An editorial piece by Jaded Security on what the CISSP curriculum leaves out and what defenders need that the certification does not provide. Part one of an ongoing series.
This is part one of what will probably be an ongoing series. A book could be written about what the CISSP does not teach; the fundamentals are a good place to start.
Thinking like an attacker
The CISSP curriculum treats security as a defensive discipline. Build walls. Write policies. Implement controls. Check boxes.
Attackers do not think about controls. They think about gaps. They look at an organisation from the outside and ask: where is the weakest point? What has been forgotten? What is assumed to be safe but is not?
The CISSP will teach defence in depth. It will not teach how to identify the one layer that everyone forgot to test.
The gap between policy and reality
Every organisation has a password policy. “Minimum 8 characters, complexity requirements, rotate every 90 days.” The CISSP would give full marks for implementing this.
In reality, users write their passwords on sticky notes. They increment the number at the end every 90 days. They use the same root password across personal and corporate accounts. The policy is technically implemented and practically useless.
The CISSP teaches how to write the policy. It does not teach how to verify that the policy is actually achieving its intended outcome.
Real incident response
The CISSP has an entire domain dedicated to incident response. It covers the phases: preparation, identification, containment, eradication, recovery, lessons learned. Nice and clean. Six steps.
Real incident response is chaos. The CEO is calling every fifteen minutes. Legal wants to know if disclosure is required. The affected system is also the one running payroll, and payday is tomorrow. The junior analyst who discovered the alert is panicking. And the incident-response plan that took three months to write does not cover this specific scenario.
The CISSP teaches the framework. Experience teaches what to do when the framework does not apply.