Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Certifiably Certified
Richard Forno, 2002-10-23

As security certifications become more plentiful, they are losing their real value.

Comments Mode:
Certifiably Certified 2002-10-23
Anonymous
Certifiably Certified 2002-10-23
Anonymous
Certifiably Certified 2002-10-23
Floydman
Certifiably Certified 2002-10-23
Anonymous (3 replies)
HR departments... 2002-10-24
Anonymous
Certifiably Certified 2002-10-24
Anonymous (2 replies)
Certifiably Certified 2002-10-24
Anonymous
Certifiably Certified 2002-10-25
Anonymous
Certifiably Certified 2002-10-28
Anonymous
Certifiably Certified 2002-10-23
Fabio Ghioni
Ever try one? 2002-10-23
Regular Guy (3 replies)
Re: Ever try one? 2002-10-24
Andrew Jones
I have taken SANS's Security Essentials course (and passed the certification exam), and i just shelled out another $2000 for their IDS course. I have tried one.

I don't think Mr. Forno's point is that all security certifications are patently bad. He even mentions SANS as being established and respectable. He also did not say that he does not hire people with certifications. I think his point is the inequality that exists between people with experience but no certifications and people with certifications and no experience. Companies are choosing the later, although certifications are not worth much without the experience to back them up. He says nothing about the group of people with both experience and certifications.

Additionally, from his writings, i believe that Mr. Forno takes his profession very seriously, and it disturbs him that security certification entities are popping up purporting to "teach security", when they are only out to make a buck. (As a counterexample, take again SANS, which is a not-for-profit organization, and takes the attitiude that they are not teaching to the exam, but rather teaching what their students need to know, and if their students know everything they need to know, they will do fine on the exam.) These same entities are also trying to appeal to the money grubbing side of their students by claiming to be able to drastically increase their salaries. They show no concern for helping their students to do their jobs well.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/118/16899#16899
Ever try one? 2002-10-24
Anonymous
Ever try one? 2002-10-29
oh-woe-is-us@so-sad.com
penis envy 2002-10-24
tammy (1 replies)
penis envy 2002-10-25
Anonymous
Whole lot of useless words 2002-10-24
Anonymous (2 replies)
Re: Whole lot of useless words 2002-10-25
Phil Burg (philb@operamail.com) (1 replies)
Re: Whole lot of useless words 2002-10-28
Anonymous
Whole lot of useless words 2002-10-25
blacklight
Certifiable 2002-10-24
Anonymous (1 replies)
Certifiable 2002-10-24
Anonymous (1 replies)
Certifiable 2002-10-25
Anonymous
Certifiably Certified 2002-10-24
Wykkyd (2 replies)
Certifiably Certified 2002-10-24
DarkCrypt0
Certifiably Certified 2002-10-24
Alphabet Soup
Certifiably Certified 2002-10-24
Anonymous
Certifiably Certified 2002-10-25
LittleW0lf (1 replies)
Certifiably Certified 2002-10-28
Anonymous, CISSP (1 replies)
Certifiably Certified 2002-10-29
Anonymous cissp
Certifiably Certified 2002-10-25
Marcus Green
Right on! 2002-10-25
Gary L.
Certifiably Certified 2002-10-25
windows311@hotmail.com (SPAM avoidance)
Qualifying Experience 2002-10-26
Regular guy
Certification as barrier break 2002-10-27
Anonymous
Certifiably Certified 2002-10-28
Anonymous, CISSP, GSEC, GCIA, GCFW, CCNA, CCSE (1 replies)
Certifiably Certified 2002-10-29
Brad Bemis
Certifiably Certified 2002-10-28
Brad Bemis
Please send me my certification... 2002-10-30
D3M (1 replies)
Certifiably Certified 2002-11-01
Tommy
Certifiably Certified 2002-11-03
Jeff Schmidt
Certifiably Certified 2002-11-05
Bob Radvanovsky, Certified Technological Sanitation Disposal Engineer (CTDSE)
And another thing... 2002-11-05
Bob Radvanovsky, Certified Technological Sanitation Disposal Engineer (CTDSE)







 

Privacy Statement
Copyright 2009, SecurityFocus