Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
A Certified Waste of Time
Jon Lasser, 2002-03-13

In which your intrepid columnist hands over $450 to sit for the CISSP exam, only to conclude that it measures little of value.

Comments Mode:
The answer is 16 2002-03-13
Anonymous (1 replies)
The answer is 16 2002-03-15
Anonymous (1 replies)
The answer is 16 2002-03-18
Arthur Dent
A Certified Waste of Time 2002-03-13
Jim Rodgers
A Certified Waste of Time 2002-03-13
Anonymous
A Certified Waste of Time 2002-03-13
BaijuShah, CISSP
A Certified Waste of Time... not for me! 2002-03-13
Aaron Higbee (2 replies)
No real correlation 2002-03-13
Anonymous (1 replies)
No real correlation 2002-03-15
John Whorfin <johnwhorfin@lectroid.net>
A Certified Waste of Time 2002-03-13
Anonymous (1 replies)
A Certified Waste of Time 2002-03-15
Anonymous
A Certified Waste of Time 2002-03-13
Anonymous
A Certified Waste of Time 2002-03-13
cray@ttlunlimited.com (1 replies)
CCIE-Security & Cisco Security Specialist 1 2002-03-16
teLi, CCNP (5 replies)
CCIE-Security & Cisco Security Specialist 1 2002-03-18
Thomas Porter, Ph.D.
CCIE-Security & Cisco Security Specialist 1 2002-03-29
Mr. Chase
The CCIE security is based totally around Cisco Products, and as far as I remember Cisco isn't a software company (sure the company was based off stolen software but that is beside the point). Is that why their Cisco Secure IDS is trash and can't go beyond 100Mbps and that you have to use the Blade for the Cat 6K if you want anything over 100Mbps and you've got to stack them in that $$expensive$$ 6K to get anything near gigE.
Oh wait but then don't you then need to spend some Big $$$ to get some type of data correlation mechanism for Cisco Secure IDS because it can't do logging to a sql database by itself. Oh and then its not configurable to work with any device that could be used with Expect you can only work with Cisco routing devices.
You're TFTP server is secured properly and you allow write access to that directory too :) Oh so that means that I can go about downloading and cracking your routing and switching gear not to mention posting rooted .bin files. Wait, you're using Cisco Log server for NT and if it runs out of disk space your PIX stops working right how nice :)
Oh and those little 35 series switches that don't support SSH. Secure VLAN all the way right? Yeah Right!

Secure Policy Design in CCIE security non-existent, Host based security (sorry that is one of our partners jobs), Incident Response hmmm no, most CCIEs that I know can hardly spell UNIX let alone build a secure Sun box unless you count the CSIDS boxes as Suns (NOT). IDS Signature Development (lets leave that to CCO, they know best anyway)
I didn't know that there was an experience requirement for the CCIE security.

The CISSP represents that you've been in the business for at least 3 years and the CCIE security doesn't say that you've ever touched any of the equipment except in the lab.

My Network is built on SAFE. I'd like for you to meet our newest recruit the "SAFE CRACKER"


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/67/11497#11497
A Certified Waste of Time 2002-03-13
Anonymous (1 replies)
A Certified Waste of Time 2002-03-20
Anonymous
A Certified Waste of Time 2002-03-14
Anonymous (1 replies)
A Certified Waste of Time 2002-03-24
Anonymous
A Certified Waste of Time 2002-03-14
Ian Simpson
Congratulations 2002-03-14
auto318190 (1 replies)
A Certified Waste of Time 2002-03-14
Anonymous (1 replies)
A Certified Waste of Time 2002-03-15
Anonymous2
A Certified Waste of Time 2002-03-14
Coldman
Trivial Pursuit 2002-03-14
Mike R
Go to SANS 2002-03-14
Chris (3 replies)
Go to SANS?! 2002-03-14
Anonymous (1 replies)
Go to SANS?! 2002-03-24
Anonymous
Go to SANS 2002-03-14
HD, CISSP (1 replies)
Go to SANS 2002-03-18
Anonymous
Go to SANS 2002-03-15
Tim (2 replies)
Go to SANS 2002-03-20
Anonymous
Go to SANS 2002-03-24
Anonymous
A Certified Waste of Time 2002-03-14
Terry Atkison
Certs 2002-03-14
W. Allen (1 replies)
Certs 2002-03-21
Anonymous
A Certified Waste of Time 2002-03-14
Louis Dolton
A Certified Waste of Time 2002-03-14
Anonymous
A Certified Waste of Time 2002-03-14
Surreal
Pass it and respect it. Do not pass it and blame the test. 2002-03-14
From someone who doesn't know anything but it is a CISSP
A Certified Waste of Time 2002-03-14
Anonymous CISSP
Take it for what it's worth 2002-03-14
Anonymous
A Certified Waste of Time 2002-03-14
Anonymous
A Certified Waste of Time: John Lasser 2002-03-14
David Hawley, CISSP
It's so easy to criticize, Isn't it? 2002-03-14
Dr. Mike Ewing (2 replies)
now that you mention it .. 2002-03-17
No One of Consequence (1 replies)
now that you mention it .. 2002-03-21
Anonymous
A Certified Waste of Time 2002-03-14
Anonymous, CISSP, SSCP
A Certified Waste of Time 2002-03-14
Anonymous
A Certified Waste of Time 2002-03-14
Anonymous
A Certified Waste of Time?? 2002-03-14
matt@whatuwant.com
What is your basic problem? 2002-03-14
Anonymous
A Certified Waste of SF Goodwill 2002-03-14
Chris (2 replies)
A Certified Waste of SF Goodwill 2002-03-18
Anonymous
Prove Your Point 2002-03-14
Anonymous
A Certified Waste of Time 2002-03-14
Anonymous
A Certified Waste of Time 2002-03-14
Arnie Jackson
Specialists vs. Generalists 2002-03-15
Robert Alberti, CISSP
A Certified Waste of Time 2002-03-15
Anonymous
Obviously written by someone who doesn't understand security 2002-03-15
Chris Thatcher, CISSP, MCSE
A few more thoughts... 2002-03-15
Rick Ewart, CPA & CISSP
A Certified Waste of Time 2002-03-15
Edward J. Liebig CISSP, CBCP, MCP - Director, IT Security
A Certified Waste of Time 2002-03-15
MCurry
A Certified Waste of Time 2002-03-15
Anonymous
More to it than that 2002-03-15
Don Helms CISSP
CISSPs in Europe? 2002-03-15
gmflash@web.de (1 replies)
CISSPs in Europe? 2002-03-20
Salvatore Cagliari <cks@s-cagliari.de>
A Certified Waste of Time 2002-03-15
Jim Webster, CISSP
A Certified Waste of Time - NOT! 2002-03-15
Chris Hare CISSP, CISA
What... 2002-03-15
Anonymous (1 replies)
What... 2002-03-18
Anonymous
A Certified Waste of Time 2002-03-16
teLi, CCNP (1 replies)
A Certified Waste of Time 2002-03-18
Anonymous
A Certified Waste of Time 2002-03-16
Samuel Yeung, CISA, BS7799 Lead Auditor (1 replies)
A Certified Bunch of Crybabies... 2002-03-16
Mr. Andre Robitaille, I wonder how many acronyms I can put after my name? (1 replies)
A Certified Bunch of Crybabies...AND Talk about Anally Retentive!! 2002-03-25
Dr. E. W. c.r.t.f.q., c.b.o.h.i.c.a, c.w.g.a.s., cv43, LEO
Lasser's Waste of Time 2002-03-16
CISSP and Happy about it
The CISSP replies 2002-03-16
Guy Unconvinced, TLA BFD EIEIO IMHO
Certification epiphany? 2002-03-17
David Byrne, CISSP, MCSE, MCP+I
A Certified Waste of Time 2002-03-17
Anonymous
A Certified Waste of Time 2002-03-18
Anonymous
A Student's View 2002-03-18
Frank Reid
CISSP is for Security Management 2002-03-18
Chris Shepherd
A Certified Waste of Time 2002-03-19
Security Expert
Beware Of Consultant LIke Jon Lasser 2002-03-19
Scott Sattler (4 replies)
Beware Of Consultant LIke Jon Lasser 2002-03-20
Not Impressed by a Sting of Certs (1 replies)
Beware Of Consultant LIke Jon Lasser 2002-03-20
Robert Banz, (this space for rent)
Beware Of Consultant LIke Jon Lasser 2002-04-03
Mike Rose (mbr@eclipse.net)
What does it measure? 2002-03-19
Anonymous
Lasser is both right, and wrong. 2002-03-20
Bill Schmidt, CISSP
A Certified Waste of Time 2002-03-20
Anonymous CISSP
Something to ponder 2002-03-20
jj
Get a Life 2002-03-21
Anonymous
A Certified Waste of Time 2002-03-21
Jack
A Certified Waste of Time 2002-03-21
Anonymous
A Certified Waste of Time 2002-03-21
Patric
Certificates 2002-03-21
Ernie
A Certified Waste of Time 2002-03-22
Anonymous
Value 2002-03-22
Troy McCarty
there goes the brain 2002-03-24
Mr Morrow
A Certified Waste of Time 2002-03-25
Anonymous
SANS?! GIMME A BREAK! 2002-03-25
Anonymous (1 replies)
SANS?! GIMME A BREAK! 2002-03-26
Anonymous
A Certified Waste of Time 2002-03-25
Anonymous
What about SCNP?? 2002-03-26
Anonymous
Remember the P in CISSP 2002-03-26
Robert Kerby, CISSP
The top domain is english. 2002-03-27
Anonymous (1 replies)
The top domain is english. 2002-03-27
Anonymous
Lasser works for SANS 2002-03-28
Truth in Journalism Seeker
It's Too Early. 2002-03-31
Colin Rous (emphatically NOT a CISSP)
My Response 2002-04-02
Jon Lasser (2 replies)
My Response 2002-04-03
Not Really Anonymous
Well done 2002-04-03
Anonymous
(ISC)2 vs ethics 2002-04-06
Anonymous
A Certified Waste of Time 2006-11-08
Paul S. Vincent (1 replies)
Re: A Certified Waste of Time 2007-01-07
Paul Henry CISSP
Don't Take This Author Seriously 2007-05-20
Anonymous
Poor guy! 2007-08-09
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus