SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> No Category

Certification more political than practical

Certification more political than practical

By:  Vince Tuesday  On: 18 Apr 2002 For: Channelworld India 

Some months ago, I proudly earned my Global Information Assurance Certification (GIAC) in network intrusion detection from the Bethesda, Md.-based SANS Institute Inc. I was impressed by the technical depth of the course and by the difficulty of the evaluation process.

Some months ago, I proudly earned my Global Information Assurance Certification (GIAC) in network intrusion detection from the Bethesda, Md.-based SANS Institute Inc. I was impressed by the technical depth of the course and by the difficulty of the evaluation process.

I'm confident that any potential hires with this certification will know one end of a TCP packet from the other. But whether they would ever get to use that knowledge in a commercial environment is a different question. The certification process goes much technically deeper than any security professional ever needs to in our environment.

That depth comes with a price, in terms of breadth. To cover network intrusion-detection systems in such detail means that host-based detection systems and other subjects are skimmed over. I recently completed my Certified Information Systems Security Personnel (CISSP) exam and found that it has gone to the opposite extreme, sacrificing much-needed depth for breadth. So are such certifications worth it? Perhaps, but not for the reasons you read about in the marketing literature.

Claims vs. Reality

The SANS Institute has data showing that people with a GIAC earn 12 per cent more than staffers without the qualification. This is a cute statistic, but one with questionable meaning: Better-funded companies are more likely to send their employees for GIAC certification and are more likely to pay them better. Professionals with the certification are generally more senior and experienced than non-certified staff. This doesn't prove that the GIAC raises your income.

I'd like to see statistics on the salary levels of staffers who fail their GIAC test, but I know I won't anytime soon.

Despite the inflated salary claims, the SANS courses offer good training. We have sent staffers to courses and they have enjoyed themselves and improved their technical knowledge.

However, a review of job postings will show that the GIAC isn't well known. I found 2,990 security job listings, of which seven mentioned GIAC and 11 mentioned SANS. A qualification requested for 0.6 per cent of jobs isn't going to set the world on fire.

There is one certification that does a little better. The CISSP was mentioned in 75 job descriptions, or 2.5 per cent of the jobs. That's better, but it's still not great. A more interesting statistic is that more than 70 per cent of the jobs that required a GIAC also required the CISSP.

Friends told me of recruitment agents who refused to put their résumés forward for appropriate jobs because they didn't have their CISSP. I also kept seeing CISSP books sticking out of people's bags on the subway, so I decided to pursue the certification myself.

The CISSP is administered by the International Information Systems Security Certification Consortium Inc., also known as (ISC)². It offers weeklong exam preparation courses, but because no courses in my area were convenient, I relied on books for my training.


Sign up for our Newsletters
Tags: Statistics












Print |  Views: 575   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Vince Tuesday Vince Tuesday is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Red Hat to train Linux architects in Singapore
Red Hat to train Linux architects in SingaporeWith Linux bagging more “prime time” in the enterprise, there is now a growing demand in the region for certified professionals to work on major open-source projects. Open source solutions provider, Red Hat, says this is a key reason why it is ramping up its certification and training services for Linux professionals.
Better validation for security pros
Better validation for security prosThe Global Information Assurance Certification (GIAC) has announced sweeping changes to its testing process that will allow the certification to better validate the skills of security professionals.
True grit
True gritHow can CIOs make sure that their IT employees keep up with the furious pace of technology? Traditional training options might provide the solution, but sometimes bolder action is called for.
IT managers: Ambassadors of first impressions
my sister-in-law, who recently graduated from university, is trying to get her career off the ground. as we all know, though, getting
Should I Get Certified?
by jason w. eckertin the 1980s, business-class computers and computer networks were difficult to configure and maintain. if you hired someone to set up a computer network or administer network servers, that person probably had a degree in computer science, science, math or engineering since those were typically the only university programs that exposed students to the
What Certifications Should I Write
by jason w. eckertso you have decided that you want to get certified.now, you must choose what to get certified in. not an easy task. in short, you should always choose certifications that will give you a return on your investment. the cost of certification doesn’t just involve the up-front cost that you pay a testing centre to take a certificati
blog comments powered by Disqus