In Depth
Security Certifications? You're Certifiable
Are security certifications all they're cracked up to be? Here's your guide through the jungle of acronyms.
By Simone Kaplan
>
But no one group or individual has stepped forward to guide the security field toward a gold standard of training and education. "It's getting a little crazy right now," says David Cullinane, CPP, CISSP and president of the Information Systems Security Association (ISSA). "There are too many certifications with no distinction between them."
The proliferation of security certifications is especially confusing for CSOs, since there's no governing body to vet the certification process. "There are so many certifications coming down the pike that no one can keep track of what's real and what's not," says Cullinane, who's Washington Mutual's CISO.
Are You Experienced?
Certification certainly isn't a substitute for experience, but for security newbies, it's a way to get interviews and differentiate themselves from other job candidates. Today's reality, however, is fairly cut-and-dried: Typically, the more letters after your name, the more money you make.
"No one wants to pay for skills unless there's some proof of proficiency," says David Foote, cofounder, president and chief research officer of Foote Partners, a management consultancy. According to the company's survey data, security workers with certifications such as the CISSP and GIAC series (see "Now I Know My ABCs," this page) are paid anywhere from 6 percent to 12 percent more in bonus pay than those without certifications. The Foote survey also found that 50 percent of companies are covering the cost of certifying employees.
Consequently, security employees are seeing the incentive for taking the certification tests. "If you have a couple of years of experience, there's a pot of gold waiting for you if you get certified," Foote says.
No surprise, then, that technical certifications such as the SANS Institute's GIAC series
Some certifying bodies
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



