Security Certifications

Slides:



Advertisements
Similar presentations
Perspectives 2008 Canadian Live Learning Overview Ronda Warrick | Product Marketing November 6, 2008.
Advertisements

Reasons to Become CISSP Certified Keith A. Watson, CISSP CERIAS.
DoD Information Assurance Certification
1 Presented by Mark D’Ermes Director of Recruiting Wednesday May 16 th, 2012 Managing Your InfoSec Career An Employers Perspective This document is confidential.
Security and Personnel
Role of Vendor Technologies in the Development of Network Professionals Mak Sharma and Sharon Cox School of Computing, Telecommunications and Networks.
StanSource Inc. is Information Technology services and solutions providing organization engaged in providing a full range of solutions and services to.
EC-Council | Press The Security Books You Have Been Waiting For!
IEEE Computer Society Name Title, IEEE Computer Society The community for technology leaders.
IT Security Learning Path March IT Security Learning Path 0-1 years2-3 years5-10 years IT Security Beginner IT Security Intermediate IT Security.
UMBC TRAINING CENTERS © 2010, Paladin Group, LLC Certified Information System Security Professional (CISSP)
CIT 694 Introduction. CISSP Certified Information Systems Security Professional “The credential for professionals who develop policies and procedures.
(c) 2004 Allan Berg Building the Security Workforce of Tomorrow Allan Berg University of Dallas Graduate School of Management.
Security Certification
Slides copyright 2010 by Paladin Group, LLC used with permission by UMBC Training Centers, LLC.
What is CISSP Anyway? A Presentation by: George L. McMullin II, CISSP COO, CorpNet Security, Inc. Executive Director, NEbraskaCERT.
The Road to the Microsoft MCITP Certifications and Other Topics Networking Curriculum.
Certified Information System Security Professional (CISSP)
The Top Ten of Security. Ten best practices for securing your network. Ten best security web sites. Eight certifications.
Certification and Training Presented by Sam Jeyandran.
1 © (ISC) 2, 2002 INTERNATIONAL INFORMATION SYSTEMS SECURITY CERTIFICATION CONSORTIUM, INC. Andreja Satran, (ISC)2 & ITIL Manager qSTC - (ISC)2 Certified.
W. Hord Tipton, CISSP- ISSEP, CAP, CISA (ISC)² Executive Director.
A Collaborative Approach to Employee Development & Corporate Citizenship Corporate Affiliate Program.
The Importance and Benefits of IT Certification Presented by Steve Delahunty Board Member Emeritus Network Professional Association NETWORK PROFESSIONAL.
Essential Enterprise IT Governance with COBIT®5 Date: 7 th and 8 th October 2015 Time: 9 am to 5.30 pm Venue: Iverson Associates, Center Point Bandar Utama,
Michael Bender - MCT, MCITP, VCP Madison College Computer Systems Administration.
Solutions for BDMHS  JF&C is a highly qualified company that performs a wide variety if technical services in the Chicago land area to business, government.
CODP Certified Organization Development Professional September 2015.
CISSP Thomas Moore. Thomas Moore, Ph.D., EMBA BCSA BCSP LCNAD CISM CISSP LMNOP (Licensed Microsoft Network Operations Professional) B.S. No, really, in.
Hosted by Staffing Security Positions How To Choose The Right Personnel Jeffrey Posluns, CISA, CISSP, SSCP, CCNP, GSEC SecuritySage Inc.
Security+ Brian E. Brzezicki. About Me Instructor Brian E. Brzezicki Bachelor of Science, Computer.
CSTE Quality-Assurance Certified Software Test Engineer Visit:
Certified Information System Security Professional (CISSP)
2 Information System Security Association ISSA Buffalo Niagara Introduction to CISSP Study Sessions.
COG-105 Cognos IBM Cognos 8 BI Technical Specialist Visit:
JN0-120 Juniper Networks Certified Internet Associate, E-series Visit:
Computer Security Fundamentals by Chuck Easttom Chapter 11 Network Scanning and Vulnerability Scanning.
CSCE 727 Industry Certifications in IA. Global IA Workforce Trends A Frost & Sullivan Market Survey Sponsored by (ISC) 2® Prepared by Robert Ayoub, CISSP,
HP0-794 HP Implementing Windows Server 2003 on HP ProLiant Cluster Solutions Visit:
Cisco Conducting Cisco Unified Wireless Site Survey (CUWSS) Visit:
Information Security Principles and Practices by Mark Merkow and Jim Breithaupt Chapter 3: Certification Programs and the Common Body of Knowledge.
Nortel Communication Server 1000 Rls5.0-BCM Rls.4.0 Multi-site Visit:
Computer & Info Security Instructor: David Wilkeson, CISSP Class Website: Grades.
HCNA-CC Huawei Certified Network Associate Contact Center (HCNA-CC) validates the basic knowledge and skills required by a contact center. With the HCNA-CC.
2 Overview With active participation from individuals and chapters all over the world, the Information Systems Security Association (ISSA)
Free Social Media Management Tool
New York Bar Exam WEBINAR June 2017.
1Y0-972 Citrix MetaFrame® Password Manager Administration
DoD Information Assurance Certification
CISSP-ISSEP® - Certified Information Systems Security Professional
MOS-O2K Microsoft Microsoft Outlook 2000
Top 10 DevOps online Resources to learn Share & Practice by scmGalaxy
HP0-891 HP Implementing HP XP1024/128 Array Solution Fundamentals
ISSAP Class A. Padgett Peterson, P.E., CISSP 24 August, 2011
ICDL-NET ICDL The ICDL L4 net exam
HP0-171 HP HP Networked Storage Sales Professional
ISA 400 Management Information Security
Nortel Nortel Secure Router Rls.3.0 Configuration Management
The Path of the PC Tech Chapter 1.
Cert Store Solution is a platform of 100+ IT professionals and having 500+ IT/Security and Academic courses. Cert Store is the Gold and Accredited partner.
2018 New CheckPoint Exam Dumps Killtest
What does it take to become a CPA?
Building the Security Workforce of Tomorrow
Building the Security Workforce of Tomorrow
Computer Security Fundamentals
HP0-J16 HP Introduction to SANs
CS 490/CIS 790 Information System Security
Security week 1 Introductions Class website Syllabus review
000-M16 IBM M16 IBM Rational Change and Release Management Tech Sales Mastery v1 Visit:
000-M24 IBM IBM Rational AppScan Technical Sales Mastery Test v1
Presentation transcript:

Security Certifications NEbraskaCERT by Aaron Grothe/CISSP/Security+ & Bob McCoy/CISSP/Security+

Introduction Disclaimers General Points Certifications Summary General Purpose Security Specialization E.g. Computer Forensics Vendor Other Summary Resources

Disclaimers All opinions are mine/Bob's NEbraskaCERT does offer CISSP training not affiliated with ISC2 NebraskaCERT will be offering a chance to sit for the CISSP exam this August 2 at our conference NebraskaCERT may also be offering another training/certification program this year such as NSA IAM All values listed are subject to change

General Points Certifications are not a substitute for experience Certifications vary widely in their quality Be wary of most certifications that are bundled with training Bootcamps with exams at the end might get you a certification, but how much will you retain You probably won't find out which problems you got wrong – in some cases such as CISSP you won't even get a score

General Points Slides will be on the website (http://www.nebraskacert.org) in the next couple of days

General Certifications Check Point Certified Security Principles Associate CompTIA Security+ ISC2 CISSP ISC2 SSCP ISC2 area of concentrations

General Certifications (Cont) ISACA CISA ISACA CISM SANS GIAC Security Engineer TruSecure TICSA

Check Point Certified Security Principles Associate (CSPA) Vendor Checkpoint Exam Format Multiple Choice Recertification Requirements N/A Vendor Specific No Cost $150

Check Point Certified Security Principles Associate (CSPA) Value (Subjective) Medium Pros Entry level certification for Check Point Emphasizes Basics Might Supplement other certifications Known Name Cons Potential confusion “what do you mean you don't know how to configure a firewall”

CompTIA Security+ Vendor Exam Format Recertification requirements Multiple Choice Exam 100 questions Recertification requirements None Vendor Specific No Cost $225

CompTIA Security+ Value (subjective) Pros Cons Low Can be taken through Prometric/VUE centers Good entry level certification Can be used to cross certify for some other certifications such as Microsoft Lots of study material available Cons Entry level certification

ISC2 Certified System Security Professional (CISSP) Vendor ISC2 Exam Format 1 Exam 250 questions 6 Hours Recertification requirements Continuing Education Credits & annual fee Vendor Specific No Cost $499 Early Registration, $85 Recert fee

ISC2 Certified System Security Professional (CISSP) Value (Subjective) Very High Pros Gold standard Wide breadth of topics Cons Not as rare as it used to be :-) Limited exam availability Need professional Experience No scores

ISC2 System Security Certified Practitioner (SSCP) Vendor ISC2 Exam Format 1 Exam 125 multiple choice questions 3 hours Recertification Requirements Continuing education requirements & Annual Fee Vendor Specific No Cost $369 Early Registration, $?? Annual Fee

ISC2 System Security Certified Practitioner (SSCP) Value (Subjective) High Pros More easily attained than CISSP Lower requirements Cons Exam availibility restricted as CISSP Considered by some as a junior CISSP

ISC2 Area of Concentrations ISC2 offers the following 3 areas of concentrations Information System Security Engineering Professional (ISSEP) – Developed with NSA ISSMP stands for Information System Security Management Professional (ISSMP) - Management ISSAP stands for Information System Security Architecture Professional (ISSAP) - Architecture

ISC2 Area of Concentrations Exam Format 1 Additional Exam – 100 questions Recertification requirements Continuing education credits & Annual Fee Vendor specific No Cost ~$300

ISC2 Area of Concentrations Value (subjective) Probably High Pros Build upon CISSP Buzz word worth Cons Market hasn't set value yet Lack of study materials

ISACA Certified Information System Auditor (CISA) Vendor ISACA Exam Format 1 Multiple choice exam 200 questions 4 hours Recertification requirements Continuing education credits and annual fee Vendor Specific No Cost $465 Exam Fee, $85 Annual Fee

ISACA Certified Information System Auditor (CISA) Value (subjective) Very high Pros Good name recognition outside of Computer Security Folk Not particularly technical Cons Only offered once a year Experience requirements

ISACA Certified Information System Manager (CISM) Vendor Information System Audit and Control Association Exam Format 1 Multiple choice exam 200 questions 4 hours Recertification requirements Continuing education credits and an annual fee Cost $465 exam fee and $85 annual fee

ISACA Certified Information System Manager (CISM) Value (Subjective) Moderate Pros Complements CISA Cons Not as well known as CISA Confused with CISSP by many Offered only once a year in June Lot of people offered chance to get CISM without taking exam

SANS GIAC Security Engineer Vendor SANS Exam format Multiple choice exams Recertification Requirements Continuing education credits Vendor Specific No Cost 7 Exams at $250, $1250

SANS GIAC Security Engineer Value (Subjective) Very High Pros The “other” security certification Areas of specialization Is more than just an exam Cons Almost a way of life

TruSecure ICSA Certified Security Associate (TICSA) Vendor TruSecure Exam Format 70 question format, multiple choice Recertification requirements Valid for 2 years, Recert plan being developed Vendor Specific No Cost $295.00

TruSecure ICSA Certified Security Associate (TICSA) Value (subjective) Medium Pros Alternative to Security+ for first security certification Appears to have more technical content TruSecure/ICSA has some recognition Cons None, really

Specialized Certifications Certified Wireless Security Professional (CWSP) Certified Ethical Hacker Certified Computer Examiner Certification

Certified Wireless Security Professional (CWSP) Vendor Planet 3 Wireless Prereqs CWNA (Certified Wireless Network Administrator) Exam Format 1 CWNA, 1 CWSP Multiple choice, 60 questions Recertification requirements N/A Cost $150 per exam

Certified Wireless Security Professional (CWSP) Value (subjective) High Pros Wireless is hot area right now Some room for growth in certification path Cons Planet 3 Wireless??? How does this compare to Cisco's

Certified Ethical Hacker Vendor EC-Council (E-Commerce Consultants) Exam Format 125 questions multiple choice Recertification requirements N/A Vendor Specific No Cost ~$250

Certified Ethical Hacker Value (subjective) N/A Pros “Ethical Hacker” title is cool Can take test online Tool based Cons EC-Council Market has yet to place any value on it

Certified Computer Examiner Certification Vendor Certified Computer Examiner.com Exam Format Multiple choice exam Hands on testing Recertification requirements N/A Cost $345, plus potential fees for media

Certified Computer Examiner Certification Value Subjective Relatively High Pros Forensics are hot right now Actually have to recover data off a drive Cons Vendor is not well established yet

Vendor Vendors offer security certifications for their products Checkpoint Cisco HP Microsoft Network Associates (Sniffer Pro) Novell Sun Symantec

Other These are a few other certifications which might be encountered Brainbench offers a variety of certifications including HIPPA and Internet Security Security Certified Program offers several certifications such as Security Certified Network Professional (SCNP) IEEE was working on a certification program

Other CIW offers the CIW Security Analyst certification Ideahamster has several Open Source certification programs, most are tied to training – they make a lot of great information available on their site

Summary Possible Certification Paths Security+ -> TruSecure -> CISSP Vendor Specific Area of specilization Brainbench offers free online sign up and some older exams for free Good chance to get back in habit of taking tests

Summary How to get Continuing Education Credits CSFs qualify Give a talk Attend a security conference Write an article for a security magazine or an article about security

Resources (High Level) CertCities http://www.certcities.com GoCertify http://www.gocertify.com

Resources (General Certs) Certified Computer Examiner http://www.certified-computer-examiner.com/ CompTIA http://www.comptia.com CWSP http://www.cwne.com ISC2 http://www.isc2.org

Resources (General Certs) ISACA http://www.isaca.org Sans http://www.sans.org TruSecure http://ticsa.trusecure.com

Resources (Vendors) Check Point Cisco HP Microsoft http://www.checkpoint.com Cisco http://www.cisco.com HP http://www.hp.com Microsoft http://www.microsoft.com

Resources (Vendors) Network Associates Novell Symantec http://www.networkassociates.com Novell http://www.novell.com Symantec http://www.symantec.com

Resources (Other) Brainbench Security Certified Program CIW IEEE http://www.brainbench.com Security Certified Program http://www.securitycertified.net CIW http://www.ciwcertified.com IEEE http://www.ieee.org Idea Hamster http://www.ideahamster.org

Contact Info E-mail addresses grothe@earthlink.net bob@mccoy.net