<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Why I Don&#8217;t Like CRISC</title>
	<atom:link href="http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/feed/" rel="self" type="application/rss+xml" />
	<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/</link>
	<description>The Blog Inspired By The Book</description>
	<lastBuildDate>Wed, 16 May 2012 16:05:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: IT AUDIT</title>
		<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/#comment-10863</link>
		<dc:creator>IT AUDIT</dc:creator>
		<pubDate>Wed, 16 May 2012 16:05:54 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1251#comment-10863</guid>
		<description>I know an IT Auditor who was just given the CRISC Cert because he is a member of ISACA, when they introduced the cert so he was grandfathered the CERT. and this guy knows nothing of IT, has no IT background, and from working with him I think he makes stuff up that he thinks is validate his existence here. I think he is a member of ISACA, and now a Chapter leader to have something to account for him of nothing at all.</description>
		<content:encoded><![CDATA[<p>I know an IT Auditor who was just given the CRISC Cert because he is a member of ISACA, when they introduced the cert so he was grandfathered the CERT. and this guy knows nothing of IT, has no IT background, and from working with him I think he makes stuff up that he thinks is validate his existence here. I think he is a member of ISACA, and now a Chapter leader to have something to account for him of nothing at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/#comment-10761</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Thu, 01 Mar 2012 21:41:29 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1251#comment-10761</guid>
		<description>@conrad

Thats great for you. I work at a director level for a &quot;major financial institution&quot; with 17 analysts reporting to me. 

A - There is no &quot;there there&quot; around the CRISC so Im not sure what you mean when you say it is applicable/appropriate.

B - As such, and given my current knowledge of the curriculum (admittedly sparse and due to change), a CRISC would not only NOT preoare you for a job in my team, but would probably inhibit your interview process by giving you a false sense of security.</description>
		<content:encoded><![CDATA[<p>@conrad</p>
<p>Thats great for you. I work at a director level for a &#8220;major financial institution&#8221; with 17 analysts reporting to me. </p>
<p>A &#8211; There is no &#8220;there there&#8221; around the CRISC so Im not sure what you mean when you say it is applicable/appropriate.</p>
<p>B &#8211; As such, and given my current knowledge of the curriculum (admittedly sparse and due to change), a CRISC would not only NOT preoare you for a job in my team, but would probably inhibit your interview process by giving you a false sense of security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Conrad</title>
		<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/#comment-10760</link>
		<dc:creator>Conrad</dc:creator>
		<pubDate>Thu, 01 Mar 2012 16:22:55 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1251#comment-10760</guid>
		<description>I perform Information Technology risk assessment for a major financial institution.  I am CISA certified and will be sitting for CISSP examination spring 2012.  CRISC is wholly applicable/appropriate for people in my particular line of work.  I would agree its not a broad spectrum certification track..but why should it have to be?</description>
		<content:encoded><![CDATA[<p>I perform Information Technology risk assessment for a major financial institution.  I am CISA certified and will be sitting for CISSP examination spring 2012.  CRISC is wholly applicable/appropriate for people in my particular line of work.  I would agree its not a broad spectrum certification track..but why should it have to be?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mustafa</title>
		<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/#comment-10576</link>
		<dc:creator>Mustafa</dc:creator>
		<pubDate>Sun, 29 Jan 2012 17:47:35 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1251#comment-10576</guid>
		<description>Okay,

Can anyone recommend a better certification for someone looking to be certified in Risk Management?

Thanks</description>
		<content:encoded><![CDATA[<p>Okay,</p>
<p>Can anyone recommend a better certification for someone looking to be certified in Risk Management?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: School</title>
		<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/#comment-10358</link>
		<dc:creator>School</dc:creator>
		<pubDate>Sat, 24 Dec 2011 08:48:52 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1251#comment-10358</guid>
		<description>Heya i?m for the first time here. I found this board and I find It truly useful &amp; it helped me out much. I am hoping to give something again and help others such as you aided me.</description>
		<content:encoded><![CDATA[<p>Heya i?m for the first time here. I found this board and I find It truly useful &amp; it helped me out much. I am hoping to give something again and help others such as you aided me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Barchie</title>
		<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/#comment-9118</link>
		<dc:creator>John Barchie</dc:creator>
		<pubDate>Wed, 20 Jul 2011 22:31:59 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1251#comment-9118</guid>
		<description>All,

   I jumped at the opportunity for the CRISC cert.  I am a CISSP, CISM and have several networking certs.  I learned risk management from the banking industry (FFIEC).   I am technical and I work in mixed DOD/commercial environments.
 
   Unlike CISM which is almost purely management CRISC is geared towared design and implementation.  Which is a cert we needed, hell I practically begged for it.  So much money is wasted on addressing the wrong  infosec risks it makes me sick.  

   Unlike mature fields that have a depth of data to draw from InfoSec is problematic due to the advent of more mature IT programs, but by using comparative analysis and WAGs it is at least possible to identify higher priority assets.  This understanding in and of itself justifies the emergence of the CRISC program. 

   Before there was IT there was InfoSec, and in the commercial world the CRISC helps to identify the controls necessary for good operational security.  Of course it helps if the CRISC practitioner has practical experience (and my application was a pain to fill out), and in fact experience is a requirement, but I find that it is much more important at this stage of our collective maturity level to know what to do, how to do it then becomes a task instead of a mission.  

   I can&#039;t tell you the number of times some IT manager wanted the firewall, AV and IDS configured as if those three controls were all that mattered. (And I am a former IT manager and can do all that) Seriously, most IT manager have never even heard of an information security risk assessment.  (And what the hell is IT doing being responsible for infosec risk anyway?)

My 2cents.</description>
		<content:encoded><![CDATA[<p>All,</p>
<p>   I jumped at the opportunity for the CRISC cert.  I am a CISSP, CISM and have several networking certs.  I learned risk management from the banking industry (FFIEC).   I am technical and I work in mixed DOD/commercial environments.</p>
<p>   Unlike CISM which is almost purely management CRISC is geared towared design and implementation.  Which is a cert we needed, hell I practically begged for it.  So much money is wasted on addressing the wrong  infosec risks it makes me sick.  </p>
<p>   Unlike mature fields that have a depth of data to draw from InfoSec is problematic due to the advent of more mature IT programs, but by using comparative analysis and WAGs it is at least possible to identify higher priority assets.  This understanding in and of itself justifies the emergence of the CRISC program. </p>
<p>   Before there was IT there was InfoSec, and in the commercial world the CRISC helps to identify the controls necessary for good operational security.  Of course it helps if the CRISC practitioner has practical experience (and my application was a pain to fill out), and in fact experience is a requirement, but I find that it is much more important at this stage of our collective maturity level to know what to do, how to do it then becomes a task instead of a mission.  </p>
<p>   I can&#8217;t tell you the number of times some IT manager wanted the firewall, AV and IDS configured as if those three controls were all that mattered. (And I am a former IT manager and can do all that) Seriously, most IT manager have never even heard of an information security risk assessment.  (And what the hell is IT doing being responsible for infosec risk anyway?)</p>
<p>My 2cents.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rich</title>
		<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/#comment-8788</link>
		<dc:creator>Rich</dc:creator>
		<pubDate>Tue, 03 May 2011 18:01:30 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1251#comment-8788</guid>
		<description>I could get it because I had my own company and then got hired to be the Director of Security so it makes me look good. I never take exams just go for grandfather certifications. Rich.Owen@earlywarning.com</description>
		<content:encoded><![CDATA[<p>I could get it because I had my own company and then got hired to be the Director of Security so it makes me look good. I never take exams just go for grandfather certifications. <a href="mailto:Rich.Owen@earlywarning.com">Rich.Owen@earlywarning.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: frankly frank</title>
		<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/#comment-8744</link>
		<dc:creator>frankly frank</dc:creator>
		<pubDate>Wed, 20 Apr 2011 06:10:16 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1251#comment-8744</guid>
		<description>Greetings.  I love ISACA - but I *hate* grandfathering in the way it&#039;s done now.  I&#039;ll also share a thought further below on some people&#039;s stuck-up view of people who have certs but lesser hands-on experience.

An earlier comment made here now paraphrased:  new certs are &quot;a start&quot; and better-refined in their body of knowledge 3 to 5 years after their creation.

THEREFORE, I feel that ISACA should change its grandfathering provision to allow the candidate to only keep it for 3 years and then they HAVE TO take the exam to keep it.  Only thereafter the CPE rule would apply.  Might cut into residual revenue for the credentialing organization - but that&#039;s all the more incentive to develop its BOK and get industry buy-in and not waste time with things that are flashy but hollow.

Next, on the cert .vs. hands-on issue, in the world of corporate types, there are specialists and generalists.  Author Geoffrey Moore observes that IT is a &quot;competence&quot; culture where specialists thrive because at the end of the day the person who knows the most technically, hits the most balls over the fence, and works the longest hours, gets to be the boss.

Generalists don&#039;t think that way which is why they&#039;re needed as supervisors over the teckies to keep things from turning into sweat-shop.

Corporate cultures that allow staff to make hire decisions rather than unit managers will have a problem with diversity.  They&#039;ll also give lip-service to being a &quot;learning organization&quot; but ultimately will hire for skill in the moment rather than overall talent.  The Gallup Organization has written multiple books on this issue in the last 10 years.

It&#039;s a waste of time for mid-career professionals as job candidates, who have a credential but only &quot;related experience&quot; in the new field they seek to enter, to interview with a specialist in a &quot;competence&quot; culture.  If that&#039;s the deal-breaker, then AVOID these organizations as their overall corporate culture is likely ad-hoc rather than managed.

Best Wishes,
Frank</description>
		<content:encoded><![CDATA[<p>Greetings.  I love ISACA &#8211; but I *hate* grandfathering in the way it&#8217;s done now.  I&#8217;ll also share a thought further below on some people&#8217;s stuck-up view of people who have certs but lesser hands-on experience.</p>
<p>An earlier comment made here now paraphrased:  new certs are &#8220;a start&#8221; and better-refined in their body of knowledge 3 to 5 years after their creation.</p>
<p>THEREFORE, I feel that ISACA should change its grandfathering provision to allow the candidate to only keep it for 3 years and then they HAVE TO take the exam to keep it.  Only thereafter the CPE rule would apply.  Might cut into residual revenue for the credentialing organization &#8211; but that&#8217;s all the more incentive to develop its BOK and get industry buy-in and not waste time with things that are flashy but hollow.</p>
<p>Next, on the cert .vs. hands-on issue, in the world of corporate types, there are specialists and generalists.  Author Geoffrey Moore observes that IT is a &#8220;competence&#8221; culture where specialists thrive because at the end of the day the person who knows the most technically, hits the most balls over the fence, and works the longest hours, gets to be the boss.</p>
<p>Generalists don&#8217;t think that way which is why they&#8217;re needed as supervisors over the teckies to keep things from turning into sweat-shop.</p>
<p>Corporate cultures that allow staff to make hire decisions rather than unit managers will have a problem with diversity.  They&#8217;ll also give lip-service to being a &#8220;learning organization&#8221; but ultimately will hire for skill in the moment rather than overall talent.  The Gallup Organization has written multiple books on this issue in the last 10 years.</p>
<p>It&#8217;s a waste of time for mid-career professionals as job candidates, who have a credential but only &#8220;related experience&#8221; in the new field they seek to enter, to interview with a specialist in a &#8220;competence&#8221; culture.  If that&#8217;s the deal-breaker, then AVOID these organizations as their overall corporate culture is likely ad-hoc rather than managed.</p>
<p>Best Wishes,<br />
Frank</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/#comment-8643</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Mon, 28 Mar 2011 19:58:30 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1251#comment-8643</guid>
		<description>Shaugn,

I think you&#039;ll find my &quot;vehemence&quot; for CRISC is directly proportional to my love of Information Risk Management.</description>
		<content:encoded><![CDATA[<p>Shaugn,</p>
<p>I think you&#8217;ll find my &#8220;vehemence&#8221; for CRISC is directly proportional to my love of Information Risk Management.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shaugn - CGEIT MBA BCom HDip(Met</title>
		<link>http://newschoolsecurity.com/2010/01/proving-crisc-is-stupid/#comment-8491</link>
		<dc:creator>Shaugn - CGEIT MBA BCom HDip(Met</dc:creator>
		<pubDate>Tue, 15 Mar 2011 10:13:52 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1251#comment-8491</guid>
		<description>Thanks Alex, the vehemence of your reply though gives me a sense that there are under currents here of a nature only known to you.
However, I respect your views, even though they differ from mine.

As for your comments about ISACA, again, I urge you to address your concerns to ISACA, they are after all the ones best placed to answer you. Also, refer to the ITGI (established in 1998), affiliated to ISACA, as one of the numerous ways that ISACA encourages debate and innovates. Getting the facts will then prevent a whole lot of conjecture.</description>
		<content:encoded><![CDATA[<p>Thanks Alex, the vehemence of your reply though gives me a sense that there are under currents here of a nature only known to you.<br />
However, I respect your views, even though they differ from mine.</p>
<p>As for your comments about ISACA, again, I urge you to address your concerns to ISACA, they are after all the ones best placed to answer you. Also, refer to the ITGI (established in 1998), affiliated to ISACA, as one of the numerous ways that ISACA encourages debate and innovates. Getting the facts will then prevent a whole lot of conjecture.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

