SSCP or CISM
So I'm looking towards opening my InfoSec career, but I'm struggling which exam to take as first. From the beginning my career was like:
1. Wintel admin (with securing the environment) - 3 years
2. Wintel Service Delivery Manager - 1,5 years
3. Wintel Technical PM - 0,5 year as a secondment
4. Quality & Compliance Consultant acting as Change & Risk Manager (working with WAST/OWASP tools). Supporting Network & Security Operations Teams - 1,5 years
5. Standards Manager - 1 year working with various standards (i.e. ISO 27001)
I have a strong process (ITIL) & improvement (Lean) background within a big Pharma company, and now I'll be leading three Customer Support teams which are far from security. But I know that in the new position it could be possible for me to switch to InfoSec, and I hope that official cert will help me with this.
Any advice is highly appreciated.
1. Wintel admin (with securing the environment) - 3 years
2. Wintel Service Delivery Manager - 1,5 years
3. Wintel Technical PM - 0,5 year as a secondment
4. Quality & Compliance Consultant acting as Change & Risk Manager (working with WAST/OWASP tools). Supporting Network & Security Operations Teams - 1,5 years
5. Standards Manager - 1 year working with various standards (i.e. ISO 27001)
I have a strong process (ITIL) & improvement (Lean) background within a big Pharma company, and now I'll be leading three Customer Support teams which are far from security. But I know that in the new position it could be possible for me to switch to InfoSec, and I hope that official cert will help me with this.
Any advice is highly appreciated.
Comments
http://www.techexams.net/forums/security-certifications/113328-what-information-security-certifications-should-i-get.html
SSCP & CISM are two totally different worlds. Entry-level vs. experienced. I recommend starting small (such as SSCP) to get your feet wet before moving on to the bigger boys (like CISSP or CISM).
As you probably saw I've moved out technical roles and was involved in policies and management stuff for the last 4 years. My question is related more on from which certificate should I start. I'm not interested in technical stuff, but I'm not 100% sure I will be able to fulfil all CISM requirements.
CISM has that odd requirement.
-b/eads
There is virtually no similarity between them and as a strategic path... Which mine was not.... It doesn't follow.
I liked SSCP and think that it's a much underrated certification, however the next leg up after it if you want to get into the upper levels of Infosec would be its bigger, badder bruv the CISSP.