Certification and Accreditation Professional

Certification and Accreditation Professional (CAP) is a vendor-neutral Information Security certification governed by the non-profit International Information Systems Security Certification Consortium (commonly known as ISC2).

Certification Subject Matter

The Certification and Accreditation Professional credential is an objective measure of the knowledge, skills and abilities required for personnel involved in the process of certifying and accrediting security of information systems. Specifically, this credential applies to those responsible for formalizing processes used to assess risk and establish security requirements. Their decisions will ensure that information systems possess security commensurate with the level of exposure to potential risk, as well as damage to assets or individuals.

The credential is appropriate for civilian, state and local governments in the U.S., as well as commercial markets. Job functions such as authorization officials, system owners, information owners, information system security officers, and certifiers as well as all senior system managers apply.

CAP Common Body of Knowledge domains

The CAP certification covers a wide range of subject matter in a variety of Information Security topics. The CAP examination is based on five domains taken from the (ISC)² Common Body of Knowledge (CBK), which are generally accepted as a compendium of industry best practices for information security. The 5 domains covered by the CAP are:

  • Understanding the Purpose of Certification
  • Initiation of the System Authorization Process
  • Certification Phase
  • Accreditation Phase
  • Continuous Monitoring Phase

ANSI/ISO/IEC Standard 17024

The CAP, like all of (ISC)2’s core credentials, have been accredited by the International Organization for Standardizations (ISO) United States representative, the American National Standards Institute (ANSI) under ANSI ISO/IEC Standard 17024, a national and global benchmark for the certification of personnel.

Requirements

Candidates for the CAP must meet several requirements:

  • Assert that he or she possesses a minimum of two years of professional experience in the information systems security certification and accreditation field
  • Attest to the truth of their assertions regarding professional experience and accept the(ISC)2 Code of Ethics.
  • Successfully answer four questions regarding criminal history and related background
  • Pass the CAP examination with a scaled score of 700 points or greater
  • Have their qualifications endorsed by another (ISC)2 certified professional in good standing. The endorser attests that the candidate's assertions regarding professional experience are true to the best of their knowledge, and that the candidate is in good standing within the information security industry.

Ongoing Certification

The CAP credential is valid for only three years, after which it must be renewed. The credential can be renewed by re-taking the exam, however the more common method is to report at least 60 Continuing Professional Education (CPE) credits since the previous renewal. Currently, to maintain the CAP certification, a member is required to earn and submit a total of 60 CPEs by the end of their three-year certification cycle and pay the Annual Membership Fee of $65 during each year of the three-year certification cycle before the annual anniversary date. With the new changes effective 30 April 2008, CAPs are required to earn and post a minimum of 10 CPEs (of the 60 CPE certification cycle total requirement) and pay the AMF of $65 during each year of the three-year certification cycle before the member’s certification or recertification annual anniversary date.

CPEs can be earned through several paths, including taking classes, attending conferences and seminars, teaching others, undertaking volunteer work, professional writing, etc., all in areas covered by the CBK. Most activities earn 1 CPE for each hour of time spent, however preparing (but not delivering) training for others is weighted at 4 CPEs/hour, published articles are worth 10 CPEs, and published books 40 CPEs.

Education

(ISC)2 offers Official CBK Review Seminars around the world designed to provide prospective candidates with information across all domains covered by the CAP exam.

See Also

  • Certified Information Systems Security Professional (CISSP )
  • Information Systems Security Architecture Professional (ISSAP)
  • Information Systems Security Management Professional (ISSMP)
  • Information Systems Security Engineering Professional (ISSEP)
  • Systems Security Certified Practitioner (SSCP)
  • Certified Secure Software Lifecycle Professional (CSSLP)

es:Certification and Accreditation Professional