CISSP and SANS GSEC - Comparing Security Certifications
They are both excellent programs with significant overlap as well as some significant differences. SANS GSEC material is more practically oriented than CISSP. Some comment that CISSP is more managerially or theoretically oriented than GSEC. I’ll comment that CISSP has some bizarre stuff in it! For example, no one cares if something is "Bell Lapadula" or not – not in industry at least. Bell what??? “Bela Lugosi??” – wasn’t he the original movie “Dracula” or "Batman?" (GSEC also mentions Bell Lapadula although very briefly). Most of the material in both programs is very useful.
SANS GSEC training has 10 hours of hands-on training whereas most CISSP programs do not. There is more emphasis on learning "how to do things as compared to knowing things” in SANS GSEC. CISSP requires four years of experience in security whereas SANS GSEC has no such requirement. SANS GSEC certification consists of online exams plus a “practical component.” CISSP certification requires you to report to an authorized test site for a rigorous, and many people say scary, examination.
SANS GSEC training is developed and run by The SANS Institute, who are essentially the GSEC people. I don’t know of any other sources of GSEC training. CISSP training is available from many sources including The International Information Systems Security Certification Consortium, better known as (ISC)2, the CISSP people.CISSP and SANS GSEC training is intrusive! For example the SANS GSEC “Boot Camp” (as it’s often called) is six days long including most evenings. It runs over the weekend and I've never heard anyone complain. CISSP programs tend to be 5+days long as well. Depending on your level of experience, additional study may well be required before taking the certifying exams. It is very possible to get certified without taking training.I can't tell anyone how valuable being CISSP or SANS GSEC certified will be to them. I’ve consulting on Information Security for well over a decade, and none of my clients have ever asked or cared! Others have told me that it’s been invaluable to them. My informal research shows that these certifications are slightly more useful on the East and West Coast of the USA than in the center. In Asia-Pacific, CISSP seems to rule.
That said, the knowledge learned while getting certified is valuable itself. Security is a broad enough field that certainly no one knows everything. Having a certification can't hurt, and sometimes it can help a lot, especially if you are just developing your expertise and experience. What about other security certifications? TruSecure has a TICSA certification aimed at “IT Practitioners.” I was certified as a TICSA Subject Matter Expert at one point, or so TruSecure told me, but apparently they lost my paperwork! A good program, which appears to still exist, even though TruSecure doesn’t exist anymore.
I’ve also heard good things about the CompTIA Security+ certification, but have no experience with it. It seems to be more of an entry level certification than CISSP and GSEC.
SANS and (ISC)2 actually have a number of additonal certifications as well.
There are actually a lot of Certifications out there, but in security, CISSP and SANS GSEC are the biggest by far. I haven't even touched on vendor specific certifications, and there seem to be hundreds of those in the security space.
Disclaimer: I’ve been involved in security and security training for a long time. I occasionally teach security classes for SANS. I’m SANS GSEC certified and may eventually get around to taking the CISSP exam as well. TruSecure was a client of mine while they existed.
Updated - click for new copy here.






