An editorial piece by Jaded Security on ISC2’s member-directory privacy practices and the apparent disconnect from the security principles the organisation certifies its members against.
The criticism levelled at ISC2 in earlier coverage on this site continues to apply, with a new issue worth flagging: the member directory.
ISC2 has made CISSP-holder information searchable online. Name, certification status, and other details are available for anyone to look up. The problem: there is no clear way to opt out of having that information publicly listed.
For an organisation that is supposed to represent information-security professionals, this is embarrassing. Security professionals spend their careers telling organisations to minimise data exposure, implement privacy controls, and give users control over their personal information. Yet the organisation that certifies them cannot follow its own principles.
Privacy is not just a technical issue. It is a fundamental right. Security professionals, of all people, should not have their information exposed without explicit consent and without a clear mechanism to withdraw that consent.
ISC2: add an opt-out button. It should not be this hard.