Skip to main content

Information Security Certifications are Worthless and Causing More Harm than Good

https://arstechnica.com/security/2016/07/cissp-certification-how-to-hire-infosec-pros

https://www.tacnetsol.com/blogs/news/security-certifications-are-worthless-and-causing-more-harm-than-good


Here’s an excerpt from a 2016 Ars Technica article:
Recruiter Thomas Ptacek, whose Chicago-based agency Starfighter specializes in recruiting security folk, describes the CISSP as “a joke,” and claims that in his experience a job description requiring a CISSP was a warning flag to industry elite not to apply.
“I don’t think there are that many high-level practitioners outside of management who put much stock in the CISSP,” he says.
Dan Tentler, founder of the attack simulation consultancy Phobos Group, compares hiring infosec workers based on passing an exam to hiring other professionals on the same basis: “Would you feel comfortable letting a doctor be your primary care physician if all it took was to pass a written multiple choice exam?”
He believes that “ISC2 is making money hand over fist,” and that the organization is “diluting the market with people who have no idea what they’re doing.”
I concur. And I’m not alone.
Top 10 Problems with IT Certifications
5 Reasons Certifications Aren’t Worth It
Your CISSP is Worthless - Now What?
Hiring decisions based on security certifications is not only flawed, but they lead your organization into a false sense of security. This will eventually cause more harm than good.
The fact that someone is “certified” – CEH, CISSP, GICSP, insert-your-security-cert-here – does not make them a skilled and experienced security professional or a “hacker.” And it doesn’t equip them to think like a hacker either.
It simply means they know the vocabulary and they know how to pass a test. Okay, maybe they know how to install Kali, run Nmap, and launch a Metasploit payload against a Windows XP box. But any 13-year old can do that, too.
I’m fortunate and privileged to work along side some of the best skilled security experts I know. And not one of them credits a certificate for their skills and knowledge. In fact, everyone here at the company – myself included – is self-taught.
Craig Heffner, DEFCON speaker and firmware reverse engineer extraordinaire, learned his trade craft while stationed in the mountains of Afghanistan by reading books sent to him and hacking devices in his down time. No certificates needed.
Peter Eacmen, partner here at TNS, developed his innate ability to hack systems during his time at the Naval Postgraduate School. And he proved his skills by earning the coveted DEFCON Black Badge as a member of Sk3wl 0f r00t. No certificates needed.
And I was arrested for hacking in 1985. Yet I obtained my TS/SCI security clearance from the US National Security Agency in 2002. No certificates needed.
In all these cases, skills, talent, and creative thinking were developed over long periods of time and not obtained by studying for some industry certification test.
If you must obtain a security certificate for compliance or regulator reasons, so be it. But it’s practical experience and skills which hold the true value and not some hot, trendy security certification.
So please save your money and stop feeding the security certification machines. We don’t value them and neither should you.
One final excerpt from the Ars Technica article:
“A 13-year-old kid can turn your company inside out, and you have a $10 million security budget, and your CISSPs are compliant,” Tentler says. “Tell me what kind of validation you get.”

Comments

Popular posts from this blog

The Difference Between LEGO MINDSTORMS EV3 Home Edition (#31313) and LEGO MINDSTORMS Education EV3 (#45544)

http://robotsquare.com/2013/11/25/difference-between-ev3-home-edition-and-education-ev3/ This article covers the difference between the LEGO MINDSTORMS EV3 Home Edition and LEGO MINDSTORMS Education EV3 products. Other articles in the ‘difference between’ series: * The difference and compatibility between EV3 and NXT ( link ) * The difference between NXT Home Edition and NXT Education products ( link ) One robotics platform, two targets The LEGO MINDSTORMS EV3 robotics platform has been developed for two different target audiences. We have home users (children and hobbyists) and educational users (students and teachers). LEGO has designed a base set for each group, as well as several add on sets. There isn’t a clear line between home users and educational users, though. It’s fine to use the Education set at home, and it’s fine to use the Home Edition set at school. This article aims to clarify the differences between the two product lines so you can decide which

Let’s ban PowerPoint in lectures – it makes students more stupid and professors more boring

https://theconversation.com/lets-ban-powerpoint-in-lectures-it-makes-students-more-stupid-and-professors-more-boring-36183 Reading bullet points off a screen doesn't teach anyone anything. Author Bent Meier Sørensen Professor in Philosophy and Business at Copenhagen Business School Disclosure Statement Bent Meier Sørensen does not work for, consult to, own shares in or receive funding from any company or organisation that would benefit from this article, and has no relevant affiliations. The Conversation is funded by CSIRO, Melbourne, Monash, RMIT, UTS, UWA, ACU, ANU, ASB, Baker IDI, Canberra, CDU, Curtin, Deakin, ECU, Flinders, Griffith, the Harry Perkins Institute, JCU, La Trobe, Massey, Murdoch, Newcastle, UQ, QUT, SAHMRI, Swinburne, Sydney, UNDA, UNE, UniSA, UNSW, USC, USQ, UTAS, UWS, VU and Wollongong.

Building a portable GSM BTS using the Nuand bladeRF, Raspberry Pi and YateBTS (The Definitive and Step by Step Guide)

https://blog.strcpy.info/2016/04/21/building-a-portable-gsm-bts-using-bladerf-raspberry-and-yatebts-the-definitive-guide/ Building a portable GSM BTS using the Nuand bladeRF, Raspberry Pi and YateBTS (The Definitive and Step by Step Guide) I was always amazed when I read articles published by some hackers related to GSM technology. H owever , playing with GSM technologies was not cheap until the arrival of Software Defined Radios (SDRs), besides not being something easy to be implemented. A fter reading various articles related to GSM BTS, I noticed that there were a lot of inconsistent and or incomplete information related to the topic. From this, I decided to write this article, detailing and describing step by step the building process of a portable and operational GSM BTS. Before starting with the “hands on”, I would like to thank all the pioneering Hackers and Researchers who started the studies related to previously closed GSM technology. In particul