Looking for some learning plan guidence.
-
I'm looking for a little guidance on how I might approach a career change to cyber security.
I've been managing the IT and technology for a medium sized manufacturing company for the past 25 years. I took care of everything from infrastructure and servers to machine tool controls and phone systems. The later part learning about and bringing my environment into compliance with NIST 800-171. Not only the IT side, but facility security, HR, etc.. We should be OSC for CMMC by the end of this year. After that I want to shift gears and help small businesses in the DIB realize compliance. To many small family run shops I have run into who are giving up and selling out instead of suffering through compliance. That's not good.
I started the CISSP program with the intention of translating the last 10 years into the current lingo. I then joined ISC2 and shifted gears to SSCP first. I'm starting my third section of that on Monday. But now I am starting to question my path. Is the ISC2 route the best route for me?
-
The area you seem to be looking for would be more in the realm of GRC (Governance Risk, and Compliance). Though you will get introductions to this area from just about every vendor certification. It will depend on the level of depth you desire. With ISC2, CISSP, this focus is more on management of security in the IT space and SCCP does go into more depth about managing security within systems. Neither is easy and requires much study and expense.
ISACA also has the CRISC certification. Again, more aligned with your stated goals. We offer you a chance to look at all three within our site and compare which may be the path you choose to walk down.