Showing posts with label IT security. Show all posts
Showing posts with label IT security. Show all posts

Monday, November 9, 2009

CompTIA Survey Reveals: IT Pros Seeking Security Certifications

IT Pros Seeking Security Certifications, CompTIA Survey Reveals



Interest also high in ethical hacking and forensics certifications



Oakbrook Terrace, Ill., Nov. 4, 2009 – Information technology (IT) professionals are placing their bets on security-themed certifications as they plot their next career moves, a new study from CompTIA, the leading trade association for the IT industry, reveals.



The CompTIA survey of more than 1,500 IT workers found that 37 percent intend to pursue a security certification over the next five years. Another 18 percent of IT workers said they will seek ethical hacking certifications during the same time period, while 13 percent identified forensics as their next certification target. The results are included in the CompTIA study IT Training and Certification: Insights and Opportunities.



“Given the growing reach of security, with threats becoming more pervasive and dangerous and with no business or industry immune to those threats, it makes sense that many IT professionals view this as a must-have for career advancement,” said Terry Erdle, senior vice president, skills certifications, CompTIA.



Other technology areas where survey respondents said they will seek new certifications over the next five years include green IT, healthcare IT, mobile and software-as-a-service.



Economic advancement and personal growth are key drivers for seeking IT certifications, the CompTIA study also reveals. Eighty-eight percent of certification holders indicated they pursue a certification to enhance their résumé. An identical 88 percent said personal growth is a major or minor reason in their decision to pursue a certification.



IT workers are willing to invest the time and resources necessary to advance their career by adding new certifications to their credentials. On average, candidates for an IT certification spend 44.5 hours studying and preparing to sit for an exam; and approximately one in three individuals spend 60 or more hours preparing. Fifty percent of IT certification holders pay for the exams themselves, while 38 percent rely on an employer to cover the exam fee.



“This confirms that many professionals are truly committed to the IT field and take pride in developing their skills and showcasing their expertise,” Erdle said.



The web-based survey was completed by 1,537 IT professionals during the period from July 13 through July 31, 2009. Survey participants were primarily from the United States, Canada and the United Kingdom.

original article: http://www.comptia.org/News/PressReleases/09-11-04/IT_Pros_Seeking_Security_Certifications_CompTIA_Survey_Reveals.aspx

Wednesday, October 7, 2009

The Role of a Certified Ethical Hacker

The term "hacker" doesn't just apply to crooks, thieves and anyone else looking to subvert computer security systems for malevolent purposes. Some hackers are in the business of improving security. Certified Ethical Hackers are paid by companies and government agencies to test their computer systems against the sort of attacks the bad guys often attempt to pull off.

Computer infrastructure has become the foundation of businesses, governments, and militaries across the globe. Unfortunately, the onset of computer dependence has only opened a myriad of opportunities for cybercrime and potentially devastating consequences. Unlike in the past, when criminals would have to physically peculate information, cybercrime involves finding network loopholes, running snippets of code, and virtually having access to billions of bits of data within seconds.




Although many establishments that use online networks to carry highly sensitive and confidential information neglect to close these "backdoor openings" (making it too late), others have circumvented the possibility of hackers gaining entry into their data by commissioning trusted third parties to assess any vulnerabilities. Individuals such as Jonathan James, Kevin Mitnick, and Kevin Poulsen have given the term "computer hacker" a bad rap; however, their moral counterparts, ethical hackers, are able ease the minds of companies and governments.

White Hats


True ethical hackers can be certified by the International Council of E-Commerce Consultants (EC-Council) through various tests, background checks and screenings. An individual that is trained as a Certified Ethical Hacker (CEH) is often employed by a private or public network security company or department that works with private businesses, government agencies and even the military. As computers advance, the Internet evolves and networks expand, the need for Certified Ethical Hackers is growing.



The government has developed its own specific certification entitled the Certified Network Defense Architect (CNDA), which is open only to selected individuals. However, the coursework and testing is synonymous with that of a CEH. A CNDA is capable of working for the United States government and/or military. The Department of Homeland Security's National Cybersecurity Division (NCSD) directly and indirectly employs many CNDAs. These individuals constantly combat the vulnerability of the government's computer infrastructure as well as the nation's in general.



The Department of Defense's Information Processing Techniques Office (IPTO) and Defense Information Systems Agency are also homes of CNDAs. These individuals complete various tests on new military networks, software , devices and other diverse information technology-related materials. The role of these personnel is to develop gapless computer infrastructure in prohibiting malicious hacking of any branch of government and its subsidiaries. Although some ethical hackers are employed by these government agencies, others seek employment with private network security and information technology professional companies.



Private Sector

IT companies that work specifically with the security of private networks employ Certified Ethical Hackers. These third-party businesses work with firms and corporations of any trade or business. As identity theft is a major concern with the World Wide Web, companies that hold highly sensitive information are at stake to protect that data for their customers and clients. There have been various scandals in which malicious hackers have stolen an innumerable amount of personal information such as credit card numbers, Social Security numbers, names, phone numbers and addresses. Companies that keep these records on file have great concern in being confident that this information is not vulnerable to any outside source.



Furthermore, millions of individuals are starting to do all of their financial record keeping online through banks' Web sites. How would a banking company explain to their customers that a hacker had stolen all of their account numbers, names and addresses and has the potential to drain their accounts? Although it may sound far-fetched, the possibility is definitely a reality. Banks have a great deal of pressure to protect their technological mainframes -- not to mention the fact that to remain competitive with other banks, they are almost required to provide online services. Everything is being driven to the Internet these days. As more business is done through information technology, the greater the risk of crime and theft; no more iron bars, locks and brick walls to keep that money safe.



So how do all of these gaps in a technological society apply to the Certified Ethical Hacker? A CEH will be the inspector who would, in layman terms, go around after the bank was built and check for any way in or out of the secured building. After a company has established an essential network, whether it's a bank or not, a network security company of IT professionals, including CEHs, will perform vulnerability tests, or penetration tests, to check for any areas lacking security. These third-party IT companies will assess susceptible areas and develop a report for the business. The most crucial part of this process is that it takes place prior to the network going live. A company that wants to remain in business will always make this arrangement, as unsecured networks are easy targets for malicious hackers, and it only takes seconds for something to happen.



Although identity theft is a concern of the general population and businesses, there are other bits of data that a hacker may be seeking as well. What if someone intercepted emails, user names and passwords from the U.S. Department of Defense? Although hard to believe, it has been done; actually, only in September of 2000. Jonathan James, a 16-year-old from Florida, was "fooling around" and developed a back door in a server for the DoD. He was able to run a program that intercepted thousands of highly confidential emails about biological, chemical and nuclear weapons. Despite these horrifying facts, the security of this information has been fortified over the years, greatly diminishing the opportunities for malicious hacking, with partial thanks to CEHs and CNDAs.



Certified Ethical Hackers have more than a job in the IT world, as they have the privilege and know-how to keep the general population safe from cybercrime. CEHs and CNDAs play a critical role in the prevention of malevolent cyberattacks on businesses, government and military. As the potential threat toward any network, server or database is always a possibility, the profession of ethical hacking is only to grow.



original article: http://www.technewsworld.com/story/68311.html
By Ryan Corey

TechNewsWorld
10/07/09
Ryan Corey is the director of admissions at the Academy of Computer Education (ACE), a computer training school in the Washington, D.C., metro area.

Friday, February 20, 2009

IT Security Salaries on Rise; Certified Ethical Hacker Certification Up 40%

According to a new study “IT Skills and Certifications Pay Index” published by Foote Partners, salaries in the IT security space are on the rise.

"It's not just a 'slash-and-burn' recession strategy based strictly on CIOs cutting costs," said David Foote, co-founder and CEO of Foote Partners, in a news report. "It looks like a calculated effort (by CIOs), in a time of chaos and severe constriction, to smartly invest in skills and technologies that will not only tactically see them through the recession, but also ensure that (their companies) are stronger and undiminished at their core when it's over."

Overall IT security certifications pay grew 0.8 percent over the past three months, and 1.9 percent year-over-year, the report states. Certifications posting the greatest gains were the GIAC Security Essentials Certification (GSEC), which was up 46.7 percent in the fourth quarter of 2008, and the Certified Ethical Hacker (CEH) certification, up 40 percent. The Certified Information Security Manager (CISM) was also up 7.1 percent over the past quarter. Of the highest-paying IT certifications, 18 out of 42, or 42.9 percent, were related to security, the report says.

For noncertified security skills, network security management made neither gains nor losses in the past quarter, but was up 6.7 percent over the past six months, and 14.3% year-over-year, the Foote study says. Network security management and "various project-based security skills" were among the highest-paying non-certified IT skills of the past three months.