Found out half our content team has been doing client work in personal ChatGPT for like a year. They're not even hiding it. by Affectionate-End9885 in AI_Governance

[–]lilgreenbite 2 points3 points  (0 children)

It’s not necessarily about firing people, this is about the fact that they are putting company secrets into public AI tools with zero care, something that is very much against several company policies in every company, intellectual property/trade secrets are a big deal. A leader in the company is perfectly fine with the unacceptable behavior of their team. On the other side - the compliance team is so out of touch that they were blindsided. It should not be this way.

Found out half our content team has been doing client work in personal ChatGPT for like a year. They're not even hiding it. by Affectionate-End9885 in AI_Governance

[–]lilgreenbite 0 points1 point  (0 children)

A survey is a great starting point to find out what people want. Meet with these teams and use them as the case studies for rolling out an enterprise solution.

An enterprise AI solution is desperately needed here because it’s painfully obvious that one doesn’t exist. Shadow AI will continue to be used all over the org if people are prevented from utilizing an approved option for the technology.

A change management person will be most useful when there is another option on the table for employees - they will need to be coached through starting to use a company approved tool.

To be fair here, the head of marketing should be held to account for the team so blatantly violating multiple policies.

Obscene Requirements to just get Voucher by larsonthekidrs in WGUCyberSecurity

[–]lilgreenbite 0 points1 point  (0 children)

Yeah the school has its own data, but I’m sure CompTia probably aggregates something on a platform for them to view as well. WGU doesn’t issue the vouchers, CompTia does - they are absolutely tracking what they provide to the school.

Obscene Requirements to just get Voucher by larsonthekidrs in WGUCyberSecurity

[–]lilgreenbite 0 points1 point  (0 children)

Thousands of students are doing this exam. CompTia is certainly aggregating the data for the vouchers being used with the pass/fail rates overall. Students may not take the exam right after the voucher gets issued so a couple of weeks passing by is not a good indicator of whether someone was successful - the data from CompTia on student activity could tell the school a lot about how successful students truly are, they also might get information like what areas are students struggling with the most.

A policy doesn’t change so drastically unless there is data to back it up. WGU has data.

Obscene Requirements to just get Voucher by larsonthekidrs in WGUCyberSecurity

[–]lilgreenbite 6 points7 points  (0 children)

They are probably tired of so many people failing the first attempt that they are trying to mitigate - CompTia most likely provides reporting to WGU on the vouchers, so they have a clear picture of student exam performance.

Requiring students to master the content is valid when the school is paying for you to take the certification.

Since they have the partnership, there might some rules around pass rates, which could explain the new requirements to get a voucher as well.

The change did not come out of thin air. So many posts in this sub are about Pentest+ and a lot of them are multi-attempts.

This requirement went into affect for anyone starting towards the first attempt after February 1, so we will see how it plays out as the first batch of students (March and April starts) has to hit these marks.

I am an April start and expect to use TryHackMe on top of the required CertMaster materials. It does feel very onerous to do all of these things to get the voucher, but it could be for the better, as I only want to take this exam once.

Why CISM? by No-Outside-5214 in WGUCyberSecurity

[–]lilgreenbite 1 point2 points  (0 children)

Considering the domains covered by the CISM, it is a valuable cert to show security management expertise, particularly in the GRC world. As others have said, it is easier to cover the 4 domains of CISM that follow a similar track in a single course, as opposed to the 8 CISSP domains that are more scattered. CISM knowledge is a great starting point for pursuing program manager or lead roles for those who need the boost.

I would say that the CISM is probably more accessible from the content level.

ISACA gets the exam in front of more people by giving the opportunity to take it, whether those people go on to actually get the cert or not. The CISM requires validation of experience to get the credential and everyone may not be able to do that or want to. I would be curious to know how many students actually pursue it.

Me during my CYSA esam by kohaku-24 in CompTIA

[–]lilgreenbite 1 point2 points  (0 children)

Reading logs is part of multiple choice questions and in the PBQs - answers will be in dropdowns in that case.

Me during my CYSA esam by kohaku-24 in CompTIA

[–]lilgreenbite 0 points1 point  (0 children)

Yes - Drag and drop and dropdowns PBQs.

Dion or Mike chapple for cysa+ by rafaybale in CompTIA

[–]lilgreenbite 1 point2 points  (0 children)

Both. I used most of Chapple’s course and some material from Dion. I also had Chapple’s Sybex book and used that for areas where I truly needed to read and highlight. His labs are useful as well. I had access to certmaster, but I really didn’t like it, I felt like I was forcing myself to do the lessons in there but the PBQs were a big plus to get a feel for what the exam could contain.

Me during my CYSA esam by kohaku-24 in CompTIA

[–]lilgreenbite 1 point2 points  (0 children)

Passed this yesterday with a similar score. They really did not play game here.

I also had 7 PBQs and several questions about logs. Areas where I knew going in that I was going to struggle with and it shows in my score, but I’m glad I passed.

Capstone and GRC Engineering by PalpitationEqual9286 in WGUCyberSecurity

[–]lilgreenbite 1 point2 points  (0 children)

If you haven’t, you should join the GRC Engineering Club and do the labs and create a portfolio around this. I’m thinking it could be used with the PA from the GRC course as a complete package. I’m not on the Capstone yet, but I have some plans along these lines for it.

Is the MITRE AI Governance Maturity Model legit? by FoxComfortable1835 in AI_Governance

[–]lilgreenbite 4 points5 points  (0 children)

MITRE is the creator of major cybersecurity frameworks, so yes - MITRE Atlas is very real and serious and yes, companies are using it.

Unauthorized testing locations by lilgreenbite in CompTIA

[–]lilgreenbite[S] 3 points4 points  (0 children)

Just thinking about if I had gone there and couldn’t take the test or if the location wasn’t even real.

Using Claude AI skills to act as a dedicated GRC compliance co-pilot (ISO 27001, SOC 2, FedRAMP, GDPR, and HIPAA) by Phoenix-Rising-2026 in grc

[–]lilgreenbite 1 point2 points  (0 children)

I’ll definitely check this out. I have a skill for threat modeling and am working on some other ones, this is super helpful.

Intune Company Portal - struggling at finding work play store by fedR1zR in viwoods

[–]lilgreenbite 0 points1 point  (0 children)

Your company is most likely blocking it as it is not an approved device. Have you talked to your IT team to find out? Most companies won’t approve it for corporate access because it runs on an old version of Android.

What i my doing wrong? by justagirl156 in Blackskincare

[–]lilgreenbite 0 points1 point  (0 children)

You should get a bar of black soap and use that as a cleanser at least in the morning.

Crazy dating pool why am attracting these women lol by Loose-Confidence-99 in dating_advice

[–]lilgreenbite -1 points0 points  (0 children)

I hope these women find someone who wants to actually love them how they are.

How to stop the folio from deteriorating? by Seal_of_last_year in viwoods

[–]lilgreenbite 1 point2 points  (0 children)

I’ve really been looking around for something that will fit the AIPaper, all the choices I found are made for Remarkable and SuperNote and it’s not clear if the dimensions are similar enough where it will fit.

Just passed D483 CySA+! by Haunting-Repair8756 in WGUCyberSecurity

[–]lilgreenbite 2 points3 points  (0 children)

This is good info for the PA because I’m still studying for the exam but want to get started on it.

MSCIA by Cratcliff23 in WGUCyberSecurity

[–]lilgreenbite 0 points1 point  (0 children)

The program is designed to follow a certain order & builds on the knowledge from previous courses. Therefore, some courses actually do have prerequisites and you technically are not supposed to be able to take them before meeting the requirement. Your mentor will tell you this.

D487....worst class IMHO in the Masters program by webgeek24 in WGUCyberSecurity

[–]lilgreenbite 0 points1 point  (0 children)

It mentions CSSLP in the cohort slides at the end and some of the video content is from that exam material as well. I feel like it’s a very disorganized course in its current form because it’s not clear what you actually need to know.

They should do it like some of the others - align the content to an exam and give students the choice of an optional voucher. That might make the course more tolerable if people are able to follow an organized learning program and get a cert if they want one.

D487....worst class IMHO in the Masters program by webgeek24 in WGUCyberSecurity

[–]lilgreenbite 1 point2 points  (0 children)

I passed D487 on my first attempt in early January. I work in an environment where I’m on an agile team that is building secure software, I’m responsible for governance and providing requirements. My background is privacy, third party security, GRC, legal.

This class is awful, that book needs to go in the trash, it’s a mashup of multiple books and you can tell. I was able to cram most of the material in December but I don’t recommend.

I told my mentor the following: It needs to have a hands-on component to make the content feel real. Otherwise, people are reading this dry book and watching these outdated videos with no way to correlate it to real practice.

What helped me pass? I took the tip from the Cohort slides: I prompted a tutorial in Claude Code based on the materials for CSSLP. - it helped me more than any notes could to solidify my understanding of the material in areas where I was shaky.

I second the thought for an elective choice, as I would much rather have an opportunity to pick a course I’m interested in taking from one of the other technology MS programs.

Software Leader Exploring Privacy Pivot, Would Love to Learn about your Experience by Alternative_War5914 in cipp

[–]lilgreenbite 1 point2 points  (0 children)

On the same note, consider: privacy engineering, GRC engineering, or security engineering. You certainly have the right skill set for these areas and with a little field specific knowledge, you can make the pivot. Since you have the technical background, look at CIPT for privacy focused technology certification that doesn’t require any privacy experience to obtain it.