Showing posts with label security certification. Show all posts
Showing posts with label security certification. Show all posts

Thursday, April 8, 2010

The (ISC)2 Takes the CSSLP To Computer Based Testing

The (ISC)2 has joined the ranks of security certification organizations in allowing computer based testing for its exams. The CSSLP is the first, as described by the (ISC)2 in the email quoted below:

"(ISC)2 today announced the availability of computer-based exams for its Certified Secure Software Lifecycle Professional (CSSLP) credential. The CSSLP is the first (ISC)2 certification exam to make the transition from paper-and-pencil delivery. Computer-based testing for (ISC)2 's other credential exams will be phased in over the next three years."
Moving the CSSLP and other certification tests from a large scale pencil and paper exam to an online format isn't a huge change, but should make the testing process more approachable for many. Why it will take three years is a better question - this should actually make the tests easier to maintain, and it should mean that the (ISC)2 's exam creation process and question randomization is far simpler.

Thursday, March 25, 2010

Followup: GIAC Certificate Renewals

I recently posted about GIAC's new renewal process, and inquired with SANS about how the renewal tracking would work. Here's their answer:

"SANS training no earlier than two years prior to your certification expiration date is eligible for CMUs toward your certification renewal. Once you register and pay for your renewal, you will need to fill out the Submission Form and fax it 866-627-6387 for review."

Hopefully SANS will follow in the footsteps of their peers as they work with this process, and will automatically count SANS courses toward a rolling renewal total.

Wednesday, March 17, 2010

New GIAC Certification Maintenance Process - Keep your GIAC cert without retesting

SANS is moving their GIAC certification maintenance to fit a model closer to that used by (ISC)2). Now, options are both a re-certification exam or a "Certification Maintenance Unit" (CMU) approach requiring 36 CMUs over a 4 year time period. The cost to renew - $399 - is still required, although additional certifications that expire within the next two years are done at half cost.

The main options are course based CMUs and GIAC Gold papers, although the standard certification exam remains an option, and a number of smaller CMU count secondary activities are available.

In brief:

  • Retaking and passing the test is worth 36 CMUs
  • A GIAC gold paper is worth 36 CMUs
  • A completed 6 day SANS or "qualifying non-SANS" course is worth 36 CMUs
  • A 1 day course is worth 6 CMUs.
  • Documented work experience is worth 12 CMUs
  • GIAC or SANS community participation is worth 6 CMUs
If you have a SANS certification, this is an attractive option - you'd pay the same for the test, and can likely complete enough coursework over four years to finish 36 CMUs. Will these requirements keep GIAC certification holders up to par? Only time will tell.

I've queried SANS about how they're tracking existing training during the past 4 years for those who have pending renewals, and if they will provide a tracking mechanism like (ISC)2 does for CISSP holders, and I'll post their response.

Wednesday, June 4, 2008

Security Certifications Hold Value While IT Certifications Drop

EWeek's Deb Perelman notes in a recent article that compensation for those with IT certifications has fallen for the 7th straight quarter, but that security certifications are holding their value:

Foote found some exceptions to the decline of certifications as well, but only in the security arena, due to its heavily technical nature.

"Security is a deeply technical domain and certification is an important qualification in areas where technical skills dominate," he explained.


Will security certifications see a similar drop? It seems that as security becomes more of a commodity in the IT space that we will see a similar devaluing for the certificates and an increased focus on the skillsets and experience. Certificates will continue to be useful in technically focused positions, or those that need some basic form of filter for candidates. They will also continue to help mark out those candidates who are interested in continuing education.

Thursday, August 9, 2007

Certifications and pay

A recent Computerworld article points to an increase in salary for information security practitioners with certifications. Despite questions about the usefulness of some certifications - Bejtlich's take on the CISSP is a great example - they're still required or desired for many positions. Despite views from some in the industry about it, the article notes that the CISSP is amongst the most valuable certifications - at least from a pay perspective:

"Among the certification programs commanding the highest premiums were Certified Information Systems Security Professional (CISSP) , Certified Information Systems Auditor (CISA) and Certified InformationSecurity Manager (CISM)"
How does this negative view of the CISSP from respected industry folks like Thomas Ptacek and Richard Bejtlich fit with a high value for the CISSP? For one, more senior IT staffers are getting the CISSP. The oft maligned "mile wide, inch deep" coverage is well suited to the broad view of management. Similarly, the CISSP's experience requirement helps, but doesn't guarantee more time in the field, and thus one would expect a correlation to higher wages.

More technical certifications, such as many of the SANS paths - GIAC, GCIH, and such are more likely to be found in the hands of technically oriented professionals. The value of the certificates is definitely there, but the correlation to higher wage may not be as easy to show - fewer senior managers and C level positions are likely to have the SANS technical certifications.

Where does that leave us as professionals? Well, for one, the government is requiring more certifications. Per the article there is a "Department of Defense directive which requires over 100,000 security professionals in certain specific job roles to be certified within a five year period" which will drive certification for many in the public sector. Second, compliance requirements dealing with PCI, HIPAA, FERPA, the GLBA, SOX, and other standards mean that companies are looking for security staffers - and certifications are an easy filter for HR.

Given those trends, a certification may just be a good route to a few dollars more on your paycheck, or into a new job - if your friends give you a hard time, tell them to think of it as analyzing and exploiting the system.