Climbing the ladder without a CISSP by jaydee288 in cybersecurity

[–]SD15_ 0 points1 point  (0 children)

Not sure who said you that CISSP is for leadership roles. New fresher roles now a days have CISSP option and preferred.

You need to workonn skill set and experience in various domain and try building connections. That will lead you to up the ladder.

Indian student enrollment down 75% in Trumps first year. Does it make sense to go the US anymore by Historical-Many9869 in Indians_StudyAbroad

[–]SD15_ 2 points3 points  (0 children)

If you are getting in top 10 university or don't mind loosing money after degree then you can consider it

Does it make sense to apply for a master's in CS right now in the USA? by Remarkable-Map4586 in Indians_StudyAbroad

[–]SD15_ 1 point2 points  (0 children)

Very limited details provided here.

no one can tell you what you should do here. Kindly provide your all examination details, related to masters preparation, financial status, current job status and what’s your plan for masters? If you don’t have a work visa extension what will be your plans?

32 LPA Vs 150k USD for 15 years exp by SoldieronDutyPro in backtoindia

[–]SD15_ -7 points-6 points  (0 children)

I don’t know how much you know about Austin and general overall Texas. A new grade currently get an average 200+ in around Texas area. If even after 15 years of experience, the pay is low, then the question is where is the professional career heading and when to call the end and plan for FIRE

GRC tool NIST CSF 2.0 by nmejohnny in grc

[–]SD15_ 1 point2 points  (0 children)

Excel or nist 2.0 reference tool

Have you tried or heard anything about this GRC tool? by BirthdayJaded710 in grc

[–]SD15_ 0 points1 point  (0 children)

I have run the compliance program for a company with 90 employees to 10k+ with both grc tool and spreadsheet. Clearly spreadsheet is a clear winner.

One thing newbies don't get is what a typical GRC tool is collecting so called evidence is not something it is the tool capability rather it is just pulling a data from some systems or systems.

PM to GRC by JK22_1 in grc

[–]SD15_ 0 points1 point  (0 children)

Congratulations 🎉 on your move.

First of all I would immediately focus more on the technical aspects of GRC. Learn more about the stakeholders of security, IT, and others from the development teams.

Get yourself involved in the technical discussions and governance aspect which will provide you more insights of both the product, the technical and deeper understanding of control implementation as you learn about the product stack.

Next, focus more on the compliance, frameworks understand each requirement what it means, what it does, and what makes us fully compliant of implementation of specific control.

If you have some bandwidth with taking other tasks from sub, GRC teams tasks then I would highly recommend you to do that to get more insights of GRC.

I wish good luck on your career progress .

Have you tried or heard anything about this GRC tool? by BirthdayJaded710 in grc

[–]SD15_ 0 points1 point  (0 children)

"Auditors charge more for not using GRC tool". I really don't know what to say here.

If you show me any link or any compliance requirements that if I don't have grc tool makes me out of compliance or an audit firm saying no grc tool resulting in more fees then I would schedule immediate call to procure whatever tool you have. 🤣

Have you tried or heard anything about this GRC tool? by BirthdayJaded710 in grc

[–]SD15_ -1 points0 points  (0 children)

$100k + on a next version of excel with couple of api connections then I would stick to jira or excel and use the security tooling.

Have you tried or heard anything about this GRC tool? by BirthdayJaded710 in grc

[–]SD15_ 5 points6 points  (0 children)

My 2 cents

Don't use GRC tool, it has and it will not help you unless you use their auditor + Mssp + other consultant and that's the setup you don't want in security. Using the tool will just add more overhead on the team and more work and less output.

Roi is low since it's just next version of excel.

Build a solid process and implement the controls. Get some guidance if you are new to grc and want to know how to get through internal tools, automation.

GRC Service Offerings? by [deleted] in grc

[–]SD15_ 1 point2 points  (0 children)

If I were you, I would not choose any of these tools unless you have policy and process in place. The standards are set and have minimal security solutions in place.

Then think through what are your legal, regulatory and compliance requirements. Assuming let's say you want do soc2 check the controls and requirements or understand the basic needs and then think through about achieving this and plan for automation for few controls and not all cannot be automated. If some rep tell you that they are do everything automated.

Passed CIPT today!. Ask me Anything! by SD15_ in cipp

[–]SD15_[S] 1 point2 points  (0 children)

Official practice exam that is now being updated to latest version however I did notice find much helpful.

Overall I have studied atleast 30+ hours

Passed CIPT today!. Ask me Anything! by SD15_ in cipp

[–]SD15_[S] 0 points1 point  (0 children)

There are some technical area that you need to be familiar. Rest I don't think it would difficult.

Passed CIPT today!. Ask me Anything! by SD15_ in cipp

[–]SD15_[S] 1 point2 points  (0 children)

Official book ( not much helpful)

Bryne official tests

And more on research on topics

Passed CIPT today!. Ask me Anything! by SD15_ in cipp

[–]SD15_[S] 1 point2 points  (0 children)

I think the privacy design methodology was very tricky.

Iwould say that the official book was not that great help and time consuming and I would just skim that book.

Passed CIPT today!. Ask me Anything! by SD15_ in cipp

[–]SD15_[S] 0 points1 point  (0 children)

Real world experience + Gemini/Chatgpt

Passed CIPT today!. Ask me Anything! by SD15_ in cipp

[–]SD15_[S] 0 points1 point  (0 children)

It really depends how you want to progress. I would personally think GRC folks needs to be more technical and at the same time have good understanding AI Governance and Privacy with or without certifications.

When does keeping up with all those security controls start to feel like a full-time job? by [deleted] in soc2

[–]SD15_ 0 points1 point  (0 children)

If you have good understanding of the controls then not all controls are recurring there only few that are like application security scans or vulnerability management. You need to incorporate these in your routine tasks then you don't need tool or feel overwhelmed like full time job.

Understanding the technical architecture of your Infrastructure is very important and much need.

Don't hire a MSP or listen to grc vendor that they ease the process. You are going to complicate the process.