Showing posts with label IT security certifications. Show all posts
Showing posts with label IT security certifications. Show all posts

Friday, February 4, 2011

New Security Certifications from Cisco

New Security Specialist certifications cover IOS, firewalls and VPNs

Cisco lists certifications in two broad categories: career certifications and specialist certifications. The career certifications include the broad and more commonly known certifications, like the CCNA, CCNP, and so on. The specialist certifications cover a narrower range of topics - sometimes directly overlapping with the technology in the career certifications, and sometimes covering topics outside the career certifications.
 
Before this week, Cisco already had several specialty certifications related to security. Cisco's adding three back to the mix this week:

  
  • Cisco IOS Security Specialist
  • Cisco Firewall Security Specialist
  • Cisco VPN Security Specialist

How do you get these? Well, you simply pass one or two of the current CCNP Security exams, and meet the pre-requisite of needing a current CCNA Security certification. These certs map directly to the exams in the new CCNP Security certification. If you pass all four exams to get your CCNP Security cert, you could earn 5 total specialty certs - the three above, plus the IPS and ASA specialty certifications.
 
Cisco announces new CCNP Security career certification

 
Why the Focus on Security?

 
The bigger question that comes to mind is why all this focus on security?

 
1) Security Requires Role redundancy: Simply put, you can't go without a qualified person for short to medium periods of time. Everyone has to have some time off, go to classes and meetings, and so on, and the risk associated with having your only skilled person gone and unavailable is too much. The solution? At least have role redundancy, that is, have multiple people with real skills for each part of the security puzzle. Common sense, but this is one of the reasons highlighted by Cisco.

 
2) Security Personnel Turnover Expected to Increase: Cisco reviewed generally the assertion that demand for network security engineers will exceed the supply for the foreseeable future, and that Cisco was trying to help the market through these new exams and courses (last fall) and these new specialty certifications. Taking that at face value, it's a microeconomics 101 issue: demand exceeds supply, which drives up how much security engineers are paid. That means turnover as more security engineers go for new higher-paying jobs. And it creates an opportunity to learn security and get dragged along into job opportunities and higher pay.

 
Then, you tag team that idea with the chance of going months without key network security personnel after someone goes to a new job, then the need for role redundancy is greater - which means most organizations should be scrambling to increase security skills of the existing staff.

 
So, that's some of the substance of what I heard from Cisco. However, I was a bit skeptical, and asked if they had any publicly available data to back up the baseline assumption: security personnel demand does/will exceed supply. Cisco cited three references:

 

A 2010 CCIE survey, which showed that security is the top skill needed over the next 5 years. (Survey is dated Feb 2009.)

A 2009 Forrester research study, published on Cisco's web site. This survey asserts that managers need to focus on roles, coverage, and that managers claim that they look at certifications to validate skills. If you look closely, those certs follow behind the idea of looking for experience. (I have to admit, reading the report, it made me wonder if the objective was to favor certifications, but you can make your own assessment.)

An article on the HomelanSecurityNewsWire.com web site, which has some real evidence of the demand exceeds supply argument. In particular, this article sites competition with the private sector for security engineers and that the candidates currently filling the technical security jobs simply aren't technical.

 

 

 
origianl article by Wendell Odom http://www.networkworld.com/news/2011/020311-cisco-announces-three-security-certifications.html?page=1

Monday, November 9, 2009

CompTIA Survey Reveals: IT Pros Seeking Security Certifications

IT Pros Seeking Security Certifications, CompTIA Survey Reveals



Interest also high in ethical hacking and forensics certifications



Oakbrook Terrace, Ill., Nov. 4, 2009 – Information technology (IT) professionals are placing their bets on security-themed certifications as they plot their next career moves, a new study from CompTIA, the leading trade association for the IT industry, reveals.



The CompTIA survey of more than 1,500 IT workers found that 37 percent intend to pursue a security certification over the next five years. Another 18 percent of IT workers said they will seek ethical hacking certifications during the same time period, while 13 percent identified forensics as their next certification target. The results are included in the CompTIA study IT Training and Certification: Insights and Opportunities.



“Given the growing reach of security, with threats becoming more pervasive and dangerous and with no business or industry immune to those threats, it makes sense that many IT professionals view this as a must-have for career advancement,” said Terry Erdle, senior vice president, skills certifications, CompTIA.



Other technology areas where survey respondents said they will seek new certifications over the next five years include green IT, healthcare IT, mobile and software-as-a-service.



Economic advancement and personal growth are key drivers for seeking IT certifications, the CompTIA study also reveals. Eighty-eight percent of certification holders indicated they pursue a certification to enhance their résumé. An identical 88 percent said personal growth is a major or minor reason in their decision to pursue a certification.



IT workers are willing to invest the time and resources necessary to advance their career by adding new certifications to their credentials. On average, candidates for an IT certification spend 44.5 hours studying and preparing to sit for an exam; and approximately one in three individuals spend 60 or more hours preparing. Fifty percent of IT certification holders pay for the exams themselves, while 38 percent rely on an employer to cover the exam fee.



“This confirms that many professionals are truly committed to the IT field and take pride in developing their skills and showcasing their expertise,” Erdle said.



The web-based survey was completed by 1,537 IT professionals during the period from July 13 through July 31, 2009. Survey participants were primarily from the United States, Canada and the United Kingdom.

original article: http://www.comptia.org/News/PressReleases/09-11-04/IT_Pros_Seeking_Security_Certifications_CompTIA_Survey_Reveals.aspx

Wednesday, October 7, 2009

The Role of a Certified Ethical Hacker

The term "hacker" doesn't just apply to crooks, thieves and anyone else looking to subvert computer security systems for malevolent purposes. Some hackers are in the business of improving security. Certified Ethical Hackers are paid by companies and government agencies to test their computer systems against the sort of attacks the bad guys often attempt to pull off.

Computer infrastructure has become the foundation of businesses, governments, and militaries across the globe. Unfortunately, the onset of computer dependence has only opened a myriad of opportunities for cybercrime and potentially devastating consequences. Unlike in the past, when criminals would have to physically peculate information, cybercrime involves finding network loopholes, running snippets of code, and virtually having access to billions of bits of data within seconds.




Although many establishments that use online networks to carry highly sensitive and confidential information neglect to close these "backdoor openings" (making it too late), others have circumvented the possibility of hackers gaining entry into their data by commissioning trusted third parties to assess any vulnerabilities. Individuals such as Jonathan James, Kevin Mitnick, and Kevin Poulsen have given the term "computer hacker" a bad rap; however, their moral counterparts, ethical hackers, are able ease the minds of companies and governments.

White Hats


True ethical hackers can be certified by the International Council of E-Commerce Consultants (EC-Council) through various tests, background checks and screenings. An individual that is trained as a Certified Ethical Hacker (CEH) is often employed by a private or public network security company or department that works with private businesses, government agencies and even the military. As computers advance, the Internet evolves and networks expand, the need for Certified Ethical Hackers is growing.



The government has developed its own specific certification entitled the Certified Network Defense Architect (CNDA), which is open only to selected individuals. However, the coursework and testing is synonymous with that of a CEH. A CNDA is capable of working for the United States government and/or military. The Department of Homeland Security's National Cybersecurity Division (NCSD) directly and indirectly employs many CNDAs. These individuals constantly combat the vulnerability of the government's computer infrastructure as well as the nation's in general.



The Department of Defense's Information Processing Techniques Office (IPTO) and Defense Information Systems Agency are also homes of CNDAs. These individuals complete various tests on new military networks, software , devices and other diverse information technology-related materials. The role of these personnel is to develop gapless computer infrastructure in prohibiting malicious hacking of any branch of government and its subsidiaries. Although some ethical hackers are employed by these government agencies, others seek employment with private network security and information technology professional companies.



Private Sector

IT companies that work specifically with the security of private networks employ Certified Ethical Hackers. These third-party businesses work with firms and corporations of any trade or business. As identity theft is a major concern with the World Wide Web, companies that hold highly sensitive information are at stake to protect that data for their customers and clients. There have been various scandals in which malicious hackers have stolen an innumerable amount of personal information such as credit card numbers, Social Security numbers, names, phone numbers and addresses. Companies that keep these records on file have great concern in being confident that this information is not vulnerable to any outside source.



Furthermore, millions of individuals are starting to do all of their financial record keeping online through banks' Web sites. How would a banking company explain to their customers that a hacker had stolen all of their account numbers, names and addresses and has the potential to drain their accounts? Although it may sound far-fetched, the possibility is definitely a reality. Banks have a great deal of pressure to protect their technological mainframes -- not to mention the fact that to remain competitive with other banks, they are almost required to provide online services. Everything is being driven to the Internet these days. As more business is done through information technology, the greater the risk of crime and theft; no more iron bars, locks and brick walls to keep that money safe.



So how do all of these gaps in a technological society apply to the Certified Ethical Hacker? A CEH will be the inspector who would, in layman terms, go around after the bank was built and check for any way in or out of the secured building. After a company has established an essential network, whether it's a bank or not, a network security company of IT professionals, including CEHs, will perform vulnerability tests, or penetration tests, to check for any areas lacking security. These third-party IT companies will assess susceptible areas and develop a report for the business. The most crucial part of this process is that it takes place prior to the network going live. A company that wants to remain in business will always make this arrangement, as unsecured networks are easy targets for malicious hackers, and it only takes seconds for something to happen.



Although identity theft is a concern of the general population and businesses, there are other bits of data that a hacker may be seeking as well. What if someone intercepted emails, user names and passwords from the U.S. Department of Defense? Although hard to believe, it has been done; actually, only in September of 2000. Jonathan James, a 16-year-old from Florida, was "fooling around" and developed a back door in a server for the DoD. He was able to run a program that intercepted thousands of highly confidential emails about biological, chemical and nuclear weapons. Despite these horrifying facts, the security of this information has been fortified over the years, greatly diminishing the opportunities for malicious hacking, with partial thanks to CEHs and CNDAs.



Certified Ethical Hackers have more than a job in the IT world, as they have the privilege and know-how to keep the general population safe from cybercrime. CEHs and CNDAs play a critical role in the prevention of malevolent cyberattacks on businesses, government and military. As the potential threat toward any network, server or database is always a possibility, the profession of ethical hacking is only to grow.



original article: http://www.technewsworld.com/story/68311.html
By Ryan Corey

TechNewsWorld
10/07/09
Ryan Corey is the director of admissions at the Academy of Computer Education (ACE), a computer training school in the Washington, D.C., metro area.