Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Certifiably Certified
Richard Forno, 2002-10-23

As security certifications become more plentiful, they are losing their real value.

Comments Mode:
Certifiably Certified 2002-10-23
Anonymous
Certifiably Certified 2002-10-23
Anonymous
Certifiably Certified 2002-10-23
Floydman
Certifiably Certified 2002-10-23
Anonymous (3 replies)
HR departments... 2002-10-24
Anonymous
Certifiably Certified 2002-10-24
Anonymous (2 replies)
Certifiably Certified 2002-10-24
Anonymous
Certifiably Certified 2002-10-25
Anonymous
Certifiably Certified 2002-10-28
Anonymous
Certifiably Certified 2002-10-23
Fabio Ghioni
Ever try one? 2002-10-23
Regular Guy (3 replies)
Re: Ever try one? 2002-10-24
Andrew Jones
Ever try one? 2002-10-24
Anonymous
Ever try one? 2002-10-29
oh-woe-is-us@so-sad.com
penis envy 2002-10-24
tammy (1 replies)
penis envy 2002-10-25
Anonymous
Whole lot of useless words 2002-10-24
Anonymous (2 replies)
Re: Whole lot of useless words 2002-10-25
Phil Burg (philb@operamail.com) (1 replies)
Re: Whole lot of useless words 2002-10-28
Anonymous
Whole lot of useless words 2002-10-25
blacklight
Certifiable 2002-10-24
Anonymous (1 replies)
Certifiable 2002-10-24
Anonymous (1 replies)
Certifiable 2002-10-25
Anonymous
Certifiably Certified 2002-10-24
Wykkyd (2 replies)
Certifiably Certified 2002-10-24
DarkCrypt0
Certifiably Certified 2002-10-24
Alphabet Soup
Certifiably Certified 2002-10-24
Anonymous
Certifiably Certified 2002-10-25
LittleW0lf (1 replies)
Certifiably Certified 2002-10-28
Anonymous, CISSP (1 replies)
Certifiably Certified 2002-10-29
Anonymous cissp
Certifiably Certified 2002-10-25
Marcus Green
Right on! 2002-10-25
Gary L.
Certifiably Certified 2002-10-25
windows311@hotmail.com (SPAM avoidance)
Qualifying Experience 2002-10-26
Regular guy
Certification as barrier break 2002-10-27
Anonymous
Certifiably Certified 2002-10-28
Anonymous, CISSP, GSEC, GCIA, GCFW, CCNA, CCSE (1 replies)
I would agree that the CISSP is basically a useless certification if you are looking for a deeply technical security practitioner as the test is severely dated, shallow and not all that hard to pass. However, I noticed this article did not mention any certifications that are currently available from SANS/GIAC.

I hold the CISSP, CCSE and the CCNA but they are, as the author correctly states, nothing more than a piece of paper. I am most proud of my SANS/GIAC certifications because of the required practical that is developed to show your mastery of the subject material and multiple exams to test your knowledge of the course material.

I would highly suggest taking part in one of the certifications tracks available from SANS/GIAC. I think you would be suitably impressed and would find that it requires not only time but a great deal of knowledge in order to get the certification.

For those ranting that certifications don't prove anything then I would invite you to make those same assertions after completing a few. I used to think the same way and would prattle on for hours about how worthless certs are and how I would never obtain one but it was really just a coverup to the fact that I was too lazy to get off my butt and earn one. I started with CCSE (CCSA also) and the moved to the CCNA. I learned a little but didn't feel all that knowledgeable but then I enrolled in the SANS Security Essentials course and was impressed with the depth and amount of material covered in the course. I felt I had a good background in Infosec (14 years experience) but I found I had a lot of gaps in my knowledge that the GSEC helped me even out.

From there I obtained the GCFW (Firewall/VPN) and the GCIA (Intrusion Detection) and then took the CISSP because it was required for my job. I was a bit worried because of all the horror stories I have heard about the exam but it was laughable. Honestly - the exam is a joke.

My point is this:

1. Try out the GIAC/SANS certifications.
2. Don't knock certs until you have a couple
3. Knowledge IS power
4. Employers DO look for certifications.



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/118/16965#16965
Certifiably Certified 2002-10-29
Brad Bemis
Certifiably Certified 2002-10-28
Brad Bemis
Please send me my certification... 2002-10-30
D3M (1 replies)
Certifiably Certified 2002-11-01
Tommy
Certifiably Certified 2002-11-03
Jeff Schmidt
Certifiably Certified 2002-11-05
Bob Radvanovsky, Certified Technological Sanitation Disposal Engineer (CTDSE)
And another thing... 2002-11-05
Bob Radvanovsky, Certified Technological Sanitation Disposal Engineer (CTDSE)







 

Privacy Statement
Copyright 2009, SecurityFocus