Winging It · Implausible Deniability
I have held the CISSP for what I'm told is an unreasonable length of time. I sat it when it was still ten domains, two hundred and fifty questions, and six hours. On paper. With a pencil. In a room that smelled like carpet cleaner and quiet desperation. I mention this partly for sympathy, which I will accept, and partly because it's context for everything that follows.
The Certified Information Systems Security Professional examination is, depending on who you ask, either the gold standard of cybersecurity credentials or the most elaborate hazing ritual in professional life. It is an exam that tests your ability to answer questions about security in a way that has almost no relationship to how security is practised, in environments that no longer exist, using terminology that nobody uses, about scenarios that would get you fired if you handled them the way the exam expects. And it costs a fortune. And you need it. And everyone knows you need it. And nobody can quite explain why.
The study process begins, in my experience, approximately four months before you intend to sit the exam and approximately three months and three weeks after you bought the textbook. The textbook is enormous. It is always enormous. The current edition of the Official (ISC)² Study Guide runs to over a thousand pages, which is roughly the same length as War and Peace, except Tolstoy had the decency to include characters you could care about. The CISSP study guide has eight domains. Eight. It had ten when I sat it, which felt less like a curriculum and more like a punishment. As though security were a medieval kingdom that had been divided among quarrelling heirs, each one demanding equal representation regardless of relevance.
There is a domain on physical security. In an era where most of us work in a browser, on a laptop, connected to cloud infrastructure distributed across three continents, there is a section of the most prestigious cybersecurity exam that requires you to know about bollards. Mantrap doors. Fence heights. The optimal fence height, if you're wondering, is eight feet. With three strands of barbed wire. Angled outward at forty-five degrees. I learned this. I committed it to memory. I can tell you the difference between a mantrap and a vestibule. I have never, in twenty-five years, been asked to specify a fence. But I can. I am certified to have opinions about fences. This is what the exam buys you.
The study period itself follows a pattern so universal it might as well be codified. Week one: enthusiasm. You buy the book. You buy the practice tests. You download an app. You create a study schedule with colour-coded blocks that allocates ninety minutes every evening and four hours on Saturday mornings. You tell people you're studying for the CISSP and they nod with the respectful sympathy usually reserved for people training for an ultramarathon or going through a divorce.
Week two: you open the book. You read about the security governance domain. It is about governance. You learn that governance is important. You learn that policies support governance. You learn that standards support policies. You learn that procedures support standards. You learn that guidelines support procedures. You make notes. The notes look exactly like the book but in your handwriting. You are copying a textbook. You are a university student again, except older, tireder, and paying for it yourself.
Week three: you skip an evening. Just one. You were tired. Week four: you skip three evenings. The colour-coded schedule develops gaps. Week five through eleven: the book sits on your bedside table accumulating guilt in the way that only an unread textbook can. You pick it up occasionally. You read a page about the Biba integrity model. You put it down. You pick it up again. You read about Bell-LaPadula. You understand it for approximately nine minutes and then it's gone, like a dream you can't quite hold onto after waking. Star property. Simple security property. Strong star property. The words enter your eyes, travel to your brain, and exit through your ears without making contact with anything on the way through.
Week twelve: panic. The exam is in three weeks. You have covered two and a half domains out of ten. You abandon the textbook and switch to what the CISSP community calls "the cram." This involves practice questions. Thousands of practice questions. You download apps. You join forums. You watch YouTube videos made by people who passed the exam and now speak about it with the haunted authority of combat veterans. "Think like a manager," they say. "Think like a manager." This is the most repeated piece of CISSP advice in existence and it means that when presented with a security problem, you should choose the answer that involves the most process and the least actual technical work. It is, unfortunately, excellent advice.
The practice questions are an art form. They test whether you can identify which of four plausible answers the exam considers correct, which is a different skill entirely from knowing the answer. "A company has experienced a data breach. What should the CISO do first?" The answers are all things a CISO should do. Notify the board. Contain the breach. Activate the incident response plan. Assess the scope. They are all correct. You must pick the most correct one. The most correct one is always the one that sounds the least urgent. Assess. Determine. Evaluate. Never "fix the thing." Never "stop the bleeding." The CISSP operates in a world where every emergency is best met with a meeting.
I took the exam on a rainy Tuesday. You file into a room. You get a paper booklet and a pencil that has been sharpened by someone who clearly resented the task. You sit at a desk. Two hundred and fifty questions. Six hours. The clock on the wall is the only company you're allowed. Not your phone. Not your notes. Not your self-respect. Just you, the pencil, and a small booklet that is about to ask you how you feel about fences.
The first question was about the OSI model. I have learned the OSI model four times in my career. Once at college. Once for my first certification. Once for the CISSP. And once more for the CISSP. Each time, I have memorised all seven layers, understood what each one does, nodded with satisfaction, and then forgotten the whole thing within seventy-two hours of the exam ending. I could not, right now, tell you what the session layer does. I'm not convinced the session layer knows what it does. It is the middle child of networking models. It exists because someone needed seven layers and six wasn't enough.
The exam took six hours. Some questions I knew. Some questions I deduced. Some questions I stared at with the blank intensity of a man trying to remember a word in a language he doesn't speak. There were questions about cryptographic key lengths. There were questions about fire suppression systems. There were questions about tape backup rotation, tape backup in this economy, using a scheme called Grandfather-Father-Son, which sounds like a BBC drama about a farming family and is instead a method of rotating magnetic tape that was last relevant when people still had pagers.
There is a moment, about three hours in, where you stop trying to remember what you've learned and start trying to channel what the exam wants to hear. You think like a manager. You think about governance. You think about risk. You pick the answer that is most cautious, most procedural, most likely to have been written by someone who has never touched a firewall but has very strong opinions about frameworks. You become the answer. You are no longer a security practitioner. You are a policy document in human form. And it works, which is the worst part.
I passed. I got the notification. I felt the brief, warm glow of achievement that comes from clearing a hurdle you're not entirely sure should exist. I was now certified. I had demonstrated, through six hours of multiple-choice questions about fences and tape rotation and the session layer, that I was a qualified security professional. Companies could now trust me. Clients could now rely on me. The letters after my name proved that I knew things. Important things. Things I had already forgotten.
The CPE cycle starts immediately. Continuing Professional Education. To keep the certification, you need to earn credits every year by attending training, writing papers, or doing other professional development activities. This is sensible in theory. In practice, it means logging activities in a portal that looks like it was designed in 2004, because it was, and hoping that nobody audits your claim that listening to a podcast on the way to work constitutes structured learning.
Then there's the annual maintenance fee. A hundred and thirty-five dollars. Every year. Not for new content. Not for updated training. Not for access to anything that might help me deal with the threats I actually face on a Tuesday morning. Just for the privilege of continuing to call myself certified. It is a subscription to my own name.
I renewed it last year. I logged my CPEs. I paid the fee. I did this with the quiet resignation of a man renewing a gym membership he hasn't used since March. The renewal email arrived again last week. A hundred and thirty-five dollars. Due next month. I'm not entirely sure I'm going to pay it.
I can tell you about the Biba model. I can tell you about Bell-LaPadula. I can tell you the optimal height for a perimeter fence.
I cannot tell you what the session layer does.
But at least for the moment, I'm certified.
— Chris
