Sorry for the confused. My point was CISSP is the best so far but if you don’t have CISSP get a Computer Science degree. It will help you a lot to understand how management and psychology work in IT department.
I have my CISSP and I also have others, like some from ISECOM covering the OSSTMM. In fact (disclaimer) I got so into it I am now their US trainer for their certifications working directly for ISECOM.
The CISSP in my experience is really only good for the paper compliance side of things. The OPST is for actually testing and the test is hands on, you actually work the problems to come up with the answer not just pick from a list. In fact, the OPST and OPSA certs are a part of the Masters in security program at La Salle University in Barcelona Spain.
Im not saying the CISSP has no value, But its quickly becoming one of those that anyone that studys can go pass. And no, the time in the industry requirements dont make a difference, you can be "creative" and they will still accept it.