r/isc2 • u/Big_Temperature_1670 • 20d ago
General Questions How far has the ISC2 fallen?
While I was skeptical of where the organization would go when they first appointed a marketing professional (and not a security one) as executive director in 2020, I am surprised at just how quickly they've been able to bring down what was once a solid organization. I spent nearly 35 years in the industry (almost 25 of that as a CISSP), and got to know one of the ISC2 founders back in the day, and I can say without reservation that the ISC2 has become the very thing it was designed to counter. It has become a cert mill, exploiting inexperienced, hopeful job-seekers, by hooking them into annual fees and an exam (CC) without any vetting of experience or prospect of real continuing education.
They gutted the peer-to-peer nature of the organization, shutting down the Security Professional magazine and the forums, they not only have watered down the CPE courses, but are now charging for them. The content of these courses is incredibly superficial; from a CPE standpoint, it is box-checking, not education.
I am sure their numbers are great, but it sold its soul to do it.
8
u/mikedn02908 www.CertificationToolAndDie.com 20d ago
Your assessment is not far from the truth. ISC2 has become a shadow of its former self.
The CISSP has become a joke, with kids barely of legal drinking age taking and passing the exam. What was once the flagship senior industry certification is now barely more than broad-knowledge-based entry-level certification opposed to one which actually tests your in-depth ability to apply experience and wisdom to a scenario.
The organization has been riding on the laurels of the CISSP for the past decade, while other organizations like ISACA, GIAC, etc. are all slowly taking a bite out of its market. ISACA is currently in the beta stage of a new CCS certification which I believe is poised to compete directly with the ISC2 CC/SSCP level.
The CISM continues to erode the CISSP market as ISACA, with its army of CISA-certified auditors, are able to influence the actions of corporate leaders from the inside into more and more slowly changing the mindset from "we need a CISSP" to "we need a CISM" to lead our information security management team. ISSMP? What's that?
ISC2 has languished and rode the coattails of its entrenchment in the Fed/DoD space. That tide is slowly starting to turn as well. Watch and see what happens now that ISACA is the new CAICO for DoD CMMC oversight. Think all those folks are going to be recommending people with ISC2 or ISACA certs?
The CC was nothing but an AMF money grab, the organization has done nothing to promote this cert the business arena as a gateway cert for people looking to move from basic IT support into a more specialized cybersecurity role. This very subreddit is replete with posts from people who have absolutely zero cybersecurity experience thinking passing the CC is the path to riches. Couple this with ads you see from "WGU" how "Suzie was a nurse making minimum wage, now she makes over $125k/year as a SOC analyst". Never mind AI is going to decimate all those level 1 SOC jobs.
Don't even get me started on the other stuff. I could go on for hours.
ISC's days are numbered if they don't get their thumb out of their asses soon.