<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; Certification/Security+</title>
	<atom:link href="http://elamb.org/category/certificationsecurity/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>ia awareness training</title>
		<link>http://elamb.org/ia-awareness-training/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ia-awareness-training</link>
		<comments>http://elamb.org/ia-awareness-training/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 15:12:20 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Certification/Security+/Infrastructure Security/Network]]></category>
		<category><![CDATA[Certification/Security+/Operational & Organizational]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[DIARMF]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Risk Management Framework]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Security Awareness/ISSA]]></category>

	<!-- AutoMeta Start -->
	<category>awareness</category>
	<category>training</category>
	<category>competencies</category>
	<category>cio</category>
	<category>strives</category>
	<category>continuum</category>
	<category>“continuum”</category>
	<category>800</category>
	<category>awareness</category>
	<category>training</category>
	<category>competencies</category>
	<category>cio</category>
	<category>strives</category>
	<category>continuum</category>
	<category>“continuum”</category>
	<category>800</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3485</guid>
		<description><![CDATA[Information Assurance Awareness Training NIST Special Publication 800-50, is a regulation dedicated to IA Awareness Training NIST SP 800-5, Building an Information Technology Security Awareness &#038; Training Program The 800-50 includes guidance on development and sustainment of an awareness &#038; &#8230; <a href="http://elamb.org/ia-awareness-training/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1>Information Assurance Awareness Training</h1>
<p></br></p>
<h2>NIST Special Publication 800-50, is a regulation dedicated to <strong>IA Awareness Training</strong></h2>
<p></br><br />
NIST SP 800-5, Building an Information Technology Security Awareness &#038; Training Program<br />
</br><br />
The 800-50 includes guidance on development and sustainment of an awareness &#038; training IT Security (aka information assurance training) program for all users, employees and supervisors within an organization.  Having a training program is mandated by the Federal Information Security Act of 2002.<br />
</br></p>
<h2>IA Awareness Training &#8211; Roles &#038; Responsibilities</h2>
<p><strong>Agency heads</strong> &#8211; must ensure that high priority is given to effective security awareness and training for employees.  Appoint a CIO<br />
<strong>CIO</strong> – Establish overall strategy, funding, tracking and report is in place for the IT security awareness and training program<br />
<strong>IT Security Program Manager </strong>– tactical deployment, development and maintenance of the IT security &#038; awareness program.<br />
<strong>Managers</strong> – responsible for complying with IT security awareness program.  Work with CIO and IT Security Program Managers to share responsibility.  Ensure all users are trained to fulfill their security roles before access is giving.  Promote professional development  and certification of the IT staff.<br />
<strong>Users</strong> – largest audience in any organization and are the single most important group of people who can help to reduce unintentional errors.<br />
</br><br />
800-50 calls learning a “continuum”.   The continuum of learning starts awareness and builds into education.<br />
Awareness – awareness is not training.  Awareness focuses on security concerns to ensure users are mindful of basic rules and issues in a given environment.<br />
</br><br />
<block>Awareness is not training. The purpose of awareness presentations is simply to focus attention on security. Awareness presentations are intended to allow individuals to recognize IT security concerns and respond accordingly.</block> &#8211;  800-50<br />
</br></p>
<blockquote><p>Training – is a formal focused method to develop a skill for job performance.<br />
Training strives to produce relevant and needed security skills and competencies – 800-50</p></blockquote>
<p></br></p>
<blockquote><p>Education – combines multidisciplinary areas into a common body of knowledge.
</p></blockquote>
<p></br><br />
<block>Education integrates all of the security skills and competencies of the various functional specialties into a common body of knowledge . . . and strives to produce IT security specialists and professionals capable of vision and pro-active response.</block> &#8211;800-50</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/ia-awareness-training/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What Do You Love? (by google)</title>
		<link>http://elamb.org/what-do-you-love-by-google/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-do-you-love-by-google</link>
		<comments>http://elamb.org/what-do-you-love-by-google/#comments</comments>
		<pubDate>Sun, 28 Aug 2011 18:48:44 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Certification/Security+/General Security Concepts]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://rob.elamb.org/?p=44</guid>
		<description><![CDATA[Google has a search tool call &#8220;What do you love?&#8221; You type in whatever you &#8220;love&#8221; and it gives you results of books, video, emails, products and items related to what you typed in. I am a HUGE fan of &#8230; <a href="http://elamb.org/what-do-you-love-by-google/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Google has a search tool call &#8220;<a href="http://www.wdyl.com" title="What Do You Love?" target="_blank">What do you love</a>?&#8221;  You type in whatever you &#8220;love&#8221; and it gives you results of books, video, emails, products and items related to what you typed in.</p>
<p>I am a HUGE fan of Google despite my fear of the organization potential power and inevitable growth into our personal lives.  So I type in something I love.. <a href="http://www.wdyl.com/#sex" title="What Do you Love? Sex" target="_blank">SEX</a>.</p>
<p>And it gave me kittens.  WTF<br />
Why does google hate sex?  I don&#8217;t get it.<br />
The only thing better than Google would be a Google that does not wuss out about sex and porn because it might offend people.  Google is pretty strict on pornography.  </p>
<p>They recently got tough on religions.  They recently removed churches from their non-profit list.  I guess Google allows non-profits the ability to get Google Ads free!  Which shows some sort of backbone although some religious organizations are incredible (and REAL non-profits) so I hope they don&#8217;t to secular on that decision.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/what-do-you-love-by-google/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Find an IT Security Jobs</title>
		<link>http://elamb.org/find-an-it-security-jobs/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=find-an-it-security-jobs</link>
		<comments>http://elamb.org/find-an-it-security-jobs/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 14:48:32 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[Internet and Information Technology Security]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[security experts]]></category>
		<category><![CDATA[System security engineering]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=2436</guid>
		<description><![CDATA[So do you have any suggestions for someone starting out in IT Security? What certifications, knowledge, training, forums, do you suggest? They will pay for the A+ cert, Network + and Security + certification. Do you have any suggestions for &#8230; <a href="http://elamb.org/find-an-it-security-jobs/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>So do you have any suggestions for someone starting out in IT Security?   What certifications, knowledge, training, forums, do you suggest?   They will pay for the A+ cert,  Network + and Security + certification.  Do you have any suggestions for someone just starting out in security?  After CompTia what should I focus on.  Although Iâ€™m not sure yet of my final career goals, Iâ€™d like to first get a job very quickly in IT security, hopefully with the government, state, or any local government;  when I say quick I mean within the next few weeks Thanks Rob for whatever info you can suggest</strong></p>
<p>Hello,</p>
<p>If you want a job fast I would suggest checking out simplyhired.com.  I would also put my resume out on Monster.com, if you have not already done so.  If you want a security job the security+ is the way to go, but also consider doing a search on monster and simplyhired to look at the skills and certifications that employers are looking for.  Pay particular attension to keywords and phrases that they are using.  You will know the keywords/phrase because they are repeated in nearly every resume for your chosen career path and/or job title.</p>
<p><strong>How I get Jobs Fast</strong><br />
For example, in my career &#8220;system security engineer&#8221; and &#8220;information security officer&#8221; I see the following keywords/phrases over and over: security clearance, cissp, 8500, diacap.  If noticed that when I have these keywords on my resume, I get calls almost DAILY from all over the US.  Here is how you can do the same:<br />
1) Find a good job title that fits what you do or what you want to do<br />
2) Do a search for that job title [use google, simplyhired.com, monster.com, dice.com or any other search engine/job database]<br />
    &#8211; Read through the job results and try to find keywords/phrases that seem to be in most or all of the jobs listed<br />
3) Try to get as many of the applicable keywords/phrases in your resume<br />
    &#8211; Either have the skills required for the chosen job title or begin working toward them<br />
    &#8211; I am not suggesting that you put lies on your resume, you&#8217;ll have to look for job titles that you have experience &#038; skills in<br />
    &#8211; Don&#8217;t mess with stuff that completely out of your league or level of expertise, be honest on your resume<br />
    &#8211; Sometimes employers will take you if you are willing to learn the skills or earn the require certification/degree in a certain time  frame.  Put that on your resume.<br />
4) Put your resume [with keywords/phrases in place] online, as many places as you can</p>
<p><strong>Research Employer Demand in certain locations </strong><br />
I am from California and I have been trying for years to find a decent job (for what I do) there.  They&#8217;ve got them in southern California but almost none in Northern.  California seems to be lacking jobs and then they don&#8217;t want to pay comparable to the cost of living there.  I noticed that Cali has a LOT of networking jobs.  If you type in <a href="http://en.wikipedia.org/wiki/Cisco_Career_Certifications">CCNP</a> in simplyhired.com for Cali, you&#8217;ll find a lot of good paying jobs.  The problem is that CCNP is a very difficult certification to get (or so I&#8217;ve heard).</p>
<p>I would recommend checking out what sort of IT skills employers are looking for in the area you want to work.   For example, even though I have lots of certifications, most of the ones that I have [that are still active lol] won&#8217;t help me for moving back to Northern California.  I researched it and found that they are mostly looking for Network Engineers [as of 2006-2010] and my Cisco routing and switching skills are still developing.  </p>
<p><strong>Play Capitalisms Game: Start a Business</strong><br />
Another option is to start your own business.  This may sound daunting, but believe it or not my website elamb.org qualifies as a business.  It took me about 1 year to get it making money, but now it makes between $400 &#8211; 800/month without me even looking at it.  It has made as much as 2k and I know <a href="www.problogger.net">people</a> who make more in a month then many people make in a year with their blogs.  It is becoming harder and harder to be an employee.  Companies do the bare minimum to take care of employees, the economy goes in a recession (or worse) and hard working people can not find a job and the value of the dollar flutuates on a downward spiral.  It seems the only way to be comfortable in this new &#8220;capitalism&#8221; is to have multiple streams of income.</p>
<p>If you are interested, start at your states business page and <a href="http://www.google.com/search?hl=en&#038;q=start+a+business+irs&#038;aq=f&#038;aqi=g1&#038;aql=&#038;oq=&#038;gs_rfai=">here</a> </p>
<p> Thanks,<br />
 Rob E.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/find-an-it-security-jobs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Value of a (Ethical Hacker) Certification</title>
		<link>http://elamb.org/the-value-of-a-ethical-hacker-certification/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-value-of-a-ethical-hacker-certification</link>
		<comments>http://elamb.org/the-value-of-a-ethical-hacker-certification/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 05:30:47 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[CEH]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[hacker]]></category>

	<!-- AutoMeta Start -->
	<category>donâ ™t</category>
	<category>ceh</category>
	<category>certifications</category>
	<category>suppose</category>
	<category>havenâ ™t</category>
	<category>cissp</category>
	<category>consistent</category>
	<category>certification</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/the-value-of-a-ethical-hacker-certification/</guid>
		<description><![CDATA[Ok, I admit it. I have totally slacked off on getting that CEH certification. Iâ€™ve had the boot camp, Iâ€™ve amassed lots of great books and resources, Iâ€™ve even talked to some people who have passed it, but I still &#8230; <a href="http://elamb.org/the-value-of-a-ethical-hacker-certification/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p> Ok, I admit it.  I have totally slacked off on getting that CEH certification.  Iâ€™ve had the boot camp, Iâ€™ve amassed lots of great books and resources, Iâ€™ve even talked to some people who have passed it, but I still havenâ€™t been consistent about studying.  For a while I was pretty consistent.  I read the Official Study Guide and started working on an Unofficial one. </p>
<p>Why donâ€™t I have that cert yet?  I suppose I just donâ€™t feel I have a reason to have it.  It would just be for show because I donâ€™t really do pen testing.  â€™d like to, but in my job, I donâ€™t usually have the opportunity to do it or reason to do it.  Iâ€™ve already got the CISSP so I donâ€™t need the CEH for some kind of prestige.  Many hackers piss on certifications they are not impressed with them and are willing hurt anyone who flashes the credentials.  The CISSP trumps most certification.  The only real benefit for me getting it is that it would force me to get more familiar with tools like netcat and Snort which I donâ€™t use enough.  I am interested in <em>cyber kung fu</em>.  Lately, I have been more drawn to the scientific and mathematical side of technology.. the side where the innovation are born, not just mastered.  Iâ€™ve been sharpening up my math skills and plan on getting into Computer Science, Electrical Engineering or physics.</p>
<p>I havenâ€™t decided whether I want to take the CEH because I want to do something that has more depth.  I suppose I could complete the CEH, go through Computer Science and specialize in security/crypto/info assurance and follow in the foot steps of Bruce Schneier and Steve Gibson.   In the beginning, certifications were definitely a step up, but Iâ€™m in a place now where they are just ornaments, flashy bobbles I could decorate my name with when  I need an ego boost.  If my wife and kids are giving me lip I can say, â€œdonâ€™t you know I am a CISSP, A+, B, C, D, E, F, G.  You MUST respect my awesome test taking ability!â€ </p>
<p>Iâ€™ve said it before, I think certifications can be of great value.  If you work for the Department of Defense in IT you pretty much MUST have one (per DoD 8570).  Certifications can give you that extra edge against competing employees in the private sector.  Problem arise when the IT certifications value is taken out of context.  Like the 8570 which makes it mandatory to have a certain certification regardless of your experience and/or degrees.  That is a bit much.  Not everyone who passes the CISSP can configure a firewall properly.   But perhaps thats the reason the DoD wants system specific certification.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/the-value-of-a-ethical-hacker-certification/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>uCertify Software &#8211; IT Certifications</title>
		<link>http://elamb.org/ucertify-software-it-certifications/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ucertify-software-it-certifications</link>
		<comments>http://elamb.org/ucertify-software-it-certifications/#comments</comments>
		<pubDate>Mon, 10 Dec 2007 16:58:53 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<category>ucertify</category>
	<category>ucertify</category>
	<category>objectives</category>
	<category>cy0</category>
	<category>tests</category>
	<category>101</category>
	<category>certifications</category>
	<category>ucerty</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/ucertify-software-it-certifications/</guid>
		<description><![CDATA[Warning: Shameless promotion of a kick ass product!! I recently got a chance to test drive uCertify&#8217;s IT certification software. I loaded the CY0-101, Security+ PrepKit. I must say I like the software and I am thinking of getting the &#8230; <a href="http://elamb.org/ucertify-software-it-certifications/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Warning: Shameless promotion of a kick ass product!!</strong></p>
<p>I recently got a chance to test drive <a href="http://www.ucertify.com/">uCertify&#8217;s IT certification software</a>.  I loaded the CY0-101, Security+ PrepKit.  I must say I like the software and I am thinking of getting the MCSA from them (think I only have to take two test to complete it).  It features the usual  breakdown of how you performed in each of the tests objectives.   It also has Flash cards that allow you to type in answers to key points on the test&#8230; I don&#8217;t recall seeing that feature on other certification software.</p>
<p>The pricing depends on the tests you get.  But its in the double digits so its a cool little investment toward a bright future.  For those of you who are serious about certifications you know that the software (such as transcender &#8211; aka the software that must not be named), boot camps and training material can cost 100&#8242;s or even 1000&#8242;s of dollars.   </p>
<p>I think that software such as <a href="http://www.ucertify.com/">uCertify</a> is a good start toward attaining a new cert (although you can never replace a solid year of experience).  </p>
<p>As for the CY0-101.. I believe Security+ will be changing their objectives sometime in 2008.  Hopefully, uCerty will keep up with that.  Comptia sent me a few surveys about the change and a couple of co-workers that are being pushed to get the Security+ told me that they want to get it before it changes.</p>
<p>My honest opinion is that software like uCerts Prepkits are great for gauging your level of preparation.  I also recommend that you use more than one gauge (particularly on the bigger tests such as CISSP).</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/ucertify-software-it-certifications/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Which Security Certification Should I Get?</title>
		<link>http://elamb.org/which-security-certification-should-i-get/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=which-security-certification-should-i-get</link>
		<comments>http://elamb.org/which-security-certification-should-i-get/#comments</comments>
		<pubDate>Fri, 31 Aug 2007 18:22:52 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<category>degree</category>
	<category>cissp</category>
	<category>credibility</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/which-security-certification-should-i-get/</guid>
		<description><![CDATA[If you can, get the CISSP, don&#8217;t waste your time with anything else. You don&#8217;t have to make it your last cert, but (if you can) make it your first. It has become the gold standard that gives you &#8220;just &#8230; <a href="http://elamb.org/which-security-certification-should-i-get/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>If you can, get the CISSP, don&#8217;t waste your time with anything else.  You don&#8217;t have to make it your last cert, but (if you can) make it your first.  It has become the gold standard that gives you &#8220;just add-water&#8221; credibility.  You can slap those initials at the end of your name and flash a badge with your ISC2, CISSP number on it. </p>
<p>The statement above will piss off a lot of security people, but it is the truth.. the inconvenient, sad and pathetic truth.  To all you skilled hackers and IS pro&#8217;s, don&#8217;t hate the blogger, hate the game.  I didn&#8217;t create the rules, I just hack them.</p>
<p>Old school hackers and security geniuses talk MAD shit about the CISSP, but what they fail to realize is that &#8220;to hack &#8216;the man&#8217;, you have to be &#8216;the man&#8217;&#8221;.  What I mean is that playing the game is essential to your financial need$.  There are always exceptions: <a href="http://www.geek.com/adrian-lamos-continuing-hack-ventures/">Adrian &#8216;homeless hacker&#8217; Lamos</a>, <a href="http://en.wikipedia.org/wiki/Steve_Gibson">Steve &#8216;I write entire apps in assembly&#8217; Gibson</a>,  <a href="http://en.wikipedia.org/wiki/Gordon_Lyon">Gordon &#8216;I created nmap&#8217; Lyon</a>, <a href="http://en.wikipedia.org/wiki/Jeff_Moss_(hacker)">Jeff &#8216;i created defcon and sold it in 2005 for 14mil&#8217; Moss</a>, <a href="http://en.wikipedia.org/wiki/Bruce_Schneier">Bruce &#8216;i decrypted code as a fetus&#8217; Schneier</a>..</p>
<p>For average bastards like you and me, the CISSP is way to go.</p>
<p>I do agree with <a href="http://dmiessler.com/blogarchive/information-security-comparing-the-cissp-and-gsec-certifications">DMiessler</a> and <a href="http://www.mckeay.net/secure/2007/08/repeat_after_me_the_cissp_is_n.html">Mckeay</a>:</p>
<blockquote><p>&#8220;Iâ€™ve met CISSPs who canâ€™t configure a home network â€” no joke. Again, I studied for it and passed it in one weekâ€™s time, and thatâ€™s with zero previous study of the test materials.</p>
<p>More than I can a test that has a 70% first-time-pass rate thatâ€™s explicitly designed for managers and non-technical types. Itâ€™s for a wide, wide base of knowledge &#8211; not for testing whether or not youâ€™d be qualified to actually do anything.&#8221; &#8212; <a href="http://dmiessler.com/blogarchive/information-security-comparing-the-cissp-and-gsec-certifications">dm</a></p></blockquote>
<blockquote><p>&#8220;..the CISSP is not a technical certificate!  It is not now, nor was it ever meant to be, a technical certification.&#8221; &#8212; <a href="http://www.mckeay.net/secure/2007/08/repeat_after_me_the_cissp_is_n.html">mckeay</a></p></blockquote>
<p>Though you may see a couple of technical questions on the test, the over all test is pretty high level, unlike the Certified Ethical Hacker or the CCNA that ask specific technical questions about specific technical issues.</p>
<p><strong>So what should you go for on the Security Certification front:</strong><br />
Go directly for the CISSP (if you can).  The fact of the matter is that most companies, the government and foreign organization look for the CISSP.  Aside from the CCIE, I don&#8217;t know of any other technical cert that will give so much credibility (even if you don&#8217;t deserve it).</p>
<p><strong>A NOTE of caution: </strong>If you get it, be real with your self.  The CISSP does not instantly make you an expert in all ten of its domains.  It will not put an &#8220;S&#8221; on your chest and make you <a href="http://www.google.com/search?source=ig&#038;hl=en&#038;q=impervious&#038;btnG=Google+Search">impervious</a> to Kryptonite.  Its just a test. Its not an I.Q. test or the Bar.  Its just a test.  If you have passed, congradulations&#8230; now the real work begins.  Good security professionals are ALWAYs learning (even more so than your average IT guy, because we have to know the latest in IT as well as policies, some law and even some level of management).  A real CISSP should be a &#8220;<a href="http://en.wikipedia.org/wiki/Jack_of_all_trades,_master_of_none">jack of all trades, Master of ONE</a>&#8220;.</p>
<p>You should also consider that there is simply no replacement for a good degree except for <strong>experience</strong>.  The good thing about the CISSP is that it requires you to have a certain amount of experience before you even attempt it.  </p>
<p><strong>Building to the CISSP:</strong><br />
Beginner: if you&#8217;re just starting, you want <a href="http://certification.comptia.org/security/">Comptia&#8217;s Security+</a> certification.<br />
Now, if your just trying to the guy who looks at audit logs all day and report what they see, then your golden.  But if you&#8217;re serious about security, then you need to play the game, get the damn CISSP (do not pass go, do not collect $200).  It pays better than a Security+&#8230; much better.</p>
<p><strong>Serious Beginner</strong><br />
Get into any kind of Information Security position and earn some &#8220;<a href="http://en.wikipedia.org/wiki/Credibility">street cred</a>&#8220;.  You may even be in a typical IT position on a filthy help desk (sorry, I&#8217;ve done it and it sucks) you can still use it to your advantage by working your way into security tasks.  If your in the military, volunteer to be the COMSEC guy or an IAO (it&#8217;ll be easy because nobody else wants to do it).  Volunteer to work with the security guys and learn from them.  The goal is the get into the security mindset and also rack up some experience.  A degree will help to with a school that allows you to set up a lab.</p>
<p><strong><br />
Novice Security</strong><br />
After a solid year of security experience you should go for the Systems Security Certified Practitioner (SSCPÂ®).  Why the SSCP?  It will help you build toward the CISSP.  At this point, if you haven&#8217;t done so already I would recommend joining the Information System Security Association (<a href="http://elamb.org/why-information-system-security-professionals-should-join-the-issa/">ISSA</a>).  You&#8217;ll begin to network with other security folks from everything from forensics to the pentesters to information security managers (who don&#8217;t even know how to set up a network).  By this time, you should have some idea what you&#8217;d like to specialize in.  The CISSP is a great foundation as certification credibility goes, but you will need to specialize.</p>
<p><strong>The CISSP</strong><br />
I found the test challenging.  You don&#8217;t want to take it twice that is for damn sure.  Just make sure your ready.  You&#8217;ll have to have about 5 years total security experience.</p>
<p>Now checks this out:</p>
<blockquote><p>&#8220;Effective 1 October 2007, professional work experience requirements for the CISSPÂ® will increase from four to five years, and direct full-time security professional work experience will be required in two or more of the ten CISSPÂ® CBKÂ® domains.&#8221; &#8211;ISC2</p></blockquote>
<p>Even a Masters degree will only replace a maximum of 1 year of experience (sounds like *NS to me):</p>
<blockquote><p>Candidates can substitute a maximum of one year of direct full-time security professional work experience described above if they have a four-year college degree OR Masterâ€™s Degree in information security from a U.S. National Center of Academic Excellence in information Security (CAEIAE) or regional equivalent. If you hold both a four-year degree and a Masterâ€™s degree, you may only apply for a one year waiver of experience.</p></blockquote>
<p><em>*NS-non sense</em></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/which-security-certification-should-i-get/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Security Certifications: DoD 8570</title>
		<link>http://elamb.org/security-certifications-dod-8570/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=security-certifications-dod-8570</link>
		<comments>http://elamb.org/security-certifications-dod-8570/#comments</comments>
		<pubDate>Tue, 26 Sep 2006 21:24:19 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Certification/Security+/Basic Cryptography/Crypto Algorithms]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<category>8570</category>
	<category>gsec</category>
	<category>of</category>
	<category>ground</category>
	<category>the</category>
	<category>top</category>
	<category>the</category>
	<category>edge</category>
	<category>cisa</category>
	<category>fissea</category>
	<category>infoseccerts</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/security-certifications-dod-8570/</guid>
		<description><![CDATA[For Government workers doing any kind of computer security/information assurance, the new regulation, DOD 8570 is a very important document. DOD 8570, Information Assurance Training, Certification and Workforce Management, requires that all government workers (active duty, govt civilian and contractors) &#8230; <a href="http://elamb.org/security-certifications-dod-8570/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><font size="2"> </font>For Government workers doing any kind of computer security/information assurance, the new regulation, DOD 8570 is a very important document.</p>
<p><a title="Dod 8570 FAQ" href="http://elamb.org/iase.disa.mil/8570FAQAug05FINAL.doc">DOD 8570, Information Assurance Training, Certification and Workforce Management</a>, requires that all government workers (active duty, govt civilian and contractors) doing security work have a security certification.   The DoD is really trying to crack down on security.</p>
<p>Among the top security certification that you can get are the CISSP and the CISA</p>
<p><img width="386" height="272" src="http://elamb.org/Image1.gif" /></p>
<p>Getting the top certs and then further specializing could give you the edge. For example, CISSP with an CISA (auditor) would cover a lot of ground as would a CISA and an IDS/C&#038;A/Architecture specialists. It would really kick ass to cover ALL ground. This would not be difficult. Not sure if each specialization would require further certifications.</p>
<p><strong>Cost, Renown, Difficulty Comparisons:</strong><strong><a href="http://dmiessler.com/writing/infoseccerts/"><u><font size="2" color="#0000ff">http://dmiessler.com/writing/infoseccerts/</font></u></a></strong></p>
<p><font size="2">Includes: GSEC, CISSP, CISA</font><font size="2"><em>*note: GSEC is $800 and difficult</em></font></p>
<p><font size="2"><strong>Security Certs and their levels according to 8570:</strong><strong><a href="http://taosecurity.blogspot.com/2006/01/dod-directive-8570.html"><u><font size="2" color="#0000ff">http://taosecurity.blogspot.com/2006/01/dod-directive-8570.html</font></u></a></strong></font></p>
<p><font size="2">Tech level I-III &#038; Management Level I-III</font><font size="2"><em>*note: GSEC is Tech level II</em></font></p>
<p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2"><strong>Future Areas of IA Certification:</strong></font><font size="2"><strong /></font></font></font></p>
<p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2"><strong>Â </strong></font></font></font></p>
<blockquote><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2">Certification and Accreditation</font></font></font></p>
<p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2">IDS and Analysts</font></font></font></p>
<p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2">Auditors</font></font></font></p>
<p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2">CND/SP members</font></font></font></p>
<p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2">IA architectures, engineers</font></font></font></p></blockquote>
<p><a href="http://csrc.nist.gov/organizations/fissea/conference/2006/Bieber-Brief-FISSEA2006.pdf#search=%22areas%20of%20ia%20certifications%208570%22">NIST Slide on 8570Â </a></p>
<p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2">(slide 10)</font><font size="2">On a recent FISC slide I saw Red team (pentesting/hacking) among these future specializations.</font></font></font></p>
<p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2">Â </font></font></font></p>
<p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2">Â </font></font></font></p>
<p class="tags">Tags: <a href="http://technorati.com/tag/security" title="See the Technorati tag page for 'security'." rel="tag">security</a>, <a href="http://technorati.com/tag/certification" title="See the Technorati tag page for 'certification'." rel="tag">certification</a>, <a href="http://technorati.com/tag/security%2Bcertification" title="See the Technorati tag page for 'security+certification'." rel="tag">security+certification</a>, <a href="http://technorati.com/tag/cissp" title="See the Technorati tag page for 'cissp'." rel="tag">cissp</a>, <a href="http://technorati.com/tag/cisa" title="See the Technorati tag page for 'cisa'." rel="tag">cisa</a>, <a href="http://technorati.com/tag/" title="See the Technorati tag page for ''." rel="tag"></a>, <a href="http://technorati.com/tag/" title="See the Technorati tag page for ''." rel="tag"></a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/security-certifications-dod-8570/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security+ Instructor: Communications Security domain</title>
		<link>http://elamb.org/security-instructor-communications-security-domain/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=security-instructor-communications-security-domain</link>
		<comments>http://elamb.org/security-instructor-communications-security-domain/#comments</comments>
		<pubDate>Sun, 10 Sep 2006 04:17:30 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Security Awareness/ISSA]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/security-instructor-communications-security-domain/</guid>
		<description><![CDATA[Today, I did my first certification lecture. As I think about how many common public speaking mistakes I made out of nervousness, it makes me laugh. I repeated things like &#8220;um&#8221;, &#8220;and what not&#8221;, &#8220;that kind of stuff&#8221;. I studdered &#8230; <a href="http://elamb.org/security-instructor-communications-security-domain/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Today, I did my first certification lecture.</p>
<p>As I think about how many common public speaking mistakes I made out of nervousness, it makes me laugh.  I repeated things like &#8220;um&#8221;, &#8220;and what not&#8221;, &#8220;that kind of stuff&#8221;.  I studdered and stammered.</p>
<p>I did my best so I still feel good about what I did.  It is actually volunteer work for the local ISSA chapter as well as a way to get &#8220;CPEs&#8221; or Continued Professional Education points toward my CISSP certification (have to get 120 in the course of 3 years).</p>
<p>It was actually a really good refresher course for me.  I love helping people so it was a pleasure to put out some helpful material to fellow Information Security professionals, but I need to get better at public speaking.</p>
<p>Our <a target="_blank" href="http://issa-cos.org">local Information System Security Association</a> Chapter here in the Springs puts on certification classes a few times a year for Comptia Security+ and the CISSP.  I hope that they eventually drum up enough interest for certified ethical hacker course.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/security-instructor-communications-security-domain/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Training on Security+</title>
		<link>http://elamb.org/training-on-security/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=training-on-security</link>
		<comments>http://elamb.org/training-on-security/#comments</comments>
		<pubDate>Sun, 25 Sep 2005 09:09:28 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Internet and Information Technology Security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Awareness/ISSA]]></category>

	<!-- AutoMeta Start -->
	<category></category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=211</guid>
		<description><![CDATA[I will be doing training on the Security+ for the ISSA-COS.&#160; I&#39;m traing the Communcation Security portion of the test.&#160; This is one of my favorite sections.&#160; I told the ISSA guys I&#39;d do it as long as I didn&#39;t &#8230; <a href="http://elamb.org/training-on-security/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I will be doing training on the Security+ for the ISSA-COS.&nbsp; I&#39;m<br />
traing the Communcation Security portion of the test.&nbsp; This is one<br />
of my favorite sections.&nbsp; </p>
<p>I told the ISSA guys I&#39;d do it as long as I didn&#39;t have to train on Crypto which is one of my weaker subjects.&nbsp; </p>
<p>I&#39;m excited about the training because I feel like I will really be<br />
able to help people ace this test.&nbsp; Most security professionals<br />
who have been IT for more than a couple of years won&#39;t have a problem<br />
studying for it and passing it.&nbsp; </p>
<p>It really is just basic technical information security<br />
stuff.&nbsp;&nbsp; There is also a lot of support on the Internet for<br />
this test: practice tests, guidance on what to study, and<br />
encouragement.&nbsp; </p>
<p>Don&#39;t sweat this test.&nbsp; Especially if you&#39;ve studied.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/training-on-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Taking the CISSP: part 1</title>
		<link>http://elamb.org/taking-the-cissp-part-1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=taking-the-cissp-part-1</link>
		<comments>http://elamb.org/taking-the-cissp-part-1/#comments</comments>
		<pubDate>Fri, 26 Aug 2005 00:48:37 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Awareness/ISSA]]></category>

	<!-- AutoMeta Start -->
	<category></category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=173</guid>
		<description><![CDATA[I took the CISSP.Â  I really don&#8217;t know what to say about it aside fromÂ acknowledging thatÂ it was extremily difficult.Â  Andrew Briney&#8217;s article is the most accurate description of the CISSP test.Â  Briney says, &#8220;It&#8217;s a mystery wrapped in riddle inside &#8230; <a href="http://elamb.org/taking-the-cissp-part-1/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I took the CISSP.Â  I really don&#8217;t know what to say about it aside fromÂ acknowledging thatÂ it was extremily difficult.Â  Andrew Briney&#8217;s article is the most accurate description of the <a href="http://infosecuritymag.techtarget.com/2003/jun/certifiable.shtml">CISSP test</a>.Â  Briney says, &#8220;It&#8217;s a mystery wrapped in riddle inside an enigma.&#8221;</p>
<p>His other very true point:</p>
<p>&#8220;<strong>The exam is best characterized as an &#8216;inch deep and a mile wide.&#8217; Whether this makes it easy or difficult is a matter of perspective</strong>.&#8221;</p>
<p>For me the hardest part were the answers.Â  I feel like I&#8217;ve mastered the art of studying forÂ a test.Â  The fact that there is so muchÂ knowledge crammed inÂ a 250 question test makes my study techniques watered down.Â Â Its very difficult to cover all 10 domainsÂ effectively.</p>
<p>I&#8217;m not one of those bastards that can walk into a test cold (no studying, no worries)Â finishÂ in half the average time andÂ pass.Â  If I don&#8217;t study, I fail.Â  I&#8217;ve learned to live with this.Â  I know my weakness.Â  I just second guess myself too much on every answer.Â  I&#8217;m one of those guysÂ that does not believe thatÂ everything is black and whiteÂ butÂ that everything is aÂ million shades of gray.Â  For me that is where the difficulty lies.Â  The CISSP wants you to choose the &#8220;best&#8221; answer.Â  So while many or even ALL of the answers might be true, there is only one <strong>BEST</strong> answer.Â  But my best might not be your best.</p>
<p>I&#8217;ve taken many certifications.Â  They have become almost a hobby of mine.Â  In June, I took the Security+ hoping it would help prepare me for the CISSP.Â  First of all let me just say comparing theÂ the CISSP andÂ the Security+Â is like comparing Lennox Lewis&#8217; fighting styleÂ to that ofÂ some 12 year old girl fromÂ John C. Still MiddleÂ School.Â  There isÂ NO freakin&#8217; comparison&#8230; NONE, do you hear me!Â  The preparation that I put into the Security+ is what help me in my CISSP success.Â  That being said, there were aboutÂ 6 very similar questions from the Security+ that were on the CISSP but the CISSP contains ALL of the domains of the Security+ on a <strong>comprehensive</strong> level.</p>
<p>As I said, I&#8217;ve taken many certs.Â  AndÂ IÂ <strong>DOÂ NOT</strong> think that taking a test will make anyoneÂ instantly smarter or more technically skilled then some &#8220;l33t hacker&#8221; that has been cracking databases since age 12, but I DO believe some certifications have great value to the IT and Security industry.Â Â With the possible exception of the CISA, the CISSP is the most exaulted security cert you can get right now.Â  Many say that any dependency on certification is what isÂ lowering the amount ofÂ IT and security professionals with skills.Â Â While there maybe truth to that,Â I say itÂ is just another way for employers to gauge whether or not they are investing in a skilled employee.Â  Whether they choose the right candidate will ultimately be decidedÂ (just like anyoneÂ else)Â by time.</p>
<p>NO certification I have taken comes within an Astronomical Unit of the CISSP.Â  Of course I&#8217;m not an MCSE or a CCNP (though I&#8217;ve tasted the fruits of both) so perhaps there is a match in its level of difficulty.</p>
<p>Having taken the test I don&#8217;t feel I was fully preparedÂ even though I have legitamate experience in nearly all aspects of security, I read a bookÂ and studied on and off for a year before taking the test.Â  I tell you, this test beat the shit out of me.Â  They give you 6 hours to complete the test and I finished in 5 1/2 hours.Â  When I was done, I was sure I&#8217;d failed.Â  I started trying to think of ways I&#8217;d pay the companyÂ back since they would not pay for a failed certification.Â  I also started studying for the repeat.Â  I was pleasantly surprised when I got theÂ &#8221;congradulations&#8221; email.</p>
<p>Adequate study for me would have consisted of reading no less thatÂ two &#8220;600 page&#8221; books andÂ going to a boot camp.Â </p>
<p>This is the best online CISSP resource I have found: <a href="http://www.cccure.org/">www.cccure.org</a>.</p>
<p>Â </p>
<p>Special Shout outs go to the <a href="http://issa-cos.org/">ISSA COS chapter</a>Â and Mr. Proeller, so long and thanks for all the bagels.. bad, bad joke&#8230;42.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/taking-the-cissp-part-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

