An editorial piece by Jaded Security on the operational gaps in the CISSP curriculum that the certification continues to ignore. Part two of an ongoing series.
The original piece on what the CISSP does not teach was framed as part one of an ongoing series. This is part two. As before, the certification is not being picked on because it is worthless; it is being picked on because it is treated as proof of operational competence and it is not. The exam has its place, but if the first move when something breaks at an organisation is to pull out the AIO study guide, the organisation is in trouble.
Threat modelling that does not survive contact
The CISSP teaches threat modelling as an exercise. STRIDE. DREAD. Attack trees. The acronyms get learned, a couple of textbook examples on a fictional banking application get worked through, and then the curriculum moves on. It is a lovely framework with its uses. The problem is that real threat models in real companies are political documents long before they are technical ones.
Here is what actually happens. A workshop convenes with the team that owns the system. Someone starts asking who the threat actors are and what they want. The product owner says “all of them”. The developer says “nation states” because it sounds impressive. The compliance person says “auditors”. The CISO has already mentally selected the threat model that justifies the project they want funded next quarter. By the time the workshop ends, the document everyone signed off on addresses none of the actual threats anyone would face.
What the CISSP does not teach is how to keep a threat-modelling exercise honest. The trick is to start with the assets, not the threats, and to force the room to rank them in front of each other. Once everyone has publicly agreed that the customer database matters more than the public marketing brochure site, the threat model writes itself, because the controls follow the rankings. If the ranking exercise gets political, that is the actual threat — and it has just been identified.
Risk acceptance as a cultural problem, not a process
The CISSP curriculum spends a lot of time on the risk-acceptance process. There is a form. Someone signs the form. The risk is now accepted. Done.
What actually happens in real organisations is this. The form goes around. Nobody who is busy reads it. The person who signs it is usually the person who is least exposed to the operational consequences. Six months later, the thing that everyone politely declined to address goes wrong, and the post-incident review concludes that the original risk acceptance was made without enough information.
The CISSP does not teach that the risk-acceptance process is theatre. It teaches that the risk-acceptance process is a control. The job of security leadership inside an organisation is to recognise when an acceptance is being signed by someone who is not actually accountable, and to escalate. That is a culture skill, not a process skill, and the certification has nothing to say about it.
Vendor management is a security function, not a procurement function
This is where the CISSP fails the modern practitioner the most. There is a domain called “Security Operations” but the level of attention paid to vendor and third-party risk is roughly proportional to how it was understood in 2003. The reality is that most organisations have more of their critical data sitting at vendors than they do on their own infrastructure. SaaS, IaaS, MSP managed databases, payroll providers, marketing automation.
The CISSP will tell candidates to put security clauses in the contract. Fine. Anyone who has ever pulled a vendor contract after a breach and tried to actually enforce a security clause knows it is a long, uphill, expensive fight, and the contract is the wrong place for the control. The right place is the architecture decision that picks the vendor in the first place, and the ongoing assurance work that confirms they are doing what they said they would do. None of which is in the curriculum.
Detection engineering does not exist in the curriculum
The CISSP has things to say about logging, monitoring, IDS, and SIEM. What it does not have is anything resembling modern detection engineering. The discipline of writing detections, testing them against real adversary behaviour, retiring the ones that produce nothing, and treating the detection corpus as production code is something the certification has not caught up to.
Candidates coming out of the CISSP thinking that “implement an IDS” is a control end up sitting in front of SIEMs that fire forty thousand low-confidence alerts a day, none of which anyone is investigating, and calling that “monitoring”. The CISSP does not tell them that ninety percent of those alerts should be deleted, that the remaining ten percent should be tuned, and that what is actually needed is a small number of high-confidence detections written against the specific environment.
The escalation question
The CISSP teaches the org chart. Who reports to whom, the right escalation path for an incident, and so on. Clean. Boxes and lines.
What the CISSP does not teach is that the most important escalation skill a security leader will ever develop is knowing when to go around the org chart, and how to do it without becoming the person who gets fired the next month for being political. There are situations in every organisation where the right call is to walk past your manager and into someone else’s office. Doing this wrong is career-ending. Doing it right is sometimes the only thing that saves the organisation from a real, public, expensive failure.
The certification cannot teach this. A mentor who has been through it twice and is willing to share what they learned can teach this. That mentor is worth more than the next three certifications anyone is tempted to chase.
Closing
This series will continue. The next instalment will probably be about audit fatigue, why most security audits produce reports that nobody reads, and what to actually do when an auditor flags something that is not the real risk. Not because audits are useless, but because the certification trains candidates to satisfy auditors rather than to lead a security program.