Good day,
Please what version of the RMF is currently used for the CAP exam? Is it the old version 1 or the new version 2? I have searched everywhere for information if the test has been switched/updated to RMF ver 2. Or better still any date that indicates a hard cutoff for the ver 1.
Where can I find this information? Anyone with information or pointers please kindly share.
Regards
Bee.
Here's a couple of posts on the subject by @ToniHahn who works in the exams team for ISC2:
https://community.isc2.org/t5/Certifications/CAP-Certification-Exam/m-p/18239#M3622
https://community.isc2.org/t5/Certifications/CAP-Certification-Exam/m-p/19536#M3826
The Certification Exam Outline has a date of 15 October 2018 which is prior to the latest release of NIST 800-37. However, the references for the exam indicate NIST 800-37 rev 2 (Dec 2018) as guidance. I understand that this is an old question but the steps and tasks within steps are vastly different between revs 1 and 2. It's my guess that the exam is still based on the former revision, but could you clarify?
@Mayesbk wrote:The Certification Exam Outline has a date of 15 October 2018 which is prior to the latest release of NIST 800-37. However, the references for the exam indicate NIST 800-37 rev 2 (Dec 2018) as guidance. I understand that this is an old question but the steps and tasks within steps are vastly different between revs 1 and 2. It's my guess that the exam is still based on the former revision, but could you clarify?
Often when a new version of a standard is released it will be used in all phases of exam development, which includes reviewing and updating existing questions for relevancy and accuracy.
Thank you so much for the response. I also noticed that the reference for the exam listed NIST 800-37 Rev 2 and not Rev 1. The RMF steps for both are totally different. I am yet to see a post stating that the current exams are entirely based on Rev1 or Rev 2.
I work in Exams and I want to state that this reply "Often when a new version of a standard is released it will be used in all phases of exam development, which includes reviewing and updating existing questions for relevancy and accuracy." is correct!
While we will not disrupt an active test, the next update will be updated.
I work in Exams and want to say that the references listed are just an item put out there to help candidates. This is not the total list. It only the top 5 references used in each domain. We try to keep the list with the most current version out there as on a next update of the exam, we will have made sure all items have the most current version. This is to maintain our exams with any changes that may be out there.
I took the exam on Friday 21 June (passed) and the exam was based on NIST SP 800-37 Rev 1. Good luck.
Congratulation @Mayesbk!
Also, thanks for the feedback on the RMF version - we get a lot of questions on that here!