Welcome to cissp CISSP training Certified Information Systems Security Professional
Search
Nickname Password Security Code Security Code Type Security Code  

Best training in the world

FITSI the certification program for the federal workforce

Rated #1 Training

Surveys

Where do you find the best price for books?

Amazon.Com
Bookpool.Com
The ISC2 webstore
CISSPS.COM
Cheapbooks.com
Ecampus.com
Other (Please leave a comment with name of site)



Results
Polls

Votes 1758

Who's Online

There are currently, 56 guest(s) and 5 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
cissp CISSP training Certified Information Systems Security Professional: ISC2 Org

Search on This Topic:   
[ Go to Home | Select a New Topic ]

(ISC)2 Election of Directors Voting “Irregularities”
Posted by boss on Wednesday, 16 November 2011 @ 22:37:32 EST (503 reads)
Topic ISC2 Org

Anonymous writes "

Dear Colleagues,

There are a few irregularities in the (ISC)2 Process/System today, as noted in the CISSP Forum.

- the (ISC)2 voting instructions posted today omit mention of the “write-in” candidate procedures

- There are five blank lines for “write-in” candidates but only 4 votes count

- the “VOTE” button is missing. There is a button labeled “button”

As information, there are at least two qualified write-in candidates available:
   - Javed Ikbal 
   - Rolf Moulton

 Rolf Moulton, CISSP-ISSMP
 “Write-In”  (ISC)² Board Candidate
 http://www.boardcandidate.com

"

(Read More... | Score: 0)


ISC2 Decertification: I Received My (ISC)2 Decertification Notice Today
Posted by boss on Sunday, 02 October 2011 @ 20:22:17 EDT (645 reads)
Topic ISC2 Org

Anonymous writes "

UPDATE ON 10 Oct 2011:

Someone asked me why I believe it is cheaper to do the exam every year and pay my Annual Maintenance Fee (AMF).  The math is VERY easy to do, see the breakdown below:

         COST BREAKDOWN FOR 120 CPE'S                     COST BREAKDOWN IF YOU DO NOT SUBMIT CPE'S   

  One week class is equal to 40 CPE's

  You need three weeks of training or the
  equivalent to get 120 CPE's in 3 years.

  This is 3 weeks of training at $2000 per class  
  on average.  Which is  a grand total of $6000

  This also means that you would loose $1000
  per day in earnings if you're a contractor.  For a great  
  total of $15,000 in loss wages.

  Let says you add hotel, Airfare, food, transportation 
  is another $1000 per class that's another $3000
  you must add to the cost.

  Adding all of the above you have $24,000 invested to 
  maintain and renew your certification.

  That's a bit too expensive for me.

 

  If I choose to not submit any CPE's and do the exam yearly 
  then it would be a lot cheaper.  

  I can do the exam on the week end where I do not loose any 
  days of consulting.   SO that's $15,000 that I am not loosing
  in wages.  

  The exam cost only at the most $600 each time.  Which is
  only $1800 over a three year period to do the exam yearly.

  The AMF is $85 a year for a total of $255 over a 3 years period.

  I can schedule an exam in my local town where I do not have to 
  pay for airfare and hotel and transportation.  

  Overall I am saving almost $22,000 by doing the exam yearly instead 
  of playing the CPE game.

  I think the numbers speaks by themselves.

NOTE FROM CLEMENT:

Today I have received my notice of Decertification.   This was not a surprise as I did not submit a single CPE's over the past 3.5 years.

A while back I published a paper on the easiest and cheapest way of maintaining the CISSP certification,  the conclusion was:  DON'T

What is the value of an exam you took 13 years ago and never ever challenged it again.  I think it is not worth as much as someone who regularly take the exam just to ensure you can still do it and your skills level has been maintained over the years.  This is the route I decided to take.

If I take the certification test every year and I pay my Annual Maintenance Fee of $85 per year this is a lot cheaper than taking a single training class for CPE's and I have the opportunity to demonstrate that I did not pass the test only once by cramming but passed it regularly over the years showing that my mastery of the ten domains of the CBK was constantly maintained.   Or I could simply submit my 500 CPE's that I have accumulated over the past 3.5 years...  But that would be too easy :-)

So I guess I will need to book my exam for sometimes this fall,  or I may wait to see how the new delivery through VUE testing is working,  if it ever become available in English of course.    I will wait a few months and revert back to the paper based exam if ISC2 don't come out with the English version before end of year.   

Three years ago I predicted the CISSP exam in English would be the last to be offered through VUE testing and it seems it will be the case.   I can enlighten you as to why this is the case over a cold Guinness when we meet in person.

Hopefully I can pass the exam when I take it again :-)

Best Regards to all


Clement

SEE WHAT THE OFFICIAL NOTICE OF DECERTIFICATION LOOKS LIKE BELOW:

01 Oct 2011

Member ID:             4988
Certifications(s):      CISSP

Three-Year cycle expiration date:   30 Apr 2011

Dear Clement Dupuis,

The purpose of this notice is to provide information regarding the status of your (ISC)2 certification.

According to our records, you have not met the renewal criteria with respect to Annual Maintenance Fees and/or Continuing Professional Education requirements. Therefore, your CISSP credential expired effective 30 Sep 2011.

Because the CISSP is a federally-registered certification mark, you may no longer use the CISSP designation in any form. For example, you may not use CISSP after your name, on printed materials and you may not display the certificate itself, wear the CISSP lapel pin or imply in any way that you are presently certified. Continued use of the CISSP designation is unauthorized and an infringement of the CISSP mark, and will result in further action being taken by (ISC)2.

To be certified again, you must sit for, and pass the CISSP examination again. However, in order to do so, you must pay any outstanding AMF and late fees before registering for the exam.

If you have any comments or questions, do not reply to this email. Please email membersupport@isc2.org.

Sincerely,

(ISC)2 Member Services

"

(ISC)2 at a crossroads: CISSP value vs. security industry growth
Posted by boss on Sunday, 25 September 2011 @ 10:46:13 EDT (827 reads)
Topic ISC2 Org

cdupuis writes "

NOTE FROM CLEMENT:

SearchSecurity has a great posting about the future of the CISSP certification and it's value.   It is interesting to note they mention one flawed metric that ISC2 has been using for year to show and gauge their success:  TOTAL NUMBER OF CISSP WORLDWIDE.  

Even thou having close to 80,000 CISSP seems like a great achievement it mostly mean nothing if you had no impact on the security community.    If you look at the CISSP forum for example, there are only a few hundreds that participate and the others are lurkers or they do not even know about the forum.   80,000 seems like a great success but it is not a whole lot considering the financial means they have and how much money they are charging for any of their services.  

The CCCure Family of Portals has more than 160,000 members overall.  We achieve this without charging one cent to our members.  Accessibility and content has always been our focus.   Yes, we do need money to survive but there are ways to offer value at fair price and certification boards have not understood this yet.   Only very recently we had to start chargind money for some of our services.   With over $1000 in operating fees per week we have to have some funding to remain alive.  We believe in offering value for the money you pay,  a good example is our quiz engine with all of it's features where we charge only  $39.99 for almost 1800 relevant and updated question while ISC2 will charge you $129 for 100 old and retired exam questions.  I would never pay $129 for 100 questions that is for sure.

Certification bodies today are making millions a year while providing little to no value to the people who took their certification.   The focus is on making money instead of education. 

Demonstrating success is a lot more than doing a few surveys per year.  So far I have not received much from ISC2 after i became certified,  I did receive a lot of advertising of PAY FOR activities.  I have not receive any best practice documents,  I have not receive documentation on the latest legislation and how we are affected as security professionals,   but I do receive my yearly note to pay for my Annual Maintenance Fees (AMF).   It seems the continous education is something members must do on their own and our organization will not provide us with tools to better do our jobs.  

There are compelling alternative to the CISSP that will soon be released,  if ISC2 does not demonstrate and exercise better care in providing TOP and RELEVANT security education while being a more active community player, they will be left behind.   This is really unfortnate for the current members who have work hard to obtain their cert and they wish to see it's value increased in the future.   A serious change of mind will be required to achieve such goals.

See the article link below:

http://searchsecurity.techtarget.com/opinion/ISC2-at-a-crossroads-CISSP-value-vs-security-industry-growth?asrc=EM_USC_14968032&track=NL-105&ad=849101&

"

(Read More... | Score: 0)


CISSP Exam Computer Based testing has arrived, English version not available yet
Posted by boss on Friday, 16 September 2011 @ 00:01:49 EDT (852 reads)
Topic ISC2 Org

cdupuis writes "
NOTE FROM CLEMENT:
Finally,  the CISSP exam will be available as a computer based exam.    Unfortunately it is not available in English yet.   Hopefully ISC2 will soon released the english version as well.   This is definively a great step forward in making the exam more accessible to people in countries outside of the USA or in smaller cities and town where training in not regularly run.   Let`s cross our finger and hopefully within a short time frame the english version will be released.  I fail to understand WHY the english version could not be released at the same time.  This is definitively something that is greatly needed right now. 

See posting from the ISC2 web site below:

As seen on the ISC2 website at:  https://www.isc2.org/latin-am-cbt.aspx Latin America Computer Based Testing (CBT)

(ISC)² is proud to announce that beginning October 1, 2011, the company will launch a pilot program to make the CISSP and SSCP exams available via CBT for candidates throughout Latin America. Latin American Candidates will be able to take the CISSP via Computer Basted Testing in Portuguese or Spanish, and SSCP candidates will be able to take the exam in Portuguese only.

The following Latin American CBT locations include:

Argentina, Bolivia, Brazil, Chile, Columbia, Costa Rica, Ecuador, El Savador, Guatemala, Honduras, Nicaragua, Panama, Paraguay, Peru, Uraguay, and Venezuala.

View the FAQs to assist you as you proceed through registration.

CISSP

SSCP

"

(Read More... | Score: 2)


ISC2 Board of Directors Ballot -- Put in your vote
Posted by boss on Sunday, 11 September 2011 @ 18:54:23 EDT (550 reads)
Topic ISC2 Org

cdupuis writes "

NOTE FROM CLEMENT:

Below you have a message from my friend Eric Conrad that he posted on his mailing list.   I agree with Eric and also support Wim Remes as someone who could bring new blood and changes to the board of directors at ISC2.    I encourage everyone to visit the platform of the candidates and put in your vote about WHO you would like to see on the board of director.  See the message from Eric below:

Hey folks,

I'll be teaching at SANS NS 2011 in Vegas in 3 weeks. First round of adult beverages is on me.

Just quick note to say that a number of people have launched campaigns to be added to the official ISC2 Board of Directors ballot.

This post by Errata Security makes a great point: read the list of ISC2's current board of directors: how many names do you recognize from their work in our community? Then do the same for SANS' current board of directors.

My results were 1 and 7, respectively. I am biased due to my work with SANS, so please play that game yourself.

It doesn't have to be this way.

I believe an injection of new blood and new ideas is long overdue, and much needed. 

I support Wim Reme's petition, and am investigating the others to see if I will support them. 

Wim passed my first test: do I know this person from their work in our community? I also agree with his platform.

If you are a CISSP, please take some time to read these candidate's platforms, and consider supporting those you agree with. Details are listed in ISC2's email, attached below.

Thank you,

                         ...Eric


---------- Forwarded message ----------
From: (ISC)2 Management <management@isc2.org>
Date: Fri, Aug 26, 2011 at 10:40 AM
Subject: OFFICIAL: Election Petitioners Requesting Your Support


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Dear Valued Member,

Pursuant to the current (ISC)2 Bylaws, Section IV, Paragraph 8, any member of (ISC)2 may be listed on the official election ballot if they submit a petition containing at least one percent (1%) of the membership as of the date of the election announcement.  As of 16 July 2011, that number was 79,368, resulting in 794 signatures necessary to submit a petition.  However, the (ISC)2 Board of Directors has voted that the number be reduced to 500.

As mentioned in the last e-mail regarding this year's election, which announced the official board slate, this one-time e-mail is sent on behalf of those members requesting your support in a petition to be listed on the official ballot. This year, four members have requested we notify you of their candidacy.

Seth Hardy - email:  shardy@asymptotic.ca  website:  http://sethforisc2board.org

Javed Ikbal - email: javed@bodelection.com   website: http://bodelection.com

Rolf Moulton, CISSP-ISSMP - email:  rolf.moulton@boardcandidate.com  website:  http://www.boardcandidate.com

Wim Remes - email: wim@remes-it.be  website:  http://blog.remes-it.be/petition.html

All questions regarding the listed member, his background, experience, qualifications, or platform should be directed to the respective member via his website or e-mail referenced above.  DO NOT send your e-mail supporting the candidate to (ISC)2 - it will not be counted.  It must go directly to the candidate.

We look forward to your participation in the upcoming elections!  As always, if you have questions regarding the elections, please send an e-mail to bodelections@isc2.org.

NOTE: THIS MESSAGE IS NOT AN ENDORSEMENT OF THE LISTED MEMBER(S) CANDIDACY IN ANY WAY. LINKS LISTED HEREIN HAVE BEEN PROVIDED BY THE RESPECTIVE MEMBER(S).  NO STATEMENT OR WARRANTY IS MADE BY (ISC)2 WITH REGARD TO THE CONTENT, ACCURACY, OR SECURITY OF SUCH SITES.

Best regards,

Dorsey Morrow, CISSP-ISSMP
General Counsel & Corporate Secretary


Please do not reply to this message. For questions or to contact (ISC)2, please visit http://www.isc2.org/contactus.

To download the up to date pgp key, go to https://mail-gw.isc2.org.

"

(Read More... | Score: 0)


ISC2® forgot about the meaning of the letter "A" in CIA
Posted by boss on Saturday, 20 August 2011 @ 18:59:37 EDT (717 reads)
Topic ISC2 Org

cdupuis writes "

NOTE FROM CLEMENT:

I received a note today from one of my student telling me the ISC2® online registrations web site will be down for over 15 days due to maintenance.  I taught this was another joke but it is true.   I visited the web site and it was confirmed,  they even encourage people to wait until the system will be back online on September 15th to register.   This is unacceptable,  why do you need two weeks to perform a system or web site upgrade?  What about continuity of operation?   It seems the Business Continuity Planning (BCP) they preach do not apply to them.   I have seen companies who are 100 times the size of ISC2® and with online systems that are way more complex perform upgrade without any downtime or very minimal downtime.   If I would tell my boss that a web upgrade will render our web site and some of our online services unavailable for two weeks, I would get fired for sure.  I fail to understand WHY such downtime is necessary???    See a copy of the text posted on the ISC2® website below:

System Maintenance Message on the exam registration page

We apologize for any inconvenience, but in order to provide you with more efficient services, (ISC)&sup2; is performing system maintenance. As a result, online exam or Review Seminar registration will not be available from 12:00 pm EDT on August 19 until 11:59 pm EDT on September 4, 2011.

We encourage you to wait to register for your exam or class until the system is available again starting at 12:00am EDT on September 5, 2011. In the event that you need to register for a seminar or exam during this time, you may download and complete the registration form below and send it to registration@isc2.org or fax to 727.683.0785 . Please note that if you are paying by credit card, we will not charge your card until our system is available again on September 5, 2011.

Exam Registration Form (PDF)         Seminar Registration Form (PDF)

Or, to register for seminars only by phone, contact an (ISC)&sup2; Certification Consultant
at +1-866-462-4777 or +1.703.891.6781 between the hours of 8:00 a.m. and 5:00 p.m. EDT.



The main web site also got the following message:
We apologize for any inconvenience, but in order to provide you with more efficient services, (ISC)&sup2; is currently upgrading its registration processing system. As a result, online exam registration will not be not available from 12:00 pm EDT on August 19 until 11:59 pm EDT on September 4, 2011. We encourage you to wait to register for your exam or class until the system is available again starting at 12:00am EDT on September 5, 2011.

 

Best regards

Clement

"

(Read More... | Score: 5)


OSG NEWS: CISSP CIB Clarification
Posted by boss on Friday, 15 July 2011 @ 00:41:01 EDT (1166 reads)
Topic ISC2 Org

Anonymous writes "

NOTE FROM CLEMENT:
I usually do not post anonymous articles but this one is well written and does provide some objectives and accurate clarification on the process to create the updated content within the DCO.    I will not debate the Job Task Analysis within someone else post but I think there are defenitively subjects that should have been added that are not added.  Maybe people are filling out those Job Task Analysis online survey forms too quickly or there is issue with the sampling.  In any case,   I would like to thank the anonymous poster for the clarifications.   It is very helpful for all future CISSPs. 

Recently, Clement Dupuis provided a detailed line by line comparison of CISSP’s Detail Content Outline (DCO) of 2009 and 2012, and also commented on the information included in the Candidate Information Bulletin (CIB) on his posting at http://www.cccure.org/modules.php?name=News&file=article&sid=1552

Providing such a detailed comparison of two DCOs and identifying the content added and edited should be helpful to aspiring CISSPs who are planning to write the CISSP test in near future. Kudos to Clement for providing such a service to the IT security community.

However, a few misconceptions exist in the post which, if corrected, could be helpful to all readers of this post. Certification examinations are criterion-referenced tests, in which domains of performance are defined by conducting a job analysis study. For that reason, (ISC)2 conducts a job analysis for each credential in regular intervals of three years to update the current status of the profession.

The important purpose of the DCO derived through a job analysis is not intended for teaching but for developing tasks, knowledge elements and skills important in the practice field. In general, DCO does not include emerging technologies that are coming up in practice but have not been widely used. The content cannot be added to the DCO if only a small selected group of professionals practice it. For the CISSP examination, new technology has to be practiced by the majority of the professionals throughout the world before the content used in the technology is included in the DCO. Anything new that has not been fully used by a larger community throughout the world will be captured on the successive job analysis assuming that those technologies stay in use. Obviously, there is a short lag between emerging technology and what is included in the DCO. Since the purpose of conducting a job analysis is to update the existing DCO, no drastic changes occur within the DCO unless the whole focus/purpose of the certification has changed.

Clement has made an accurate observation on the list of references provided in the two versions of the CIBs. Yes, they are identical (almost) as he mentioned. Since (ISC)2 updates the reference list periodically in the CIB for each credential, the 2009 version of the CISSP CIB was updated the in May 2011. That is the reason a CIB that was developed in 2009 has a list of references some of which were published in 2010 and 2011. However, the reference list will continue to be updated regularly for the 2012 version of the CIB. Finally, regarding his comments about the sample questions, he makes a valid point that (ISC)2 should update the sample questions to reflect the current content. However, the important thing candidates should understand is that these sample questions are not meant to teach the content of the test or even be representative of the content; they are used merely as an example of the item format used in the examination.

I hope these are helpful clarifications and, again, we want to thank Clement for his insight and support of (ISC)2 and the certifications we have earned.

"

(Read More... | OSG NEWS | Score: 0)


ISC2 will release a new version of the CBK as of January 2012
Posted by boss on Tuesday, 12 July 2011 @ 23:26:33 EDT (3209 reads)
Topic ISC2 Org

cdupuis writes "

Good day to all,

Lately I have been received a lot of inquiries from members of the site about the announcement from ISC2 of a new CBK that will be released on January 2012.   Of course many are wondering if this will severely affect them, are the resources they are currently using still valid,  many are wondering if they should stop their studies and wait for this new and improve CBK, or what exactly is in stock as far as changes are concerned.  Do not get over excited, there is little to worry about this new CBK that was announced.

Over the past twelve years I have lived through many such updates, every time I was expecting the spanking new CBK with the latest and greatest security issues being covered but most of the time the update would turn out to be only changes in the domains names, subjects being moved from one domain to another, and very minor changes made to the actual content of the CBK.  This update seems to be no different looking at the present and future Candidate Information Bulleting (CIB) that was released by ISC2 which contains the current CIB and the future one to be used in January of 2012.  A grand total of 66 pages alltogether.

I have read through this new CIB and compared it with the current one.   I will give you a resume below of my findings and what is new and in some case whast has not changed at all unfortunately.

NEW DOMAIN NAMES

There are only two domains that have changes in their names:

Application Development Security will  now be called Software Development Security

Operations Security is now called Security Operations

As you can see those are VERY minor changes where only one word has been changed and for the second domain they simply flip flop two words. 

You will not be lost with new names for the domains, they are basically the same except for those two chanes.


INTRODUCTION PAGE TO THE CIB

The introduction page had very little changes done.  In fact they mostly made it more precise and they used words that better represent information security instead of generic word  that used to be within the text.

An intro paragraph was added to define what is the CISSP and as such what it provides and some of the key topics that are included within the CBK.  On this page you find that most of the changes were made within the description of WHAT IS PROFESSIONAL EXPERIENCE.

There are bullets that were redundants that have been combined together.
They replace "Creative Writing" with "Professional Writing"
They changed "Applicable titles" to say "Applicable Job Titles"
They remove the title "Officer" and replaced it with "CISO"
They replaced "Engineer" with "Information Assurance Engineer"
Titles such as Leader and Designer have been removed
The title Cryptographer is now replacing Cryptologist and Cryptanalysis
The title Architect was replaced by "Cyber Architect"
The titles of Consultant, Salesman, Representative were all removed from the list of Titles
The title of Lecturer was added to the list of applicable titles

POSITIVE ENFORCEMENT

In most of the domain the text would says the candidate should understand which has been replaced by "is expected" which clearly tells the candidate that he has to know and not only that he should know.  This is a clear distinction within the text of the new CBK.

DOMAIN 1 - ACCESS CONTROL

The introduction portion was modified to better describe what falls into this domain.  There is only one new area of knowledge that was added to this domain with a few sub-topics added to old subjects to better describe what they are.

Under Understanding Access Control Attack the following sub-bullets were added:

B.1 Threat Modeling
B.2 Asset Valuation
B.3 Vulnerability Analysis
B.4 Access Aggregation 

Under Assess Effectiveness of Access Controls the following was added:

C.1 User Entitlement
C.2 Access Review & Audit

A new bullet was added to this domain:

D. Identify and Access Provisioning lifecycle (e.g. provisioning, review, revocation)

The changes in this domain are very minimal.  Overall changes is by my estimate less than 1% of the current CIB content.  Mostly there is nothing new that was not already covered in the old CBK.

DOMAIN 2 - TELECOMMUNICATION AND NETWORK SECURITY

The text portion describing this domain has been greatly reduced.  The text portion used to be mostly a repeats of the topics listed under the text explanations.   The introduction no longer mentions anything about Firewalls, VOIP, Detecting Network Based attacks.  It was also noted the subject of Establish Secure Data Communications was removed as well.

Here are some of the changes in this domain:

A.3 Implications of Multi-Layer protocols was added

B.1 Wireless Access Points was added to the list of hardware devices

B.3 The term Filtering Devices is now replace with the new buzzword Network Access Control (NAC) devices

C.1 VOIP was replaced by simply the term Voice with examples such as POTS, PBX, and VOIP

C.3 Under Remote Access the following examples were added: screen scraper, virtual application/desktop, telecommuting

D.  Under Understand Network Attacks the following examples were added:  DDos, Spoofing

Overall this is another domain with only about 1% of changes being introduced.

DOMAIN 3 - INFORMATION SECURITY GOVERNANCE & RISK MANAGEMENT

This domain has some new bullets that were added but no real major changes overall.

B.1 Under organizational Processes some example were added:  Acquisition, Divestitures, Governance Committees

B.2 Used to be Define Security Roles and Responsibilities is now Security Roles and Responsibilities, the word define has been removed at the beginning.

E.  A new topic was added called:  Manage the information life cycles with the following examples:  classification, categorization, and ownership.  It is a new bullet but all subjects that were already covered.

F. A new topic called: Manage Third Party governance was added with the following examples: On-site assessment, document exchange and review, process/policy review.

Under risk assessment they added Qualitative, Quantitative, and Hybrid risk assessments. 

Under Manage Personel Security they added the following examples: reference checks, education verification.

For some strange reason it seems they removed Background Check from employee management???

ETHICS has been completely removed from this domain and moved back into the legal domain where it used to be a few years ago :-)

Now the CBK says Manage Personel Security instead of Evaluate Personel Security.

Overall about 1% of this domain was changed at the most.

DOMAIN 4 - SOFTWARE DEVELOPMENT SECURITY

The text description of this domain was slightly changed.

The biggest change is the replacement of the word APPLICATION by the work SOFTWARE everywhere within this domain.  That makes it a more generic domain where any type of coding and development could apply.

A.1 Development Life Cycle is now used instead of Software Development Life Cycle (SDLC)

The topic of risk analysis was removed in the list of topics.  However it still remain one of the major activity that would be done within software development. I am not sure WHY it was removed.

Under issues in source code two new examples were added:  escalation of privilege and Backdoor

The following was removed: C&A, Audit & logging, and Corrective Actions

Other than word being changed to new words, there was almost no changes to this domain.  Only topics have been removed which makes the list even shorter for this domain.

DOMAIN 5 - CRYPTOGRAPHY

The text portion was changed to better define what cryptography is and how it is done.  It used to be describe as a disguise method,  now they are presenting it as applying mathematical algorithms and data transformation to information which is a lot more accurate and better describes what cryptography really is.   Within the text they added a few lines on PKI and Key Management,  those subjects were already being covered but not listed in the text description.  

A new topic was added:

B. Understanding the Cryptography Life Cycle with the following examples: cryptography limitations, algorithm, protocol governance.     Those topics are NOT new to the CBK.  They already existed in the old CBK.

The following examples of brute force were added:  rainbow tables, specialized/scalable architecture

The topic of Employ Cryptography to maintain network security was replaced by Use Cryptography to maintain network security

The topic Use Cryptography to maintain Email Security has been replaced by Use Cryptography to maintain Application Security.   The word application in this case was NOT replace by Software like elsewhere in the CBK.

This is all for Cryptography,  overall a bit of semantic like the other domains but nothing really new in this domain.

DOMAIN 6 - SECURITY ARCHITECTURE & DESIGN

The initial text for this domain was greatly improved.  However the content has almost nothing changed except a few subjects that I was glad to see added to this domain.

A reference to OWASP was added under vulnerabilities and Threats. 

The topic of Cloud Computing, Grid Computing, and Peer to Peer was added to this domain.  I think it is about time considering the level of usage and the trend regarding virtualization and cloud computing.  Finally some of the current concerns are being added.

Overall I would say about 1 to 2% was added to this domain if the instructor or your training company takes the time to really explain what is cloud computing, what services it can provides, and what are the security issue. 

Of course many people will cover this in one slide and get it over with, in such case less than 1% would be added.

DOMAIN 7 - SECURITY OPERATIONS

The text describing this domain was improved but the topic list is almost verbatim.

The subject of Personel  Privacy and Safety was completely removed.

On the last topic they added System Resilience to Fault Tolerance requirements.

Overall zero percent of changes in this domain.  It is the same as the old one except the name where the words were turned around. 

DOMAIN 8 - BCP and DRP

In the text describing the domain they changed Business Impact Assessment to the proper term of Business Impact Analysis (BIA)

As mention previously they change the candidate will be expected to know to clearly state the candidate is expected to know

Nothing has changed within the topics of this domain except the last bullet which used to say Test & Update the plan which has been changed to Exercise, Assess, and Maintain the plan with the examples of Version Control, Distribution

Overall no  changes within this domain.

DOMAIN 9 - LEGAL, REGULATIONS, INVESTIGATION, AND COMPLIANCE

The text describing this domain has changed quite a bit.  Incident Handling has been removed from the text.  They added Ethical Behavior to the text because Ethics is now back within this domain.  The description no longer talks about laws, Computer Crimes, and Regulations. 

As mentioned already the subject of ethics has been added to this domain where it really belongs.  It lists specifically the ISC2 code of ethics and organizations code of ethics which needs to be supported.

Of note is the subject of Advanced Persistent Threats which is a really nice way of describing attacks that many people do not understand.  The candidate needs to understand how to identify Advanced Persistent Threats.  Another up to date subject added to the CBK without any details.

Under forensics they added the subject of Hardware/Embedded Devices forensics

Finally they added:

F. Ensure security in contractual  agreements and procurement processes and they list as examples:  cloud computing, outsourcing, vendor governance

DOMAIN 10 - PHYSICAL (ENVIRONMENTAL) SECURITY

The description for this domain was expanded by a few lines.

A few examples were added to the topics.

The acronym HVAC is now spelled out.

The topic of Personal privacy and Safety which was removed in a previous domain is now within Physical Security.

This is all.  So no new content but only a bit of content from another domain.

Overall mostly no changes for this domain.

LIST OF REFERENCES

Something is definitively wrong with the list of reference.   The list is a carbon copy of the 2009 list less once book from Doctor McGraw on Software Security.   A book which is by the way still applicable and good for todays issues.

I cannot believe that between 2009 and now there was no references added to the list of reference. 

Either ISC2 has not added any questions to the CBK using new references or the list has not been maintained.

Only a few of the references are 2010 and most of them are very old.

This does not seem right to me considering that new questions are being added all the time to the exam.

Very bizarre.....

SAMPLE QUESTIONS (Ouch!)

There are 3 sample questions presented.  Just like the list of references it seems they are getting dated in at least 33.3% percent of them.  

Question number 3 is about the usage of SSL under WAP.  The question does not specify which version of WAP.

WAP 2.0 was release around 2002,  it no longer required a WAP gateway.  It is amazing to see that this questions is still being used as an example.  The question is dated and no longer valid today.  Modern Handset mostly no longer use WAP at all.

This is very disappointing to see this was there in 2009 almost 7 years after it WAP 1.0 was no longer use and it is still there today 10 years after WAP 1.0 is no longer in use.

I think it is REALLY time to retire this question and come up with a better sample question.

EXAMINATION INFORMATION

There is nothing changed withing the examination information.  They only changed the end time to exam,  it used to say 3 PM for the CISSP but now they simply state the exam will be 6 hours long.   They no longer take for granted that exams all start exactly at 9 AM.

DISAPPOINTMENT

The CIB is still lacking as far as details are concerned.  The CIB initially used to have a LOT of details about the sub-topics under each of the domains subjects.  

More details would better guide any students wanting to become a CISSP.   ISC2 should at least as a minimum specific what percentage of the exam is within each of the ten domains.  CompTIA does this for their certifications.  It is not some type of secret.  What good is a CBK if it is some type of secret?

CONCLUSION

This is not what I would call an update.  As mentioned above there is at the most 2 to 3% of new material added.  I have not seen anything specific to IP Version 6,  thorough coverage of Cloud Computing and Virtualization,  DNSSEC, BGPSEC, Internal threats, Remote Access Trojan, new social engineering techniques, skimming, vishing, and other projects that have all been fielded to improve security.

Overall this is very disappointing  and mostly what I would called statu quo. 

Best regards to all

Clement

 

 

"

(Read More... | Score: 5)


FREE CPE'S for Military Members
Posted by boss on Saturday, 20 November 2010 @ 16:57:34 EST (2529 reads)
Topic ISC2 Org

cdupuis writes "

NOTE FROM CLEMENT:

One of my student made me aware in class this week of a great resource where military members can achieve CPE's for free.  See his message below:

Hello Clement!!

I just found a great link that will give any CISSP 40 CPE credits.

Check it out!

https://ia.signal.army.mil/courses.asp

David Christie (CISSP class NOV 15-19)

"

(Read More... | Score: 0)


Re: Corrected (ISC)2 Examination Results ISC2
Posted by boss on Wednesday, 17 November 2010 @ 20:37:04 EST (2225 reads)
Topic ISC2 Org

cdupuis writes "

This morning I received a message from a site member that was really unique and totally unexpected. 

This member was telling me that he was notified three weeks ago that he FAILED the exam.  Today he received a message from ISC2 advising him that he PASSED the exam.  Go figure....

A bit later in the day I received another message that was even more amazing.  It is a person who was told that he PASSED the exam but now he is being notified that really he FAILED the exam.  His endorsement form has already been submitted.  How can an organization make such a mistake which will very negatively affect this member in both his personal and professional life.  This is unacceptable to play with people`s feeling in such a way.   The ISC2 message talks about a Quality Assurance review.   For sure there has been something that went REALLY wrong somewhere and all this leaves you wondering about whether or not other exams were not graded properly.

See sample of the notificaiton messages below:

====  HERE IS THE WE TOLD YOU THAT YOU FAILED BUT REALLY YOU PASSED MESSAGE ======

From: "(ISC)2 Customer Support"
Subject: Corrected (ISC)2 Examination Results ISC2
Date: Wednesday, November 17, 2010 1:17 AM

During a quality assurance review, (ISC)2 discovered a technical error with your recent examination results. During this review, your
examination was re-graded and we are happy to advise you that you have passed the examination.

Your updated results will arrive shortly in a separate email. We apologize for this error and any concern it may have caused in the
meantime. If you have an active registration to take the exam again please contact registration@isc2.org and the registrations team will
process your refund. We look forward to having you as a member.

Sincerely,

(ISC)2


====  HERE IS THE WE TOLD YOU THAT YOU PASSED BUT REALLY YOU FAILED MESSAGE ======

 

During a quality assurance review, (ISC)2 discovered a technical error with your recent examination results. During this review, your examination was re-graded. We are sorry to inform you that the corrected results indicate you did not successfully pass the examination. Now that the problem has been identified and the data has been corrected, in order to maintain the integrity of our credentials, we will not be able to allow your passing grade to stand.

We are offering a full refund of the exam fee you previously paid OR the opportunity to retake the exam within 1 calendar year at no charge. Please call Customer Support at 727-785-0189 menu choice 5 to begin the reimbursement process receive or discuss registering for an upcoming exam at no cost.

If you have an endorsement on file, we will keep it on file until such time as you do retake and pass the examination. You will not be required to resend your paperwork.

Your updated examination results will arrive shortly in a separate email. We apologize for this error and any concern this has caused.


Sincerely,


(ISC)2

 

===========  End of we told you that you passed but really you failed message ========

 

You are certified, no you are not.   Am I really or maybe I am not.  Who should I believe?

 

Very bizarre

 

Clement

 

 

"

(Read More... | Score: 0)


ISC2 first exam to be delivered by VUE testing
Posted by boss on Wednesday, 07 April 2010 @ 15:48:19 EDT (1831 reads)
Topic ISC2 Org

cdupuis writes "

Dear Valued Member,

We are proud to announce the availability of Computer-Based Testing (CBT) for the Certified Secure Software Lifecycle Professional (CSSLP) credential.

The CSSLP aims to stem the proliferation of software vulnerabilities by establishing best practices and validating an individual's competency in addressing security issues throughout the software lifecycle. Code-language neutral, it is applicable to analysts, developers, software engineers, software architects, project managers, software quality assurance testers, programmers and others involved in the software lifecycle.  For information on experience and other requirements to sit for the exam, please visit: www.isc2.org/csslp.

The CSSLP is the first (ISC)2 certification exam to make the transition from paper-and-pencil delivery and will be available at nearly 500 Pearson Professional Centers, Pearson VUE Authorized Test Center Selects and Pearson VUE Authorized Test Centers located on U.S. military installations around the world.

(ISC)2 will gradually phase in computer-based testing for all of its credential exams over the next three years. This decision was made based on the projected growth for the profession worldwide, which the most recent (ISC)2 Global Workforce Study ("GISWS") http://www.isc2.org/workforcestudy forecasted would increase to almost 2.7 million by 2012, representing a compound annual growth rate (CAGR) of 10 percent.
CBT also gives us the ability to enhance the convenience, security and fairness of the examination process.

Pearson VUE is the global leader in computer-based testing for information technology, academic, government and professional testing programs. To experience a demonstration and tutorial of the Pearson VUE's computer-based testing experience, please visit http://www.pearsonvue.com/ppc/

.

For more information about or to register for computer-based testing for the CSSLP, please review the frequently asked questions (FAQs) at: http://www.isc2.org/csslp-cbt-faqs.aspx. To review a Candidate Information Bulletin offering details about the exam process, please visit http://www.isc2.org/uploadedFiles/Downloads/CSSLP-CBT-Candidate-Information-Bulletin.pdf.

Our transition to CBT is an exciting opportunity for our candidates and a milestone for our credential programs! As always, we thank you for your support of this investment in (ISC)2's future.

Sincerely,

(ISC)2 Management
"

(Read More... | Score: 0)


ISC2 is looking for proctors for the Orlando 3/20/2010 exam
Posted by boss on Thursday, 18 March 2010 @ 16:35:14 EDT (2691 reads)
Topic ISC2 Org

cdupuis writes "

Greetings,

I am very sorry for the short notice but I am still looking for proctors for an examination in Orlando, FL on 3-20-10 Saturday. You will earn eight (8) Type A CPE credits and have mileage and parking reimbursed. The proctoring opportunity will run onsite from 7:30 am to 3:30-4:00 pm or until the candidates for the exam are finished which ever is first.

Typical responsibilities involve checking room set-up, assisting in check-in as candidates arrive, distributing exam booklets, monitoring the examination room and assisting in post-exam routines.

Expense Restrictions:

1. We reimburse $.50 per mile with a maximum of 100 > round-trip miles (currently valued at $50.00) may be reimbursed for transportation to and from the examination site.

2. Meal reimbursement must obtain receipts: allowance for breakfast is $15.00, lunch is $20.00 unless you are getting something at the hotel where exam is being held. If a receipt is not attached to the expense sheet it WILL NOT be reimbursed.

3. No reimbursement may be made for overnight accommodations at or near the examination site.

* Please note for a period of six (6) months after proctoring one shall not, instruct, advise, direct, or assist in the preparation of any seminar, study group, training class, or training material that prepares others to sit for any (ISC)2 examination. 

Please let me know as soon as possible and I will confirm by sending you the location.

Thank you,

Mary Minshall

(ISC)2 Services

888-333-4458 ext. 2150

727-738-8522 fax

mminshall@isc2.org

"

(Read More... | Score: 0)


For CISSP's: ISC2 launched InterSeC, its very own professional networking
Posted by boss on Thursday, 10 December 2009 @ 14:25:38 EST (2521 reads)
Topic ISC2 Org

cdupuis writes "

Dear Valued Member,

(ISC)2 launched InterSeC, its very own professional networking site on September 22, 2009! Since then, over 1,600 members have joined to network with other (ISC)2 members around the globe. It's a great tool for finding other information security professionals who share your interests, while facilitating discussion and interaction.

To enjoy this new member benefit, you can join InterSeC by visiting the member home page (http://members.isc2.org) and clicking on the InterSeC logo on the upper right-hand side.

InterSeC allows you to connect with members like never before!

Groups:
Join one of the 38 groups already started on InterSeC.  You can also start your own group. Start discussions, create postings, and upload files.

Wiki:
Use this as a collaboration hub for discussions and materials on topical issues, such as best practices. Start your own discussion page on a certain topic, while linking to materials such as presentations, articles, etc. You have the control to make it a public page for all to view and edit, or as a private page for only select members of the InterSeC community.

Blog:
Share your ideas by starting your own blog. Also, view other InterSeC blogs and contribute by posting comments.

People Map:
This unique feature matches you with other InterSeC users based on similar interests. You can find this tool under 'Search Members' on the left navigation bar.

We hope that you enjoy this new way to interact with other (ISC)2 members around the world!


Sincerely,

(ISC)2 Management

Follow us on Twitter: http://www.twitter.com/isc2.

Please do not reply to this message. For questions or to contact (ISC)2, please visit http://www.isc2.org/contactus.

"

(Read More... | Score: 0)


Number of (ISC)2 credential holders (June 30, 2009)
Posted by duck on Saturday, 01 August 2009 @ 13:03:31 EDT (4069 reads)
Topic ISC2 Org

The following counts reflect the number of members per credential as of June 30, 2009:

 

CAP
Canada 7
India 1
Korea, Republic of 1
United States 588
Viet Nam     1

 

CISSP
(Other) 2
Albania 2
Andorra 1
Angola 1

Antigua and Barbuda   

1
Argentina 81
Australia 1017
Austria 77
Azerbaijan 1
Bahamas 3
Bahrain 28
Bangladesh 1
Barbados 20
Belarus 1
Belgium 284
Belize 1
Bermuda 19
Bolivia 2
Bosnia and Herzegowina 4
Botswana 3
Brazil 249
Brunei Darussalam 1
Bulgaria 17
Cambodia 1
Cameroon 1
Canada 3,383
Cayman Islands 12
Chile 69
China 431
Colombia 65
Costa Rica 5
Croatia (Hrvatska) 34
Cuba 1
Cyprus 10
Czech Republic 48
Denmark 268
Dominican Republic 4
Ecuador 4
Egypt 54
El Salvador 3
Estonia 6
Faroe Islands 1
Fiji 1
Finland 291
France 483
France, Metropolitan 3
French Polynesia 1
Georgia 1
Germany 730
Ghana 6
Georgia 1
Gibraltar 3
Greece 70
Guam 4
Guatemala 11
Haiti 1
Honduras 1
Hong Kong 1,258
Hungary 61
Iceland 4
India 1065
Indonesia 65
Iran (Islamic Republic of) 3
Iraq 4
Ireland 253
Israel 174
Italy 222
Jamaica 15
Japan 1145
Jordan 22
Kazakhstan 4
Kenya 12
Korea, Republic of 2,541
Kuwait 38
Latvia 7
Lebanon 11
Liechtenstein 1
Lithuania 9
Luxembourg 37
Macau 14
Macedonia, the former Yugoslav Republic of 6
Malaysia 213
Malta 7
Mauritius 15
Mexico 245
Morocco 1
Nepal     1
Netherlands 959
Netherlands Antilles 4
New Zealand 138
Nigeria 108
Norway 106
Oman 10
Pakistan 88
Panama 11
Peru 11
Philippines 61
Poland 153
Portugal 39
Puerto Rico 16
Qatar 36
Romania 42
Russian Federation 134
Saint Lucia 1
Saudi Arabia 175
Senegal 3
Serbia 6
Singapore 992
Slovakia (Slovak Republic) 22
Slovenia 16
South Africa 267
Spain 374
Sri Lanka 51
Sweden 318
Switzerland 447
Taiwan, Republic of China 224
Tanzania, United Republic of 1
Thailand 106
Togo 1
Trinidad and Tobago 26
Tunisia 6
Turkey 87
Turks and Caicos Islands 1
Uganda 2
Ukraine 16
United Arab Emirates 277
United Kingdom 3,209
United States 39,255
Uruguay 20
Venezuela 11
Viet Nam 10
Virgin Islands (U.S.) 2
Yemen 1
Zambia 2
Zimbabwe 3

 

CSSLP
Argentina 2
Australia 11
Austria 5
Belgium 2
Brazil 8
Canada 49
China 1
Denmark 1
Egypt     1
Finland 10
France 3
Germany 11
Greece 1
Hong Kong 14
India 18
Iran (Islamic Republic of) 2
Ireland 1
Israel 1
Italy 4
Japan 2
Jordan 1
Korea, Republic of 3
Luxembourg 1
Malaysia 3
Mexico 1
Netherlands 3
Norway 1
Pakistan 1
Peru 1
Philippines 2
Puerto Rico 1
Saudi Arabia 1
Singapore 11
South Africa 6
Sweden 5
Switzerland 4
Taiwan 1
Thailand 3
Turkey 4
United Arab Emirates 5
United Kingdom 19
United States 561

 

Fellow
Australia 1
Korea, Republic of 1
United States 18

 

ISSAP
Argentina       1
Australia 16
Austria 1
Belgium 2
Brazil 4
Canada 55
Cayman Islands 1
China 1
Croatia (local name: Hrvatska) 1
Finland 3
France 3
Germany 12
Greece 1
Hong Kong 17
India 5
Indonesia 1
Ireland 3
Israel 3
Italy 5
Japan 4
Korea, Republic of 2
Mexico 5
Netherlands 31
New Zealand 2
Nigeria 1
Norway 2
Poland 1
Qatar 1
Russian Federation 1
Saudi Arabia 1
Singapore 6
South Africa 3
Sweden 3
Switzerland 8
Taiwan, Republic of China 4
Thailand 1
Ukraine 2
United Arab Emirates 4
United Kingdom 42
United States 589

 

ISSEP
Canada 9
Germany 4
Hong Kong 1
India 2
Korea, Republic of 1
Netherlands 1
Nigeria 1
Switzerland 1
Thailand 1
United States 515

 

ISSJP
Japan 50

 

ISSMP
Australia 9
Austria 1
Belgium 1
Bermuda 1
Brazil 1
Canada 41
Croatia (local name: Hrvatska) 1
Czech Republic     1
Denmark 1
Finland 2
France 1
Germany 4
Greece 1
Hong Kong 18
India 4
Ireland 2
Israel 1
Italy 1
Japan 3
Kenya 1
Korea, Republic of 1
Lebanon 1
Malaysia 2
Netherlands 10
New Zealand 1
Nigeria 1
Oman 2
Pakistan 1
Portugal 1
Puerto Rico 1
Russian Federation 1
Saudi Arabia 1
Singapore 7
South Africa 2
Spain 3
Sweden 4
Switzerland 6
Taiwan, Republic of China 3
Turkey 1
United Kingdom 24
United States 52

 

SSCP
Australia 18
Austria 4
Belgium 3
Bermuda 1
Brazil 4
Cambodia 1
Canada 62
Caymen Islands 4
Chile 3
China 2
Cyprus 1
Denmark 5
Egypt 2
Finland 2
Germany 9
Greece 4
Hong Kong 5
India 26
Ireland 11
Israel 1
Italy 1
Japan 3
Jordan 1
Luxembourg 1
Korea, Republic of 3
Luxembourg 1
Malaysia 10
Malta 1
Mexico 3
Netherlands 13
New Zealand 1
Norway 4
Poland 5
Romania 3
Russian Federation 1
Saudi Arabia 7
Singapore 10
Slovakia (Slovak Republic) 1
South Africa 3
Spain 6
Sri Lanka 1
Sweden 2
Switzerland 2
Taiwan, Republic of China 10
Thailand 6
Turkey 3
United Arab Emirates 3
United Kingdom 52
United States 632
Uruguay 1
Venezuela 1

(Read More... | 20327 bytes more | Score: 0)


CSSLP Certification - Opening of Exam And Class Registration
Posted by boss on Thursday, 23 April 2009 @ 12:56:10 EDT (3523 reads)
Topic ISC2 Org

prakashp writes "

The CSSLP aims to stem the proliferation of security vulnerabilities resulting from insufficient development processes by establishing best practices and validating an individual’s competency in addressing security issues throughout the software lifecycle (SLC). Code-language neutral, it will be applicable to those involved in the SLC, including analysts, developers, software engineers, software architects, project managers, software quality assurance testers and programmers.

To be eligible for the certification, CSSLP candidates must demonstrate four years of professional experience in the SLC process or three years of experience and a bachelor’s degree (or regional equivalent) in an IT discipline.

It covers seven domains:

    * Secure Software Concepts - security implications in software development
    * Secure Software Requirements - capturing security requirements
    * Secure Software Design - translating security requirements into application
    * Secure Software Implementation/Coding - unit testing for security functionality and resiliency to attack, and developing secure code and exploit mitigation
    * Secure Software Testing - integrated QA testing for security functionality
    * Software Acceptance - security implication in the software acceptance phase
    * Software Deployment, Operations, Maintenance and Disposal - security issues around steady state operations and management of software

The first open exams will be offered beginning June 30, 2009

For more information on the CSSLP, You can visit www.isc2.org/csslp

Visit our CSSLP forums at:  http://www.cccure.org/forum-c19.html

"

(Read More... | Score: 0)


Recommended Training

Login here

Nickname

Password

Security Code:
Security Code
Type Security Code

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.

CCCure Partners

BRAZIL


Logical IT

Best Security Training in Brazil

São Paulo
Rio de Janeiro
Belo Horizonte
Fortaleza
Brasilia


USA


SecureNinja.Com

SecureNinja Dojo


CANADA


360 Security Experts

CISSP Montreal
CISSP Ottawa
CISSP Toronto
CISSP Quebec City
CISSP Vancouver
CISSP Winnipeg


MIDDLE EAST


CISSP Dubai
CISSP Abu Dhabi
CISSP Qatar
CISSP Kuwait
CISSP Oman

THE OISSG GROUP
The OISSG serving the Middle East security needs


EUROPEAN UNION


CISSP Dublin, Ireland
CISSP London, UK
ESPION

Best security training you can get in Ireland


AFRICA


Lagos, Nigeria
CISSP and Security Training
Digital Encode


The best security training in Lagos and Nigeria

----------------------------
Cameroon

Security Training
CISSP, CEH, Security+

GETSEC

Best Security Training in Cameroon

Most Active Members

· 1: side_winder
Total points: 15336
· 2: webplu9
Total points: 15228
· 3: Lopezco
Total points: 8514
· 4: cissp_newbie
Total points: 7593
· 5: cdupuis
Total points: 7381
· 6: mikeyoung_fla
Total points: 5526
· 7: Vladimir
Total points: 4611
· 8: damoose
Total points: 3374
· 9: MMM
Total points: 2969
· 10: educk
Total points: 2553

Today's Big Story

There isn't a Biggest Story for Today, yet.

Past Articles


All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2007 by CCCure.Org, and the site maintainers Clement Dupuis and Nathalie Lambert. Reuse is strictly prohibited without written permission of CCCure.Org or it's maintainers.

This web site is not associated directly or indirectly with ISC2, the SANS Institute, ISACA, or other certification authority. The GCFW, CISSP, SSCP, ISSEP, ISSMP, CISA, and CISM are all the property of their respecful owners. The content of this site is provided to you freely due to the generosity of our sponsors.


  • Career
  • Magazines
  • Conferences
  • Study Books
  • Certifications
  • Training
  • Tutorials
  • Quizzes
  • Forums

  • Page Generation: 0.73 Seconds