Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Time for a new certification
Don Parker, 2007-05-01

I wrote a column for Securityfocus some time ago that aired my concerns over GIAC dropping the practical portion of their certification process. That column resulted in a lot of feedback, with most agreeing about how GIAC bungled what was up till then, the best certification around.

Comments Mode:
Time for a new certification 2007-05-01
Steven Adair
Time for a new certification 2007-05-01
Wim Remes (2 replies)
Re: Time for a new certification 2007-05-09
Anonymous
Re: Time for a new certification 2007-05-20
Anonymous
Time for a new certification 2007-05-02
Omar Herrera
Time for a new certification 2007-05-02
Anonymous
Time for a new certification 2007-05-02
Fatman
Time for a new certification 2007-05-02
Anonymous
Time for a new certification 2007-05-02
Anonymous
Blocking port 53 TCP 2007-05-02
Richard Bejtlich (1 replies)
Re: Blocking port 53 TCP 2007-05-02
Don Parker (1 replies)
Re: Re: Blocking port 53 TCP 2007-05-03
Anonymous (2 replies)
Re: Re: Re: Blocking port 53 TCP 2007-05-03
Don Parker
Re: Re: Re: Blocking port 53 TCP 2007-05-04
Anonymous (2 replies)
Re: Re: Re: Re: Blocking port 53 TCP 2007-05-22
Raman (1 replies)
Blocking port 53 TCP vs CISSP 2007-05-24
G Bickers
Time for a new certification 2007-05-02
Ron Black
Time for a new certification 2007-05-02
Anonymous (1 replies)
Re: Time for a new certification 2007-05-07
Anonymous
Time for a new certification 2007-05-02
Rob Shein (1 replies)
Re: Time for a new certification 2007-05-02
Don Parker (1 replies)
Time for a new certification 2007-05-03
Anonymous (2 replies)
Re: Time for a new certification 2007-05-06
Don Parker
Re: Time for a new certification 2007-05-08
Anonymous
Bring it on! 2007-05-03
ichinin (2 replies)
Re: Bring it on! 2007-05-06
Anonymous (1 replies)
Re: Re: Bring it on! 2007-05-15
Anonymous
Re: Bring it on! 2007-05-07
Anonymous
Time for a new certification 2007-05-08
Anonymous
Time for a new certification 2007-05-09
Anonymous
I agree that today's certifications are inadequate to test the whole picture.

I consider myself a security professional. I understand the concepts, limitations, and proper uses of technical controls (IDS, vuln scans, etc) and have coded signatures, NASL scripts, data analysis scripts, and reporting interfaces. I also understand the right way to perform assessments, conduct audits, develop corrective action plans, perform risk analyses, and facilitate root cause analyses. I have experience with the Certification and Accreditation process, I know how to develop a training and awareness program, and I know what compliance metrics are, how to calculate them, and how to use them.

A certification, however, did not teach me these things. Only experience and a hunger for knowledge can teach the wide variety of skills necessary to be a true professional. Expecting a certification to be broad enough to cover all of the required aspects is folly.

We are better off using a mix and match of less complete certs like we have today to cover a baseline, then using something less definite to move us to the next higher level. I have firewall certs, forensics certs, management certs, and tons of training in various technical and soft skills. None of them, however, ensure I'm any good at what I do. Only day-to-day work, study, and peer review can ensure that I'm competent.

Stop looking at certs to be the answer. We should require more regular actions to prove competence, like publishing papers, writing books, research, and peer review journals.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/443/34533#34533
Time for a new certification 2007-05-10
Anonymous
Time for a new certification 2007-05-11
Anonymous
The CEPT & CPTE 2007-05-16
Anonymous
Time for a new certification 2007-05-20
CISSP guy (1 replies)
Re: Time for a new certification 2007-05-25
DeMartian
Time for a new certification 2007-05-24
CISA, CISSP, GSEC, CEH, MCSE, CCNA, CCSA, SEC+ Guy







 

Privacy Statement
Copyright 2009, SecurityFocus