm that metrics are collected about % passing of all exam takers. This should be the number to monitor. As nice as it is to hear on FB, LinkedIn etc that many people pass and maybe even find the format easy, these are anecdotal postings that do not allow a conclusion about the actual % of people passing the exam.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 01:55:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5736#M757</guid>
      <dc:creator>kratzy11</dc:creator>
      <dc:date>2018-01-30T01:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5738#M758</link>
      <description>&lt;P&gt;I understand that but it's all over and it's not easy to miss that everyone's passing left and right since the CAT format change. This isn't a rumor anymore, it's been a month and the entire cyber security community is talking about this becoming easier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even the CISSP boot camps are being offered at a discounted rate because they're also realizing that no one needs boot camps anymore. All you need is a week or two to study for this and it's an easy pass.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISC2, please take note of the pass rate. This isn't fair to people who put in the hard work and trained for the endurance this exam was supposed to challenge the test taker. There are so many cases of people passing in under an hour and under 100 questions.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I sincerely hope this cert isn't diluting and ISC2 needs to make this new format just as challenging and enduring to the many people like myself who worked hard for this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 02:09:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5738#M758</guid>
      <dc:creator>SunnyDee</dc:creator>
      <dc:date>2018-01-30T02:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5869#M786</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1669067561"&gt;@clementdupuis&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for joining the conversation and sorry for the delay! As stated earlier in this thread, the change in format to the CISSP exam (from linear to CAT) has had no impact on the pass rate. However, it is (ISC)² policy to not publicly disclose exact pass rates. &lt;BR /&gt; &lt;BR /&gt;(ISC)²’s transition of CISSP to CAT is an important investment in the future of its certification program. The implementation of CAT strengthens our commitment to meet the critical demand for cybersecurity professionals worldwide by providing a fair, valid, reliable, and efficient exam administration process. The CAT exam follows the same exam blueprint and contains the same percentage of items in each Domain on the test as in the linear exam.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because the exam items are targeted to the ability of a test taker in each Domain, the information obtained from those items are much more precise and are used while making the pass/fail decision. CAT provides numerous benefits to candidates including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A more precise and efficient evaluation of a candidate’s competency&lt;/LI&gt;
&lt;LI&gt;More opportunities for examination administration&lt;/LI&gt;
&lt;LI&gt;Shorter test administration sessions&lt;/LI&gt;
&lt;LI&gt;Enhanced exam security.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As for your questions related to the CAT format, I’ve checked with our Exam team for more information. While it may seem counter-intuitive, it is very common for CAT exams to be shortened by as much as 50% (from a fixed, linear exam) while providing an even greater level of precision in measure a candidate’s competency. CAT has been around for decades, and science and data support it as a more precise and reliable exam format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 21:22:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5869#M786</guid>
      <dc:creator>Kaity</dc:creator>
      <dc:date>2018-01-31T21:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5882#M787</link>
      <description>&lt;P&gt;Ms. Eagle,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my two cents on the matter:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;message has gotten out about the new CAT format through various social media sites, word of mouth, and other unofficial means.&amp;nbsp; Unfortunately, the most common message I've seen is that the exam is much shorter and easier -&amp;nbsp;so now is the time to challenge the exam before (ISC)^2 catches on and reverses course.&amp;nbsp; I cannot personally attest to the difficulty level as I earned the CISSP on the old format but it's important to acknowledge that, many times, perception is reality.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very generally speaking, people do not do their own research to build an educated opinion on most matters.&amp;nbsp;&amp;nbsp;Whichever 30-second, talking-head, sound byte is last heard is what is accepted as truth and&amp;nbsp;major media outlets&amp;nbsp;have mastered the ability to sway public opinion in this fashion.&amp;nbsp; I fear that employers will hear about the supposed&amp;nbsp;easing&amp;nbsp;of the CISSP and configure their HR filters to look for other "less attainable"&amp;nbsp;sets of letters&amp;nbsp;to in order to separate the wheat from the chaff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I am by no means implicating that a certification makes the professional but&amp;nbsp;it is a major factor in&amp;nbsp;what gets us past the hiring algorithms and a foot in the door for an interview.&amp;nbsp; I would strongly advocate that (ISC)^2 change its policy and publish their pass/fail rates.&amp;nbsp; In my opinion, this is the only way to prove to employers that the CISSP is truly the gold standard that it has been thought of for so long.&amp;nbsp; This is what credible higher learning organizations do.&amp;nbsp; For instance, you can find the acceptance and graduation rates of any quality university because it is important to distinguish their graduates from those that may have simply completed a curriculum from a degree-mill somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another thing that may help your cause would be to cite some of the research that supports your statement, "science and data support it as a more precise and reliable exam format."&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for all you do!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 04:45:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5882#M787</guid>
      <dc:creator>DAlexander</dc:creator>
      <dc:date>2018-02-01T04:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5910#M794</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/912952905"&gt;@DAlexander&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I would strongly advocate that (ISC)^2 change its policy and publish their pass/fail rates.&amp;nbsp; In my opinion, this is the only way to prove to employers that the CISSP is truly the gold standard that it has been thought of for so long.&amp;nbsp; This is what credible higher learning organizations do.&amp;nbsp; For instance, you can find the acceptance and graduation rates of any quality university because it is important to distinguish their graduates from those that may have simply completed a curriculum from a degree-mill somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;But pass/fail and acceptance rates can be misleading.&amp;nbsp;For example, the first generation or two of CISSPs probably had a high pass rate because the only people who&amp;nbsp;knew about the CISSP were people established in the industry. Today, I suspect the rate may appear low because you have a lot of folks simply trying to chase a credential and salary. Just to wax curmudgeonly here - we have raised a generation (going on two now) of kids whose education has been geared toward standardized testing. They are probably disappointed - outright aghast - to find questions on the CISSP that weren't specifically outlined or asked in their study guides etc. The CISSP exam is supposed to measure an ability to apply a comprehensive body of knowledge AND experience, which means there should be questions and&amp;nbsp;even topics not always seen in a prep guide etc. It should test that age-old ability to "know it out" and not just regurgitate content.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's on that note that&amp;nbsp;I share your concern about how the CAT impacts the CISSP because I see the CAT as bowing to an idol of regurgitation rather than mental acuity and stamina. Efficiency and security often travel in opposite directions.&amp;nbsp;Do we really want to suggest that if you can "prove" knowledge in 10 questions - rather than 15 - those other 5 aren't necessary?&amp;nbsp;Shortcuts are the anathema to security.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;From what I have read, a CAT format does not work in every environment. The CISSP is a comprehensive credential. For example, I believe&amp;nbsp;the DCO (detailed content outline) for the CISSP (can't find a link to it any more) has at least 250 topics. If we are trying to ascertain whether someone has a mastery of the CISSP CBK, you'd think&amp;nbsp;a standard exam would need a commensurate number of questions at least.&amp;nbsp;However, with the CAT being 150 questions and people being able to pass by answering as few as 100, those figures seem incongruous with the CBK. There seems to be a left and right hand issue here (and maybe a foot thrown in there too).&amp;nbsp;This stuff over here, doesn't fit with what is being done over there. To put this in true tech speak: The (ISC)2's DCO of the CBK for the CISSP doesn't fit with a CAT, OK? IMHO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All that said, the exam really is an entrance, not an achievement, test. It is one of several criteria that gets you into a cohort of CISSPs, who then, ideally, continue and progress in their education. Like you, I worry though that the CISSP brand is not carrying the weight it should. Years, ago I would explain a CISSP as "We're the ones TJX should have listened to." Then I substituted Target, later the DNC, then Equifax, and tomorrow it will be someone else.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 15:10:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5910#M794</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2018-02-01T15:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5917#M797</link>
      <description>Maybe it's just because more people can set aside the time for a shorter test.&lt;BR /&gt;&lt;BR /&gt;What was essentially a full day requirement becoming a half day; that almost certainly cuts across an availability threshold of some kind.</description>
      <pubDate>Thu, 01 Feb 2018 15:55:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5917#M797</guid>
      <dc:creator>M_Thomas</dc:creator>
      <dc:date>2018-02-01T15:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5936#M810</link>
      <description>&lt;P&gt;I was thinking the same thing (dilution) when I first saw the format change.&amp;nbsp; I hadn't heard about the increased pass-rates until reading your post.&amp;nbsp; I certainly share your concern, though.&amp;nbsp; In addition to my 20+ years of industry experience, I, too, studied daily for over 3 months.&amp;nbsp; Online bootcamps, study guides, practice exams, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm no fan of 6-hour exams, but I busted hump to pass mine.&amp;nbsp; I can understand and appreciate the adaptive exam approach, but the first iteration should have pared down from 250 questions to 200-250, IMHO.&amp;nbsp; With the breadth of scope of the CISSP certification, and demonstration of knowledge and understanding that the former exam format afforded, I question how anyone could demonstrate such in as few as 100 questions!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 19:27:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5936#M810</guid>
      <dc:creator>pkrainman</dc:creator>
      <dc:date>2018-02-01T19:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5938#M811</link>
      <description>While I fear that the industry might get saturated with CISSP's, we also need to realize that studies are showing we are going to have a shortage of InfoSec professionals by 2020. While we think there are too many CISSP's, we honestly don't have enough to support the upcoming work load needed within the industry. If ISC2 is stating the pass rate is the same, then I'm good with that. If I have any bias or discourse, is that folks will miss the wonderful opportunity of sweating through a 6 hour exam on paper and pencil. Times change, so we can adjust to it or move on.</description>
      <pubDate>Thu, 01 Feb 2018 19:33:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/5938#M811</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2018-02-01T19:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/7245#M1232</link>
      <description>&lt;P&gt;I took it just last week.&amp;nbsp; Did not pass...I studied for over a couple of months and really hard last two weeks.&amp;nbsp; I found the questions OK but the answers were not on par to what I had studied.&amp;nbsp; I found the test was hard due to that fact alone.&amp;nbsp; Following is what I have a beef about in addition to POORLY worded questions on a few.&amp;nbsp; The punctuation was terrible on some of these questions (are these not screened and reviewed?)&amp;nbsp;&lt;/P&gt;&lt;P&gt;The questions answers should not be&amp;nbsp; a "KEY WORD" test but more of what is your knowledge test and not make a person have to reread a question to lock into a particular word sandwiched between non important phrasing.&amp;nbsp; That's not testing my knowledge thats testing if I can take a test well.&amp;nbsp; My main concern is that the test is not easier but been made harder with the answers alone.&amp;nbsp; Make sense?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Feb 2018 17:26:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/7245#M1232</guid>
      <dc:creator>HardCorps88</dc:creator>
      <dc:date>2018-02-10T17:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/7251#M1237</link>
      <description>&lt;P&gt;Firstly&amp;nbsp;commiserations, you should probably get back up on the horse as soon as you feel ready, and you'll have a good story to tell&amp;nbsp;after you do pass.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think that your concerns are much from folks before the switch over to computer-assisted&amp;nbsp;testing. Were you able to flag the questions you felt bad grammar&amp;nbsp;to ISC2 in the exam?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My personal opinion&amp;nbsp;having sat CISSP twice and passed it twice (paper and non-CAT CBT), and the exam questions are designed for close parsing, comprehension application of knowledge more than they were for the recall of facts. Native English speaker? Big advantage. Read a lot(fewer people do these days)? Big advantage. Deal with wooly concepts, questions and security negotiations? Big advantage. Generational&amp;nbsp;linguistic drift may also play a part here. CISSP exam writers&amp;nbsp;are&amp;nbsp;probably, in the main, crusty old kippers like myself so we might need help with the hip new security argot. We can handle emojis but may use old forms. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This actually&amp;nbsp;tests your ability as a security leader to quickly understand what's being said or asked for, apply your knowledge and not be complaining that you found it hard to understand what's being asked&amp;nbsp;when it comes back onto your plate a week later and you need to solve it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quite often&amp;nbsp;knowledge is imperfect, and you need to choose the least bad option. You might even find yourself needing to win another battle to get action on the critical task because that forces an&amp;nbsp;action.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would be good to have others opinions, but often those one-word signifiers make all the difference, and effective security as you climb the ladder involves all sorts of trade-offs, negotiations and political hurdles. Because of this, it doesn't confirm so much to the black and white you might find if you sat say CompTIA's Security+.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming that ISC2 didn't radically change the questions banks, and all else being equal then I would say that the move to CBT made it a little harder for those with a lot of mental physical stamina who could have gleaned more info from later questions and being able to go back to previous questions based on this and easier for those that were to get more answers correct initially and might get tired during the exam.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bottom line ISC2 should probably get more data and report back as to whether the rates&amp;nbsp;different, I trust these guys because I voted for them and if you can mark what's interesting on your next sitting ask them directly for comment, they've always taken feedback on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Feb 2018 05:38:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/7251#M1237</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2018-02-11T05:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/7352#M1259</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1155017497"&gt;@HardCorps88&lt;/a&gt;!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding any issues with the exam, please reach out to Member Services using the &lt;A href="https://www.isc2.org/Contact-Us#accordion-5d0a09572cfe44d5b0251d0fdfdac3a1" target="_blank"&gt;Contact Us form&lt;/A&gt; on our site. Public discussions of specific exam content is not allowed, due to the NDA &amp;amp; (ISC)² Code of Ethics. But, we certainly want to review any issues you may have experienced, so please share them using that form so that we can properly document and handle. Thank you! &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 14:00:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/7352#M1259</guid>
      <dc:creator>Kaity</dc:creator>
      <dc:date>2018-02-14T14:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Dilution</title>
      <link>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/7355#M1262</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1155017497"&gt;@HardCorps88&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;The punctuation was terrible on some of these questions (are these not screened and reviewed?)&amp;nbsp;&lt;/P&gt;&lt;P&gt;The questions answers should not be&amp;nbsp; a "KEY WORD" test but more of what is your knowledge test and not make a person have to reread a question to lock into a particular word sandwiched between non important phrasing.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;First consider that some of the questions on the CAT (as well as the traditional test) may in fact be "test" questions. They may not be part of what you or anyone else was scored on. They are simply there to gauge appropriateness/difficulty as an exam question.&lt;BR /&gt;&lt;BR /&gt;Second, part of this may be a sign of the times. I grew up in an era where standardized tests were few and far between. Today everything is a multiple choice test. Testing alone is huge business, but as this very thread postulates, with expansion comes dilution. Here in the U.S. at least, we have shifted to being a multiple choice society (that is in all regards except for politics where 95 percent of us insist on a binary approach, but&amp;nbsp;I digress &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; ). I think another issue that to write good information security questions takes both an understanding of the subject matter and communications skills. Let's face it, there's not a lot overlap of those skill sets in our industry. How many times have you seen a meeting wasted because Fred and Wilma start correcting each other over whether the term is X or Y? We not only tend to miss the forest for the trees, we miss the trees over debating whether the bug on the bark is an "information security beetle" or a "cybersecurity beetle."&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 14:54:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/CISSP-Dilution/m-p/7355#M1262</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2018-02-14T14:54:02Z</dc:date>
    </item>
  </channel>
</rss>

