Security Basics mailing list archives

Some Facts - Was CISSP


From: "Craig Wright" <Craig.Wright () bdo com au>
Date: Tue, 15 May 2007 10:53:35 +1000

Hello James,
This is an attempt to explain a few concepts calmly. First I did not
attack you personally and you seem to assume that exasperation is an
attack, so be it.

As for the question, "how do they justify the cost of the test", this is
in my side of the argument a "point of view" as you state. It is not a
"truth" that is subject to rhetorical indecision. It is something that
is derived from numerical fact.

ISC2 (the organisation that issues the CISSP) is a non-profit firm. This
means that it does not make a profit. It does not as was stated pay
taxes as taxes are paid on profit and not turnover. You ask "what
expenditures are there?". Well I receive a copy with my members
statement. I am not going to scan and attach it, as ISC2 for a copy.
They have a link on their site for requests such as this.

It is easy to not understand economic theory and of course blame greed.
If in fact an organisation is making huge sums of money, they attract
competition.

I paid the fees for the CISSP and I yearly pay the membership fees. I
also pay ISACA, ACS IEEE and about half a dozen other IT organisations
and I do not ask for my employer to give me anything for this. ISC2 is
one of the less expensive ones. 

Basically the answer is easy. They make on profit. They are a non-profit
organisation. They on average spend all the money they make. As such,
there is not a large incentive for greed.

Your ISC2 certification and membership fees also make a newsletter,
conferences, promotions and other things in over 100 countries. Please
think about this. When looking at the amount, think of how many
countries and what they do. 

It is easy to sit back and critisise. Before doing this take some time
to get the facts. This list is not the place to get financial figures.
Ask ISC2. If you feel that they make so much money, it should be easy
for you to raise venture capital to start your own. 

Regards,
Craig

As a disclaimer, I am not being paid by ISC2 or getting any befits to
defend them - not have I been asked. This is not a response based on
greed or hubris, but rather common sense and a desire to see rational
thought.

Craig Wright
Manager of Information Systems

Direct +61 2 9286 5497
Craig.Wright () bdo com au
+61 417 683 914

BDO Kendalls (NSW)
Level 19, 2 Market Street Sydney NSW 2000
GPO BOX 2551 Sydney NSW 2001
Fax +61 2 9993 9497
www.bdo.com.au

Liability limited by a scheme approved under Professional Standards Legislation in respect of matters arising within 
those States and Territories of Australia where such legislation exists.

The information in this email and any attachments is confidential.  If you are not the named addressee you must not 
read, print, copy, distribute, or use in any way this transmission or any information it contains.  If you have 
received this message in error, please notify the sender by return email, destroy all copies and delete it from your 
system. 

Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls.  
You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or 
Director of BDO Kendalls.  It is your responsibility to scan this communication and any files attached for computer 
viruses and other defects.  BDO Kendalls does not accept liability for any loss or damage however caused which may 
result from this communication or any files attached.  A full version of the BDO Kendalls disclaimer, and our Privacy 
statement, can be found on the BDO Kendalls website at http://www.bdo.com.au or by emailing administrator () bdo com au.

BDO Kendalls is a national association of separate partnerships and entities.


Current thread: