Welcome to cissp CISSP training Certified Information Systems Security Professional
Search
Nickname Password Security Code Security Code Type Security Code  

You are certified but are your qualified?  Become qualified today.


Rated #1 Training

Surveys

Where do you find the best price for books?

Amazon.Com
Bookpool.Com
The ISC2 webstore
CISSPS.COM
Cheapbooks.com
Ecampus.com
Other (Please leave a comment with name of site)



Results
Polls

Votes: 1314
Comments: 33

Who's Online

There are currently, 82 guest(s) and 11 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

Training Classes Calendar

Test of Widget

 

Security Certification Rules Could Shake Up IT Management
Posted on Tuesday, 05 May 2009 @ 15:00:29 EDT
Contributed by cdupuis | Topic: JOBS

Security Certification Rules Could Shake Up IT Management

6/25/2008 -- Requirements for professional security certification for IT workers in civilian agencies, now being readied by the Office of Management and Budget (OMB), would have a major impact on how government and industry recruit, train and manage their IT staffs, a security expert said Wednesday.

"They are going to affect every one of us in the field," contractors and government employees, said George Datesman, a senior manager at Noblis Inc., a nonprofit high-tech consultant.

Datesman -- who holds a master's degree in criminology and has 30 years experience in law enforcement, including a stint with the Justice Department -- said at a Digital Government Institute conference on cybersecurity that OMB is finalizing minimum requirements for professional certification. He had no time frame for their release.

As IT security has become professionalized, a number of certifications have achieved general recognition industrywide, including a suite from the International Information Systems Security Certification Consortium (ISC2). ISC2 maintains and administers examinations for:

  • CISSP: Certified Information Systems Security Professional
  • ISSEP: Information Systems Security Engineering Professional
  • ISSAP: Information Systems Security Architecture Professional
  • SSCP: Systems Security Certified Practitioner

Organizations awarding certifications would have to be accredited to meet a federal mandate. Datesman likened the situation to the law-enforcement field, which still is sorting out how to fully implement requirements for increased professional training and education 30 years after the movement began. Not only would there be new hiring requirements, there also could be increased responsibility and legal liability for workers and their employers.

"This is a change we have not faced in the IT security industry before," he added.

The closest parallel has been in the Defense Department, which anticipated OMB's reaction in this area. The DOD's Directive 8570 on information assurance, approved in December 2005, requires all of the department's information assurance workers to obtain an accredited commercial certification in computer security. The DOD has approved 13 certifications for the directive.

The DOD requirement already has thrown what one conference attendee called a giant monkey wrench into the IT security manpower market.

"If OMB issues a similar requirement, it's going to throw the supply-and-demand curve even more out of balance," he said.

Datesman agreed, saying it probably would take years for the supply of certified workers to catch up with demand. A CISSP certification, for example, requires five years' experience. "You don't mint them out of college," he said.

The requirement is likely to drive up the cost of recruiting professionals, not only in government but among government contractors, who also would have to meet the requirements in staffing government contracts. Government contract language also would have to change to reflect the requirements.

Other practical considerations would be the need to formally define IT security roles and jobs and spell out the knowledge, skills and abilities needed for each. Certification and training also would have to be verified by employers, possibly creating a backlog much like that for background checks in issuing personal-identity verification cards to government workers and contactors under Homeland Security Presidential Directive 12.

No amount of education and certification will completely fulfill the need for IT security professionalism, Datesman said.

"When we did this in law enforcement 30 years ago, what we learned was that 60 percent of what they needed to know is learned on the job," he said.  William Jackson, courtesy of GCN.com


Login

Nickname

Password

Security Code:
Security Code
Type Security Code

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.

Related Links

· More about JOBS
· News by boss


Most read story about JOBS:
Security Jobs, Buffalo, NY

Article Rating

Average Score: 0
Votes: 0

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad

Options

"Security Certification Rules Could Shake Up IT Management" | Login/Create an Account | 1 comment | Search Discussion
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Security Certification Rules Could Shake Up IT Management (Score: 1)
by salah99 on Tuesday, 10 November 2009 @ 10:34:02 EST
(User Info | Send a Message)

نوكيا [forum.alamye.com] العاب [www.66z.com] صور سيارات - سيارات - اخبار السيارات [www.almuraba.net] منتدى السيارات [forum.almuraba.net] منتديات [www.rwa3.com] صدى الملاعب [www.0ff0.com] حواء [www.hawaaclub.com] العاب [www.66z.com] العاب مغامرات [www.p33p.com] العاب اطفال [www.p33p.com] العاب افلام كرتون [www.p33p.com] العاب سيارات [www.p33p.com] العاب سرعة العاب تركيز [www.p33p.com] العاب طيران و فضاء [www.p33p.com] العاب طريفة العاب مسلية [www.p33p.com] العاب منوعة العاب جميلة [www.p33p.com] العاب مكياج العاب ميك اب [www.p33p.com] العاب باربي [www.p33p.com] العاب اكشن [www.p33p.com] العاب دولز [www.p33p.com] العاب بازل العاب ذكاء [www.p33p.com] العاب تلبيس [www.p33p.com] العاب جديدة 2010 [www.p33p.com] العاب دراجات [www.p33p.com] العاب رياضية [www.p33p.com] العاب رسم وتلوين [www.p33p.com] العاب طبخ [www.p33p.com] العاب برا&#157

Read the rest of this comment...




All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2007 by CCCure.Org, and the site maintainers Clement Dupuis and Nathalie Lambert. Reuse is strictly prohibited without written permission of CCCure.Org or it's maintainers.

This web site is not associated directly or indirectly with ISC2, the SANS Institute, ISACA, or other certification authority. The GCFW, CISSP, SSCP, ISSEP, ISSMP, CISA, and CISM are all the property of their respecful owners. The content of this site is provided to you freely due to the generosity of our sponsors.


  • Career
  • Magazines
  • Conferences
  • Study Books
  • Certifications
  • Training
  • Tutorials
  • Quizzes
  • Forums

  • Page Generation: 0.28 Seconds