Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

221–224 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#221

Earlier quoted context omitted.

I really don't think you're following the point. Lawyers and doctors deal in interacting complex systems of rules. So do information security people. If you can make a certification that works for one expert in dealing with interacting complex systems of rules, you absolutely can make a certification for another expert in dealing with interacting complex systems of rules. The details of what you test are different, b…

No, you can't. That isn't how security works. Your offensive adversary follows no rules. They exist to break any rules you can think of. You can make all the rules you want and you can test people on their knowledge of them. Hackers do not care. On the defense side, they simply do not work. Everybody gets hacked. The best companies with the biggest security budgets employing people at the cutting edge of security res…

People still die. People still lose lawsuits. I-85 still partially collapsed. Yet people can be certified as knowing and following best practices in those fields.

Re: Security Certifications Are Causing More Harm Than Good

#222

Earlier quoted context omitted.

I really don't think you're following the point. Lawyers and doctors deal in interacting complex systems of rules. So do information security people. If you can make a certification that works for one expert in dealing with interacting complex systems of rules, you absolutely can make a certification for another expert in dealing with interacting complex systems of rules. The details of what you test are different, b…

No, you can't. That isn't how security works. Your offensive adversary follows no rules. They exist to break any rules you can think of. You can make all the rules you want and you can test people on their knowledge of them. Hackers do not care. On the defense side, they simply do not work. Everybody gets hacked. The best companies with the biggest security budgets employing people at the cutting edge of security res…

Illness doesn't follow rules the doctor dictates. Rainfall and earthquakes aren't set by the engineering boards. How people adjust, prepare, and respond are where the rules humans can set work. Everything else is unchangeable rules.

In computers, as in some parts of law, we have ample opportunity to address underlying rules as well as the rules around how we adjust, prepare, and react.

Re: Security Certifications Are Causing More Harm Than Good

#223

Earlier quoted context omitted.

That's an impressive resume of roles, but security is more than just those areas. I think the grandparent is trying to say that the CISSP is largely for non-technical security roles. People that manage large security organizations are generally believed to be the ones that benefit from the CISSP as they are not interested in the details and more on a 1000 foot strategic view. Without knowing more details about the yo…

In 10+ years consulting for Fortune 100 companies, zero is the number I have seen with 400+ security staff. A 50 person security team is enormous even by the standards of financial services.

Well then your exposure is limited. Boeing's corporate information security organization has around that number, as do several of the other major defense contractors.

Re: Security Certifications Are Causing More Harm Than Good

#224
post #189

Earlier quoted context omitted.

That's an impressive resume of roles, but security is more than just those areas. I think the grandparent is trying to say that the CISSP is largely for non-technical security roles. People that manage large security organizations are generally believed to be the ones that benefit from the CISSP as they are not interested in the details and more on a 1000 foot strategic view. Without knowing more details about the yo…

Have you actually looked at the CISSP material recently? It's a hodge-podge of everything under the sun. The only thing it's able to prove is that a) you have endurance and spare time to sit for a 4-6 hour multiple choice test b) you can commit to rote memory a bunch of meaningless material which you are unlikely to encounter in real security/risk management role It truly is the worst of the bunch, but for reasons ye…

I haven't looked at it in years, but that hodge-podge of material was more than enough to provide an executive with the basics that they needed to know to manage an IS organization which IMO is the goal of the certificate. As others have mentioned, it is a management cert, not one for normal use.

There are plenty of worse certificates out there - I would argue that the CEH is probably the worst one at the moment (although they are making some changes to improve)

Post reply on HN