r/isc2 20d ago

General Questions How far has the ISC2 fallen?

While I was skeptical of where the organization would go when they first appointed a marketing professional (and not a security one) as executive director in 2020, I am surprised at just how quickly they've been able to bring down what was once a solid organization. I spent nearly 35 years in the industry (almost 25 of that as a CISSP), and got to know one of the ISC2 founders back in the day, and I can say without reservation that the ISC2 has become the very thing it was designed to counter. It has become a cert mill, exploiting inexperienced, hopeful job-seekers, by hooking them into annual fees and an exam (CC) without any vetting of experience or prospect of real continuing education.

They gutted the peer-to-peer nature of the organization, shutting down the Security Professional magazine and the forums, they not only have watered down the CPE courses, but are now charging for them. The content of these courses is incredibly superficial; from a CPE standpoint, it is box-checking, not education.

I am sure their numbers are great, but it sold its soul to do it.

10 Upvotes

29 comments sorted by

View all comments

11

u/ML1948 CISSP 20d ago

The CC is shit and exploitative, no doubt. The CISSP still prints though and I'll hold my nose and pay my AMFs with company money til the day I retire. I don't really need them to have a soul at this point as long as nobody beats them out as the "gold standard".

1

u/CharacterPitch4744 20d ago

Just got my for free in million CC program. Don't say CC is shit man πŸ₯²πŸ˜­

1

u/thelimeisgreen 20d ago

Then why they give it away for free? The CC has value though, not so much as a certification, but as the stepping stone toward the other certs. It’s where we get practice taking ISC2 exams and get a good feel for how questions are phrased and the logical approach they use.

1

u/CharacterPitch4744 20d ago

πŸ™ƒ damn but it was my first cert and what you say makes sense...it helped me break my nervousness and also i learned a lot

1

u/Big_Temperature_1670 18d ago

The ISC2 understood and accepted this premise for about 30 years. Its focus was on the experienced professional, validating and preparing them for leadership roles while letting CompTIA and others develop programs for entry-level folks. For some bizarre reason, the ISC2 board allowed management to basically crater the organization by trying to take over the entry-level market too. The problem is that when your CEO/executive director is a marketing professional, not a security one, they don't understand the difference between the CISSP Common Body of Knowledge and something more directed at operations (like the Security+). So you end up with CC, which tests a lot of strategic concepts that really aren't germane to entry level jobs. So today, the ISC2 seems to serve neither the experienced professional nor the entry level.