Posts

Showing posts with the label certification

The Value of Branding and Simplicity to Certifications

Image
At the risk of stirring the cyber pot (item 3, specifically) I wanted to post a response to a great mailing list thread I've been following. A reader asked about the value of the CISSP certification. Within the context of the mailing list, several responders cited their thoughts on SANS certifications. Many mentioned why the CISSP tends to be so popular. I'd like to share my thoughts here. In my opinion, the primary reason the CISSP is so successful is that it is easy to understand it , which facilitates marketing it. It is exceptionally easy for a recruiter to search LinkedIn profiles, other databases, or resumes for the term "CISSP." If you encounter a person with the CISSP, you basically know what the person had to do to get the certification. Before continuing, answer this quick question: what are the following? 1) SSCP, 2) CAP, 3) CSSLP? Let me guess -- you didn't recognize any of them, just like I did? Now, let me see if you recognize any of the fo...

NSA IAM and IEM Summary

Image
Two years ago I wrote Thoughts on NSA IAM Course . That post is still in the top ten Google search results for NSA IAM, which is sad because that means there isn't much about the program online. IAM stands for INFOSEC Assessment Methodology. (Ugh, I hate " INFOSEC ".) The only real material about IAM (beyond the public slides used to teach the classes appears in Security Assessment: Case Studies for Implementing the NSA IAM by Russ Rogers, Greg Miles, Ed Fuller, Ted Dykstra. The Syngress sample chapter nicely summarizes the IAM purpose and compares it to alternatives. The National Security Agency (NSA) Information Security (INFOSEC) Assessment Methodology (IAM) is a detailed and systematic method for examining security vulnerabilities from an organizational perspective as opposed to a only a technical perspective. Often overlooked are the processes, procedures, documentation, and informal activities that directly impact an organization’s overall security posture ...

Thoughts on Latest CISSP Requirements Change

You all know I am a big fan of the CISSP certification. (If you don't recognize that as sarcasm, please read some old posts.) I wasn't going to comment on the press release (ISC)²® to Increase Requirements for CISSP® Credential to Validate Information Security Expertise , but no one else really has. First, a little history. The last time a requirements change was announced was January 2002, in the press release (ISC)² TO IMPLEMENT NEW CISSP REQUIREMENTS IN 2003 . That article stated: ...new requirements for the Certified Information Systems Security Professional (CISSP) certification, effective Jan. 1, 2003. As of that date, the minimum experience requirement for certification will be four years or three years with a college degree or equivalent life experience. The current requirements for the CISSP call for three years of experience... The "equivalent life experience" provision is intended for mature professionals who did not obtain a college degree but are in...

Who Needs CISSP for Ethics?

Last year I discussed the value of the CISSP with respect to its code of ethics . Today while renewing my ISSA membership, I was presented with the following: The primary goal of the Information Systems Security Association, Inc. (ISSA) is to promote practices that will ensure the confidentiality, integrity, and availability of organizational information resources. To achieve this goal, members of the Association must reflect the highest standards of ethical conduct. Therefore, ISSA has established the following Code of Ethics and requires its observance as a prerequisite for continued membership and affiliation with the Association. As an applicant for membership and as a member of ISSA, I have in the past and will in the future: * Perform all professional activities and duties in accordance with all applicable laws and the highest ethical principles; * Promote generally accepted information security current best practices and standards; * Maintain appropriate confident...

CCNP Changes

If you're interested in earning the Cisco Certified Network Professional (CCNP) certification, you should read about changes in the cert. This TCPmag.com article is a nice summary. Basically Cisco removed some old material and added a lot more on security, wireless, and other modern topics. I would like to test for the CCNP before my CCNA expires in March 2008, but I'll wait until updated study books are available.

Certification & Accreditation Re-vitalization

Thanks to the newest SANS NewsBites (link will work shortly), I learned of the Certification & Accreditation Re-vitalization Initiative launched by the Chief Information Officer from the office of the Director of National Intelligence . According to this letter from retired Maj Gen Dale Meyerrose, the C&A process is too costly and slow, due to "widely divergent standards and controls, the lack of a robust set of automated tools and reliance upon manual review." He wants to "move from a posture of risk aversion to one of risk management, from a concept of information secuirty at all costs to one of getting the right information to the right people at the right time with some reasonable assurance of timeliness, accuracy, authenticity, security, and a host of other attributes." That all sounds well and good, but it misses the key problem with C&A -- it doesn't prevent intrusions . It may be seen as a necessary condition for "securing" a...

DoD Certification Program Update

I've had a chance to read issues of Federal Computer Weekly delivered while I was on vacation. I like reading FCW because it gives me some insight into the madness found inside the Beltway. I enjoyed reading Wanted: Information assurance-savvy people , which discussed DoD's plans for certifying IT staff. I've examined this issue before. Here's a quote by someone who understands the problems with DoD's plan: Alan Paller, director of research at the SANS Institute, said DOD should have no problem meeting its initial target of 80,000-plus employees trained and accredited in information assurance. But he doesn’t think the baseline certification that DOD requires will produce a workforce capable of securing the military’s systems. “The problem is that the bulk of the certifications don’t teach people how to do security,” Paller said. “Certified people will be able to talk about security, but they won’t know how to do it — to actually encrypt data and do the necessar...

DoD 8570.01-M Posted

Thanks to David Bianco for sending me to this article about the manual for DoD 8570.1 being posted here . The .pdf looks like a scan of a hard copy document. I couldn't search it using xpdf.

DoD Directive 8570.1 Changes Everything

Image
Last night I attended my local ISSA-NoVA meeting. I listened to Steven Busch from the Defense-wide Information Assurance Program (DIAP). He is a "Change and Workforce Management Senior Managing Consultant" with IBM working on implementing DoD Directive 8570.1 , "Information Assurance Training, Certification, and Workforce Management", which I mentioned yesterday. He's also a Marine. (Notice I said "Marine," not "ex-Marine." Even though Mr. Busch is no longer in uniform, I recognize there are no "former Marines.") I will try to summarize what I heard, with the expectation that Mr. Busch's slides will be posted at the ISSA-NoVA Web site soon. I managed to get related material from this earlier briefing (.pdf, slow). There's also a summary at (ISC)2 . The vision for 8570.1 is the following: A professional, efficiently managed IA workforce with knowledge and skills to securely configure information technology, effect...

IISFA Is Irrelevant

For the past several months, I've been receiving notices from "Marcus Lawson - ISFA" of the International Information Systems Forensics Association . IISFA is the organization that awards the Certified Information Forensics Investigator™ (CIFI) Certification . I initially thought this would be a good certification for the reasons outlined in that post and previous posts linked within it. The emails from IISFA have said the following. Subject: Your International Information Systems Forensics Association membership is past due for renewal. Dear Richard, I have good news and bad news: Bad news: your membership has, or is about to expire to the Information Systems Forensics Association. This means you will no longer be a part of the "Global Voice of Information Forensics;" you will not longer receive "The Information Forensics Journal;" and you will no longer be able to participate in ISFA events; internationally or locally. Good news: You can renew ...

Notes from Airplane Reading

Image
Last week I read several magazines on the way to DoD Cybercrime. Here are a few thoughts on what I read. From the threat and vulnerability definition department, we have the article DHS offers $765M in risk-based grants from Federal Computer Weekly : The Homeland Security Department has made $765 million available in fiscal 2006 for 35 urban areas to guard against terrorist threats, DHS Secretary Michael Chertoff announced today. The Urban Areas Security Initiative (UASI) this year follows a new, risk-based formula that allots funding according to threat, vulnerability and consequence, Chertoff said... In assigning the grants, DHS also for the first time used threat analysis from the intelligence community to look at different kinds of threats, such as transient populations, Chertoff said. Replace the word "consequence" with "cost of replacement" in the second paragraph and you have the common risk equation found in my books and elsewhere. Nice reporting, Michae...

Should I Accept New ISC(2) Certification Agreement?

Today I received an email from the International Information Systems Security Certification Consortium, Inc. , ISC(2), that read, in part: "The purpose of this notice is to provide information regarding the status of your (ISC)² certification. Our records indicate that your anniversary date is near and your Annual Maintenance Fees are current. As you are aware, a total of 120 Continuing Professional Education (CPE) credits, of which at least 80 must be Type 'A' credits, are required to be submitted during each three year certification period in order to maintain your credential. Our records indicate that, based upon your CPE submissions to date, you are not on track to meet your recertification requirements at the end of the three year period. We urge you to pay close attention to this matter to avoid the expiration of your CISSP credential." OH NO! Time for me to log in to the ISC(2) Web site to record in some of the hundreds of CPEs I haven't logged. Howeve...

Demand for a BSD Associate Certification Guide

I have an idea for a new book. For the last year I have been part of the BSD Certification Group (BSDCG). I started out as a Group member, but moved to the Advisory Board when TaoSecurity business occupied too much of my time. Last month the BSDCG published its BSD Associate Exam Objectives ( .pdf ) The document outlines all the skills a candidate for the BSD Associate cert is expected to have. However, no specifics are given. For example: 3.2.12 Change the encryption algorithm used to encrypt the password database. Concept: Given a screenshot of a password database, the BSDA candidate should be able to recognize the encryption algorithm in use and how to select another algorithm. The candidate should also have a basic understanding of when to use DES, MD5 and Blowfish. Practical: login.conf(5); auth.conf(5); passwd.conf(5); adduser.conf(5) and adduser(8) I am considering writing a BSD Associate Certification Guide . The guide will cover all of the 7 domains on the cert: 1. Ins...

BSD Certification Group Solicits Donations

The BSD Certification Group is soliciting donations to offset the costs of creating the certification. The main expense is psychometric analysis of the proposed certification exam. This is fancy talk for ensuring the test assesses what the BSD Certification Group expects to measure. The BSDCG was incorporated as a non-profit corporation (a 501(c)(3) scientific and educational charitable organization) in the state of New Jersey, but the IRS has not validated their status yet.

BSD Certification Group Publishes BSD Associate Exam Objectives

Last week the BSD Certification Group published its BSD Associate Exam Objectives (.pdf). The preface of the document explains its purpose: "This document introduces the BSD Associate (BSDA) examination and describes in considerable detail the objectives covered by the exam. The exam covers material across all four major projects of BSD Unix - NetBSD, FreeBSD, OpenBSD and DragonFly BSD. While the testing candidate is expected to know concepts and practical details from all four main projects, it is not necessary to know all the details of each one. A thorough reading of this document is recommended to understand which concepts and practical details are expected to be mastered. Throughout this document, a clear distinction is placed on 'recognizing' and 'understanding', versus 'demonstrating' and 'performing'. Certain objectives call for the mere understanding of certain topics, while others call for the ability to demonstrate performance level kn...

BSD Certification Group Publishes Usage Survey

The BSD Certification Group is looking for people to complete a BSD Usage Survey . The survey consists of 19 questions. It took me less than five minutes to complete it. You can read more about the survey in this press release and the news section. Please complete this survey if you use any of the BSDs. It will help us better design a BSD Certification for you. Thank you! Also, the August newsletter has been published, and you can track BSD certification progress at our BSD Certification Group Blog .

Thoughts on NSA IAM Course

Today I finished the NSA INFOSEC Assessment Methodology (IAM) class taught by two great instructors from EDS and hosted in the beautiful Nortel PEC building in Fairfax, VA. I attended because the rate offered by EDS through my local ISSA-NoVA chapter was an incredible bargain. I did not realize prior to the class that NSA posts the exact slides used to teach the course online . The course was much more applicable to my line of work than I realized. I've decided to apply the methodology to the assessments I perform on customer network security monitoring / intrusion detection / prevention operations. Rather than use my own methodology, I plan to use the IAM system to perform hands-off assessments of the operations customers conduct to detect intrusions. I will be performing one of these assessments in the near future, so I look forward to applying lessons from IAM to this consulting work. I am scheduled to attend the two-day INFOSEC Evaluation Methodology (IEM) class nex...

What the CISSP Should Be

Today I saw a new comment on my criticism of the ISC2's attempt to survey members on "key input into the content of the CISSP® examination." Several of you have asked what I would recommend the Certified Information Systems Security Professional (CISSP) exam should cover. I have a very simple answer: NIST SP 800-27, Rev. A (.pdf). This document, titled Engineering Principles for Information Technology Security (A Baseline for Achieving Security) , is almost exactly what a so-called "security professional" should know. The document presents 33 "IT Security Principles," divided into 6 categories. These principles represent sound security theories. For future reference and to facilitate discussion, here are those 33 principles. Security Foundation Principle 1. Establish a sound security policy as the “foundation” for design Principle 2. Treat security as an integral part of the overall system design. Principle 3. Clearly delineate the physical and...

BSD Certification Group Publishes Certification Roadmap

Yesterday the BSD Certification Group published the Certification Roadmap (.pdf). I realize I have been beaten by Slashdot on this story, but I have been either teaching or in training all week! (More on that when I have time -- I return to class tomorrow.) From the press release : "The BSD Certification Group has decided that the associate level certification, followed by the professional level certification, will be rolled out in 2006. The associate certification targets those with light to moderate skills in system administration and maps to the Junior SAGE Job Description . The professional level certification is for those with stronger skills in BSD system usage and administration and maps to the Intermediate/Advanced SAGE Job Description ." Having participated in the internal voting process for this certification, I am pleased to see a two-cert approach. We will start with the junior cert; "the test activation goal for the associate level certification is Apr...

Request for Comments on NSA IAM and NSA IEM

Does anyone have experience with NSA's Infosec Assessment Methodology and Infosec Evaluation Methodology ? Through my local ISSA chapter , I've signed up to take courses on both programs for a combined price less than that offered for the IAM alone at another venue. Being a consultant in the DC metro area, I believe I am going to hear NSA IAM and IEM mentioned more frequently. Any thoughts?