The International Information Systems Security Certification Consortium ("(ISC)2")’s CISSP (Certified Information Systems Security Professional) certification is the best known information security certification. According to “(ISC)2”’s website, all CISSPs “are required to commit to fully support” the “(ISC)2” Code of Ethics. This code of ethics includes four mandatory canons:
Protect society, the commonwealth, and the infrastructure. Act honorably, honestly, justly, responsibly, and legally. Provide diligent and competent service to principals. Advance and protect the profession.The second of these canons is spelled out in more detail with a set of bullet points, the first of which is:
Tell the truth; make all stakeholders aware of your actions on a timely basis.Clearly, honesty is a key requirement of this code of ethics.
An up-and-coming certificate for information security managers is the Certified Information Security Manager (CISM) certification from the Information Systems Audit and Compliance Association (ISACA). ISACA also has a Code of Professional Ethics, which states that all ISACA certificate holders will comply with seven statements, the third of which is:
3. Serve in the interest of stakeholders in a lawful and honest manner, while maintaining high standards of conduct and character, and not engage in acts discreditable to the profession.Again, honesty is clearly a key requirement.
I recently learned that these requirements are not met by a prominent information security professional who frequently speaks at high-profile security conferences, has held the Chief Security Officer position at Exodus, Cable & Wireless, and Savvis, has been Chairman of the Internet Security Alliance, and is Chairman of the FCC’s NRIC Homeland Security focus group on cyber security.
“Dr.” Bill Hancock has degrees from a diploma mill, has repeatedly told false stories about being a Vietnam war veteran, a Navy SEAL, and a prisoner of war, and has lied about his martial arts expertise.