amicmanzo wrote: » Afternoon, As I'm searching and reading through the ISACA website regarding the experience requirements, I feel a little baffled about my experience within the military to see if it suffices to get certified. Would anyone be able to share their insight? I have three years of Incident Response and three years of penetration testing. Of course both entail information security, network security, and so on, but would how would I be able to submit my eligibility?
jcundiff wrote: » hate to be a downer, but Incident Response and Pen testing does not equal InfoSec management experience. How many resources did you manage in the service? From ISACA web site: "Submit verified evidence of a minimum of five years of information security work experience, with a minimum of three years of information security management work experience in three or more of the job practice analysis areas. The work experience must be gained within the 10-year period preceding the application date for certification or within 5 years from the date of originally passing the exam.Experience Substitutions The following security-related certifications and information systems management experience can be used to satisfy the indicated amount of information security work experience.Two Years: Certified Information Systems Auditor (CISA) in good standing Certified Information Systems Security Professional (CISSP) in good standing Post-graduate degree in information security or a related field (e.g., business administration, information systems, information assurance) One Year: One full year of information systems management experience One full year of general security management experience Skill-based security certifications (e.g., SANS Global Information Assurance Certification (GIAC), Microsoft Certified Systems Engineer (MCSE), CompTIA Security +, Disaster Recovery Institute Certified Business Continuity Professional (CBCP), ESL IT Security Manager) Completion of an information security management program at an institution aligned with the Model Curriculum The experience substitutions will not satisfy any portion of the 3-year information security management work experience requirement. Exception: Two years as a full-time university instructor teaching the management of information security can be substituted for every 1 year of information security experience. " Incident Response = Domain 4 Pen Testing = (Loosely) Domain 2 so while you have the time, you don't have 3 of the 4 domain experience
jcundiff wrote: » hate to be a downer, but Incident Response and Pen testing does not equal InfoSec management experience.
amicmanzo wrote: » In regards to resources, I've been a Senior Digital Forensic Analyst in charge of 17 personnel, a team lead of 20 and technicall lead of smaller groups during IR missions . Are these not valid enough?
xxxkaliboyxxx wrote: » So us military guys can tell if you were in a manager type role or just in a leadership position, yes there is a difference. Sounds like you were just the team leader type of guy or senior/ most competent. A manager would be the OIC of your shop aka your boss. With that said, civilians do not know the difference either way. Phrase your words directly and I don't see why you wouldn't get by with a little play on words.
jcundiff wrote: » did you have any P&L responsibilities in those roles?