ISC2’s cover photo
ISC2

ISC2

Computer and Network Security

Alexandria, Virginia 512,736 followers

Your future. Secured.

About us

ISC2 is the world’s leading member organisation for cybersecurity professionals, driven by our vision of a safe and secure cyber world. Our more than 270,000 certified members, and associates, are a force for good, safeguarding the way we live. Our award-winning certifications – including cybersecurity’s premier certification, the CISSP® – enable professionals to demonstrate their knowledge, skills and abilities at every stage of their careers. ISC2 strengthens the influence, diversity and vitality of the cybersecurity profession through advocacy, expertise and workforce empowerment that accelerates cyber safety and security in an interconnected world.

Website
https://www.isc2.org/
Industry
Computer and Network Security
Company size
201-500 employees
Headquarters
Alexandria, Virginia
Type
Nonprofit
Founded
1989
Specialties
vendor-neutral certifications, IT security training and certification, Information security training and certification, Application security training and certification, cybersecurity certification, CISSP, cybersecurtiy training, cybersecurtiy education, and cybersecurity workforce development

Locations

  • Primary

    1650 King St

    Suite 200

    Alexandria, Virginia 22314, US

    Get directions
  • Level 1, Devonshire House

    One Mayfair Place

    London, W1J 8AJ, GB

    Get directions
  • 1 Harbour View Street, Central

    Level 20, ONE IFC

    Hong Kong S.A.R., Hong Kong, HK

    Get directions

Employees at ISC2

Updates

  • View organization page for ISC2

    512,736 followers

    More than 8,000 professionals have expressed interest in helping shape the future of AI security certification. Why does that matter? Because the most credible certifications are built on real-world practice. As ISC2 develops its future AI security certification, practitioners across industries are helping identify the knowledge, skills and abilities that reflect today's challenges and tomorrow's needs. From emerging threats and evolving regulations to AI governance and implementation realities, volunteer contributions help ensure certification standards remain practical, relevant and aligned with the profession. As one volunteer shared, practitioner involvement helps ensure certifications reflect "real world challenges and current industry practices." Interested in contributing your expertise and helping define global benchmarks for AI security competence? Read the blog and learn how you can get involved: https://ow.ly/5pMr50ZVTsO

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
      +1
  • ISC2 reposted this

    Great perspectives, James Howard! As one of the 236 members holding all three CISSP concentrations AND a CISSP tattoo—you certainly “bleed green.” 💪 🔒 Your distinction between better preparation and a lower standard matters. Growth alone is not evidence of dilution. At ISC2, we take exam integrity, experience requirements, endorsement, continuing education and our Code of Ethics seriously. And as you say, professionals still have to demonstrate judgment and effectiveness on the job. For those looking to distinguish themselves further, ISSAP, ISSEP and ISSMP offer opportunities to deepen their expertise. Our upcoming AI Safety security certification will offer another path, and we’re still welcoming volunteers to help develop the exam and participate in the beta. Of course, membership is more than just certification. For me, membership also means belonging to a global professional community committed to continuous learning, ethical practice and a safer digital world. Chapters, mentoring and volunteering offer many ways to contribute. No tattoo required! Thank you for being part of this community and advancing this conversation. P.S. Interested in volunteering for the AI certification? I’ll share the link below. And if anyone else has an ISC2 tattoo, I’d love to know! 🔗 Sign up to be a subject matter expert for the AI certification here: https://lnkd.in/ey7w7jkq

    View profile for James Howard

    Cybersecurity Risk & AI Governance | Mission Assurance, Security Engineering & RMF | Decision Governance in High-Consequence Systems | CISSP (ISSAP, ISSEP, ISSMP), CGRC

    I have a CISSP tattoo. 😂 I also post the Dilbert cartoon where the guy says, “Step aside. I am certified.” Those two things are not contradictory. I earned my CISSP in 2008, and I have long said it opened doors for me that probably would not have opened otherwise. It mattered to my career. I am proud of it. ▶️ But I have never believed a certification makes somebody competent. Lately I have seen more people argue that the CISSP has become “watered down” because there are more CISSPs, younger people are passing the exam, and candidates have access to dramatically better study tools than we did 15 or 20 years ago. Maybe. But I think that claim needs evidence. “There are more CISSPs now” tells me very little without a denominator. Cybersecurity is also vastly larger than it was when I earned mine. There are more cyber jobs, more cyber professionals, more regulated environments, more cloud systems, more attack surface, and more organizations that need people who understand risk. I also think we need to distinguish between an exam becoming easier and preparation becoming better. I became an MCSE in the Windows NT 4.0 days. By the Windows 2000 era, braindump sites were circulating reconstructed, and sometimes actual, exam questions. People could memorize answers instead of learning the material. That absolutely diluted a credential. Today, CISSP candidates have adaptive test engines, online courses, enormous question banks, YouTube, Reddit, Discord, and AI. If somebody can use AI to explain Bell-LaPadula five different ways, generate scenario questions, identify weak domains, and study more efficiently, is that evidence the CISSP was watered down? Or did learning get better? 🤔 If ISC2 lowered the competency standard, that concerns me. If people are simply getting better at preparing for the standard, I have a hard time calling that a problem. Passing the exam is also not the same thing as becoming a CISSP. The experience requirement still matters. At the end of the day, I do not care how many letters are after your name. You still have to be effective. Here is what would support the dilution argument: meaningful changes in pass rates over time, evidence that the passing standard has been lowered, or employer data showing newer CISSPs lack the judgment, breadth, or risk-management ability the credential should represent. THAT would be dilution. The industry should also look in the mirror. We put “CISSP required” on jobs that do not need it, even junior ones. Then we act surprised when younger professionals pursue it. We told them it was valuable. They believed us. Difficulty, by itself, is not quality. A certification should not exist to preserve the exclusivity of those who already hold it. So the question is not “Are there too many CISSPs?” It is: does the CISSP still mean what the profession needs it to mean? If yes, growth is not dilution. If no, show me why. “There are more of them now” is not enough. #CISSP #Cybersecurity

  • View organization page for ISC2

    512,736 followers

    The most effective cybersecurity awareness efforts don't start with technology. They start with people. This edition of ISC2 Up2Date explores how cybersecurity professionals are helping colleagues better understand cyber risks, develop stronger security habits and build more resilient organizations. Featured stories include: • Member perspectives on rethinking cybersecurity awareness • Practical approaches for creating lasting behavior change • New ISC2 research on India's cybersecurity workforce • Insights into the value of professional codes of conduct As part of Cybersecurity Awareness Month, we'd like to hear from you: What approach has helped your organization improve cybersecurity understanding beyond the cybersecurity team? Read the latest issue and join the conversation: 

  • View organization page for ISC2

    512,736 followers

    Trust powers nearly every part of modern life. We trust our financial institutions, healthcare providers, employers and the digital services we use every day. That trust is built through the efforts of cybersecurity professionals whose work often happens behind the scenes. As Cybersecurity Awareness Month begins, Our CEO, Scott Beale, shares a reminder that cybersecurity is about more than technology. It’s about people protecting people. Throughout October, ISC2 will spotlight the professionals, stories and practical insights that help organizations become more resilient and security-conscious. Our latest article explores why cybersecurity awareness matters across the entire enterprise and why every employee has a role to play in reducing risk and strengthening organizational resilience: https://lnkd.in/gBumJRGY Thank you to the cybersecurity professionals helping make everyday life more secure!

    Cybersecurity is having a moment. With all the news about hacking, breaches, new AI models and previously unknown threats, everyone is paying attention to our sector.  In this moment, it seems appropriate to recognize that cybersecurity also has a month: October! This month is not just for pumpkin-flavored lattes in the US, beers in Germany or Dussehra in India. October is also Cybersecurity Awareness Month.  It’s a good time to recognize how important this profession is and how much we rely on the individuals behind it.  Trust is one of the most valuable assets in our digital world. We depend on it every day, often without realizing it.  Every time we access our bank account, schedule a doctor’s appointment, work remotely or connect with family and friends online, we’re placing trust in systems that must be secure, resilient and reliable.  That trust doesn’t happen by accident. It is built and maintained by cybersecurity professionals whose work often goes unseen, but whose impact is felt everywhere.  As we begin Cybersecurity Awareness Month, I’m reflecting on the important role these professionals play and offering my thanks to the people who help keep our digital world running securely.  At ISC2 supporting the cybersecurity profession is at the heart of our mission. Through certifications, professional development and a global community of practitioners, we’re helping professionals stay ready for what’s next.  Cybersecurity is about technology, but it’s also about people. People protecting people.  Thank you to the cybersecurity professionals around the world helping build a safe and secure cyber world.  What is one thing you wish more people understood about the cybersecurity profession? 

  • View organization page for ISC2

    512,736 followers

    Nearly 7 in 10 cybersecurity professionals say the most important area to define as AI adoption grows isn't a technical control. It's governance. In a recent LinkedIn poll, 68% of respondents identified AI governance and compliance as the top priority as AI continues to reshape cybersecurity. Practitioners also highlighted the need for AI threat modeling frameworks, secure AI data pipelines and defenses against adversarial attacks.  The results reflect a reality many organizations are facing today: securing AI requires more than technology. As AI becomes part of business-critical operations, governance, accountability, transparency and risk management are becoming foundational to responsible adoption. These findings also underscore an important question for the profession: What knowledge and expertise will cybersecurity professionals need to securely govern, deploy and manage AI systems in the years ahead? Read the full article to explore the findings and learn how cybersecurity professionals can help shape the future of AI security standards: https://lnkd.in/gYmj9r73

    • No alternative text description for this image
  • ISC2 reposted this

    The cybersecurity profession continues to evolve, and so do the ways we can contribute to strengthening it. Today, ISC2 announced an important milestone: we have been granted Accredited Standards Developer (ASD) status by ANSI - American National Standards Institute and have launched the ISC2 Standards Development Group (SDG). Why does this matter? Cybersecurity practitioners bring valuable real-world expertise to the challenges organizations face every day. As technology, threats and operational environments continue to change, there is growing need for standards that are informed by practical experience, shaped through collaboration and built through transparent, consensus-based processes. With this designation, ISC2 can convene cybersecurity professionals, industry leaders, academics and government stakeholders to help develop American National Standards that support the profession and the broader cybersecurity community. What stands out to me is the opportunity for participation. The most effective professional standards are not created by any one organization. They are built by communities of experts willing to share their knowledge, perspectives and experience. I’m grateful to everyone who helped make this milestone possible, and I look forward to seeing how our members and stakeholders help shape this next chapter. Learn more about the ISC2 Standards Development Group and opportunities to get involved:   🔗 https://lnkd.in/gB5MXfgD And also let me know, how do you see standards playing a role in addressing emerging cybersecurity challenges?

  • View organization page for ISC2

    512,736 followers

    AI is changing cybersecurity assurance. Critical infrastructure faces growing workforce challenges. And organizations are continuing to navigate evolving regulatory requirements. The latest edition of ISC2 Up2Date explores these issues and more, including: - New interactive learning experiences at ISC2 Security Congress - Building the cybersecurity workforce needed to help secure critical national infrastructure - New ISC2 research on the impact of Cybersecurity Maturity Model Certification (CMMC) preparation efforts and the current pause - An ISC2 member's perspective on how AI changed their approach to cybersecurity assurance - How partnerships are helping create pathways for the next generation of cybersecurity professionals As #CybersecurityAwarenessMonth approaches, we'd also like to hear from you: What's been the most effective way you've raised cybersecurity awareness in your organization? Your insights could be featured in an upcoming ISC2 article 👇

  • View organization page for ISC2

    512,736 followers

    Your expertise can help shape the future of AI security. ISC2 is bringing together experienced cybersecurity professionals to help develop a new AI Security certification. This is an opportunity to contribute your expertise, influence the profession and help create a credential that supports cybersecurity practitioners around the world. We're looking for volunteers with experience in: 🔹 AI Security 🔹 Application Security 🔹 Cybersecurity Operations 🔹 Security Architecture 🔹 Cloud Security 🔹 Data Protection & Privacy 🔹 Risk Management Whether participating in SME reviews, Job Task Analysis (JTA) workshops, content validation activities or framework reviews, your insights can help ensure this certification reflects today's AI security realities and tomorrow's workforce needs. Ready to make an impact? Apply to volunteer: https://ow.ly/m9Xr50ZPcKz

  • View organization page for ISC2

    512,736 followers

    What a day in Toronto! Today, we hosted our inaugural ISC2 SECURE Canada, bringing together cybersecurity professionals from across the country for a day of learning, collaboration and meaningful conversations about the challenges shaping our profession. From discussions on AI security, cyber resilience and third-party risk, to insights from industry leaders and opportunities to connect with peers, the day showcased the expertise, passion and commitment that continue to drive the cybersecurity community forward. The experience began with pre-conference workshops led by Simon Salmon and Brandon Dunlap, setting the stage for thoughtful discussions and practical learning before today's main event. We were also pleased to welcome the ISC2 Toronto Chapter, whose support and engagement helped make this milestone event even more meaningful. Strong local communities play an important role in advancing the profession, and it was great to connect with so many chapter members throughout the day. To everyone who joined us in Toronto, whether as a speaker, attendee, chapter member, sponsor, volunteer or staff member, thank you for helping make our first SECURE Canada a success. We look forward to continuing the conversation. Till next time 👋

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
      +1
  • View organization page for ISC2

    512,736 followers

    What happens when a major cybersecurity compliance requirement hits pause? The recent CMMC delay has implications for organizations, security teams and professionals responsible for balancing regulatory requirements with real-world risk management. The key takeaway: regulatory timelines may shift, but the need for strong cybersecurity practices remains constant. Explore the latest ISC2 Insights perspective and what it means for the cybersecurity community: https://ow.ly/ZCfu50ZOLOA

    • No alternative text description for this image

Affiliated pages

Similar pages

Browse jobs