Infosec Certifications: The Very Good, The Almost Good and The Really Ugly
Infosec Certifications: The Very Good, The Almost Good and The Really Ugly
CERTIFICATIONS
THE VERY GOOD, THE ALMOST
GOOD AND THE REALLY UGLY
18-Jun-2014
Lucian Corlan [email protected]
MSc InfoSec CISSP OSCP CISA SABSA CCNA Security CISM CSSLP(a) CEH
Cristian Serban [email protected]
SABSA OSCP CEH OSWP Security+ ISO27001 Auditor GIAC MCAD
#1 CompTIA SECURITY+
#2 CRISC
#3 CISM
#4 CISSP
#5 OSCE
#6 LPT
#7 CREST ACE/ICE
#8 GIAC Security Essentials
#9 CEH
#10 OSCP
https://www.linkedin.com/pulse/top-10-cyber-security-certifications-2015-sid-vanderloot
Exam Details
◦ 125 multiple choice questions
◦ duration 4 hours
◦ passing score 70%
CONFIDENTIAL and not for reproduction without prior written consent. © of The Sporting Exchange Limited. 7
CONFIDENTIAL AND NOT FOR REPRODUCTION WITHOUT PRIOR WRITTEN
CONSENT. © OF THE SPORTING EXCHANGE LIMITED.
7
ISECOM
Institute for Security and Open Methodologies
began with the release of the OSSTMM, the Open Source Security
Testing Methodology Manual
8
Silensec
9
OFFENSIVE security
OSCP & OSCE
CREST is a
not for profit
organisation
that serves the
needs of a
technical
information
security
marketplace
that requires
the services of
a regulated
professional
services
industry.
13
14
SANS
Information Security
Exam
◦ administered biannually (June & December)
◦ in limited locations worldwide (only in Bucharest for Romania)
◦ 200 questions multiple choice – four hours
◦ submit verified evidence of five (5) years of work experience in the field of information security
◦ 3 of the 5 years of work experience must be gained performing the role of an information security manager
Maintain CISM
◦ annual maintenance fee
◦ annual minimum of 20 CPE hours
◦ minimum of 120 CPE hours for a three-year reporting period
CISA certificate can be applied for if the following conditions are met + passed the CISA exam
◦ experience as an auditor of information systems
◦ compliance with Code of Ethics
◦ continuous training - CPE
◦ compliance with the standards for audits of information systems
Sample question:
A security domain X comprises a set of security elements. All of these elements are also security elements of domain Y, but Y
also contains other additional security elements. Which ONE of the following statements is TRUE?
A. Y is a subdomain of X
B. X is a subdomain of Y
C. X and Y are equivalent domains
D. X is a subdomain of Y
20
CISSP
Certified Information Systems Security Professional
International Information Systems Security Certification Consortium
◦ vendor-neutral certification
Requirements
◦ five years of direct full-time security work experience in at least two CBK domains
◦ accept the CISSP Code of Ethics
◦ criminal history and related background
◦ pass multiple choice exam, 250 questions, six hours, 700/1000 possible points
◦ endorsed by another CISSP
◦ annual fee 85$ + renew by submitting Continuing Professional Education (CPE) credits
23
Q&A