Before I embark on the CISSP, I was wondering if getting the CGRC would make sense or is even recommended. I mainly work in the GRC area (doing policy work), and would like to get a more solid understanding of the different frameworks etc. I am thinking that getting a CGRC certification could help me here.
Does it make sense to attempt this certification without the knowledge & experience required for a CISSP?
Thanks for any guidance you may have.
@dips0502 Thanks for the info.
Kind of disappointing. If ISC2 is pushing this as a "GRC" cert vs a "CAP" cert, then they need to add MORE stuff from other frameworks such as COBIT, CIS Controls, 27001, NIST CSF, etc and NOT be so heavy on RMF.
They did add some frameworks, but for now the emphasis seems to be most on RMF. Perhaps that will change the next time that they update the exam. I do agree that the name change might be more about name recognition. I still think is a good exam but definitely not technical. The CISM or ISSEP would dive deeper in GRC and frameworks.