Great Circle Associates Firewalls
(February 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Use the CISSP, Luke (was Re: Certifiying Security Auditors)
From: "Paul D. Robertson" <proberts @ clark . net>
Date: Tue, 17 Feb 1998 23:58:34 -0500 (EST)
To: Anton J Aylward <anton @ the-wire . com>
Cc: Mark Teicher <mht @ clark . net>, Bennett Todd <bet @ rahul . net>, firewalls @ GreatCircle . COM
In-reply-to: <3 . 0 . 32 . 19980217202929 . 007c3160 @ mail . the-wire . com>

On Tue, 17 Feb 1998, Anton J Aylward wrote:

> >> I don't think anyone proposes such an arrangement when they refer to
> >> ``certification''; instead, they're looking for something on the lines
> >> of the CPA and CFA, where you pay a certificying organization a testing
> >> fee, sit down and take a test, and if you make the grade then you have
> >> your certificate.

The problem is that the basic principles of accounting are fairly 
straight-forward, and numbers work the same for everyone.  While the 
particular CPA or CFA you choose may be better or worse than another 
in terms of how much they save you, the basics always work.  Security 
tends to be implementation specific and acceptable risk models vary per 
installation.  If we all made up our own mathematical policies, and 
purchasing's number system was a little different than payroll's  we'd see 
the same problems with CPAs.  

> Right.
> I propose we shut up and get on with using the CISSP.
> If you don't know what the CISSP is, look at the ISSA, CSI
> and (ISC)2 sites.  Look at Charles Cresson Wood's article on why
> the CISSP is relevant as a security certification.

Having seen the reasoning, misunderstandings, and questions of quite a few 
folks with CISSP certifications, it's about as useful as a CNE in my opinion.  

<soapbox>

I think it's high time the computer industry started realizing that 
certification classes are not a valid substitute for real-world 
experience and stopped perpetuating the folly.  

</soapbox>

Paul
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
proberts @
 clark .
 net      which may have no basis whatsoever in fact."
                                                                     PSB#9280



Follow-Ups:
References:
Indexed By Date Previous: Re: Certifiying Security Auditors
From: rdew @ el . nec . com (Bob De Witt)
Next: RE: Security Auditor versus Security Auditor
From: Anton J Aylward <anton @ the-wire . com>
Indexed By Thread Previous: Use the CISSP, Luke (was Re: Certifiying Security Auditors)
From: Anton J Aylward <anton @ the-wire . com>
Next: Re: Use the CISSP, Luke (was Re: Certifiying Security Auditors)
From: Jeromie Jackson <jeromie @ garrison . com>

Google
 
Search Internet Search www.greatcircle.com