GIAC GSTRT — Strategic Planning, Policy and Leadership
The cert that made me a better engineer, not just a better manager. What GSTRT tests, how to build the index that passes it, and why the "soft" cert is the hard one.
Let me guess what you're thinking. It's the "soft" cert. The one without packet captures or memory dumps.
I thought that too. I was wrong!
Tip
#
Open book, same as GCIH. Which means the same rule applies:
#
#
This is the part that surprised me most.
Security strategy isn't a list of tools you want to buy. It's a story about where the business is going and what has to be true for it to get there safely.
What to know:
Careful
#
Here's the thing nobody tells you: most security policy fails not because it's wrong, but because nobody reads it.
Know these cold, because the exam tests the distinction directly:
And write for the reader. Short. Plain. Specific about who does what. If someone needs a security background to understand your acceptable use policy, it will not change anyone's behaviour.
#
The part I expected to find fluffy, and didn't.
#
I love hand-to-paper for this one. Flowcharts for the policy lifecycle, current-state-to-future-state drawn out by hand. Something about drawing it makes it stay.
#
#
Yes — and especially if you're technical and slightly suspicious of it. That was me.
The engineers who get their projects funded aren't always the best engineers. They're the ones who can explain risk in the language the person holding the budget already speaks. This cert is a structured way to learn that language.
Studying for this one too? What's your target date? I'd genuinely like to know what's working for you.
Keep going!
#
Contents
Exam domains