Showing results for 
Show  only  | Search instead for 
Did you mean: 
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Defender I

Questions from New Aspirant for Certification

I recently received in in-system private mail asking several questions about preparing for the CISSP exam. The questions themselves are likely to come to mind to many others, and there is no personal information in them. Thus, I am providing those questions and my answers here, to help others who may be concerned about the costs and steps to become certified.



1 - one of the pre-requisites that I read on ISC2 website is about proven past experience. So, when do I submit this proof? - before registering for exam or after?

DCS: You do not need to verify your cybersecurity experience until after you have passed the exam. Once (ISC)2 notifies you that you have passed (not the provisional passing score at the testing center), you must either have an existing g(ISC)2 member (fully certified) endorse you for certification, having reviewed and verified your experience history as you provide to his satisfaction, OR you must send your experience history statement ot the (ISC)2 office adn ask them to endorse you. DO the latter only if you do not have a member who knows you personally and can endorse you.


2 - As a proof - My manager is willing to give me letter with details - would that be suffice with my employment and salary letters?

DCS: you do not need to provide any salary information. However, a statement from your manager describing your information security experience, number of years performing the tasks, and organized according to the eight domains, can be used to either a local endorser or to the (ISC)2 staff.



3 - Can I appear for exam without the proof letter? or it is mandatory.

DCS: You can take the exam with absolutely on infosec experience. You should not do so; but you can. If you do pass the test with no experience, you have wasted your time and money, because you have only two years to get endorsed with 4 or 5 years of domain-specific infosec experience. Therefore, you should not take the exam until you have at least three years of experience.



4 - Finally, the cost of course - it’s about 7500 USD! - Do I really need that? or I can prepare on my own with official books and prepare for exam.

DCS: You are not required to take any preparation course. The only mandatory fee is for he exam itself. There are several ways to prepare, including online course, cooperative study groups. self-study, and the high cost intensive week-long classes. The 7500USD cost you refer is clearly for one of the official (ISC)2 or independent boot camp classes. You need not take that unless you really want to. Personally, I discourage such a class, unless you need it to focus your attention in one week. The reason for my recommendation is that such cram courses do not result in long term memory. Either multi-week cooperative study groups or even self study accordion to your own study plan will result in much better understanding and knowledge retention.


5 - if I avoid the course fee - I still need to arrange for 745 USD - for the CISSP exam. Is that correct understanding?

DCS: Yes, you will have to pay the fee for the exam, itself, and take the exam at a testing center.



Good luck, all!



D. Cragin Shelton, DSc
My Blog
My LinkeDin Profile
My Community Posts
12 Replies
Newcomer III

Hi Nkeaton,


I ran into the same thing with ISACA's CISM cert. I had enough leadership experience to take the exam, and then needed three MORE years in "Management" to complete the certification.


It's a fact that men are NINE times (nearly ten times) more likely to enter management than women (Frost & Sullivan, 2017), I ended up proving that statistic. Companies for which I worked after passing CISM were supposedly 'cool' with my having passed the CISM exam, but they all flat REFUSED to put me into even entry-level management. Be aware that at the time I had been a CISSP for 4 years (thus, nine years experience), had a Master's Degree in Cybersecurity\Info Assurance (as Valedictorian of my class), and had five years in leadership.  The 'companies' where I worked were clearly Gender-Biased, and held women back; it's called "Gender SEGREGATION," where females are relegated to entry-and-just-below-management roles for their entire careers.


So, I NEVER OBTAINED the needed years experience to fully complete my CISM.


ISACA is an accessory to Gender Discrimination by putting the requirements on CISM that they do. They are unwittingly contributing to the already overwhelming discrimination against females in cybersecurity and tech in general with their requirements. 


The more peer-reviewed papers I accumulate, the more proof there is of these facts.


thank you,


Dr. Jan Shuyler Buitron, DCS
Lead Cybersecurity/Systems Engineer
Doctorate of Computer Science in Cybersecurity
Master of Science in Cybersecurity, Valedictorian




Newcomer III

I am answering my own question; the previous paper-based exam had 250 questions. Now, how many points were required to pass??


I remember it as a test-taker had to get a total of 750 points to pass the paper-based exam. NOW, all of the sites say that the present adaptive tests require 700 points as a passing number. Is my memory correct? were the paper tests scored as passing at 750 points or more?


thank you,

Dr. Jan

Advocate II

Back in 2013, almost a decade ago, at the ISC2 conference at Warwick Uni, they asked for a show of hands and for anyone who was under 40 or female to put their hands down.  The majority of the room still had their hands up.  You'd have thought an aging occupation with a bias towards men would take on board the need to attract a wider demographic.