Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Time for a new certification
Don Parker, 2007-05-01

I wrote a column for Securityfocus some time ago that aired my concerns over GIAC dropping the practical portion of their certification process. That column resulted in a lot of feedback, with most agreeing about how GIAC bungled what was up till then, the best certification around.

Comments Mode:
Time for a new certification 2007-05-01
Steven Adair
Time for a new certification 2007-05-01
Wim Remes (2 replies)
Re: Time for a new certification 2007-05-09
Anonymous
Re: Time for a new certification 2007-05-20
Anonymous
Time for a new certification 2007-05-02
Omar Herrera
Let us not just go beyond memory issues with exams. Understanding concepts is better but probably not good enough these days; we need people that is able to get the whole picture.

Hopefully, the following examples will make my point clear:

1) You have an infosec professional that understands what a DoS attack is. She/he knows that resource exhaustion puts systems to a halt. But then, you ask this infosec professional how resistant is your network to a certain network flooding attack and has no clue, probably because she/he does not even know how to measure network throughput, no to mention understanding the impact of several filtering devices and QoS boxes within it as well as the number of connections supported by the application within each server, considering load balancing and such.

2) You have an infosec professional that knows that an 16 character, alphanumeric + symbols password is more secure than a 8 character long, only letters password. Fine, but when you ask: My clients just can't memorize the 16 character long password, we have to go for less, so what is enough for my environment if I have passwords stored as MD5 hashes without salt? they just can do the math using an average processor speed to estimate brute force cracking time, let alone get statistics of dictionary attacks and estimate from there. There are other countermeasures and alternatives to password length and they know them (e.g. login retry delays, frequency to force password change) but they just can't work with them within a real situation and come up with a reasonable/feasible alternative.

Thus, in my opinion, making sure that people understand the concepts, while much better than just letting them memorize stuff is simply not enough. In fact, background knowledge necessary to understand and assess a real world situation is probably equally important, and I think that is what is needed most right now.

So the practical aspect is essential for a certification, but we shouldn't restrict it to closed labs (where everything usually happens as planned). Something similar to internships might work better, but it would also mean that we would need to change the current practice of apply-answer_exam-certify-pay_anual_fees_and report_credits_as_needed, applied by many professionals with most certifications. Instead, we should get seriously involved to really make it grow, so that those more experienced can help the new ones grow.

Just some thoughts.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/443/34502#34502
Time for a new certification 2007-05-02
Anonymous
Time for a new certification 2007-05-02
Fatman
Time for a new certification 2007-05-02
Anonymous
Time for a new certification 2007-05-02
Anonymous
Blocking port 53 TCP 2007-05-02
Richard Bejtlich (1 replies)
Re: Blocking port 53 TCP 2007-05-02
Don Parker (1 replies)
Re: Re: Blocking port 53 TCP 2007-05-03
Anonymous (2 replies)
Re: Re: Re: Blocking port 53 TCP 2007-05-03
Don Parker
Re: Re: Re: Blocking port 53 TCP 2007-05-04
Anonymous (2 replies)
Re: Re: Re: Re: Blocking port 53 TCP 2007-05-22
Raman (1 replies)
Blocking port 53 TCP vs CISSP 2007-05-24
G Bickers
Time for a new certification 2007-05-02
Ron Black
Time for a new certification 2007-05-02
Anonymous (1 replies)
Re: Time for a new certification 2007-05-07
Anonymous
Time for a new certification 2007-05-02
Rob Shein (1 replies)
Re: Time for a new certification 2007-05-02
Don Parker (1 replies)
Time for a new certification 2007-05-03
Anonymous (2 replies)
Re: Time for a new certification 2007-05-06
Don Parker
Re: Time for a new certification 2007-05-08
Anonymous
Bring it on! 2007-05-03
ichinin (2 replies)
Re: Bring it on! 2007-05-06
Anonymous (1 replies)
Re: Re: Bring it on! 2007-05-15
Anonymous
Re: Bring it on! 2007-05-07
Anonymous
Time for a new certification 2007-05-08
Anonymous
Time for a new certification 2007-05-09
Anonymous
Time for a new certification 2007-05-10
Anonymous
Time for a new certification 2007-05-11
Anonymous
The CEPT & CPTE 2007-05-16
Anonymous
Time for a new certification 2007-05-20
CISSP guy (1 replies)
Re: Time for a new certification 2007-05-25
DeMartian
Time for a new certification 2007-05-24
CISA, CISSP, GSEC, CEH, MCSE, CCNA, CCSA, SEC+ Guy







 

Privacy Statement
Copyright 2009, SecurityFocus