Send to a friend Print

Risk Management

Do security certifications have credibility?

Author:
Marcia Savage, Features Editor
Posted:
11:48 04 Jun 2007
Certifications can be one way to evaluate security consultants, but opinions vary as to their value.

The CISSP carries weight and can eliminate some of the "riffraff," says Paul Fistori, vice president of channel sales and strategic partners at security vendor Vericept. Depending on the work, Global Information Assurance Certifications and some vendor certifications can be important, some consultants say.

As a CISSP, Joseph Granneman, CTO/CSO of Rockford Health System, looks for that credential. However, it "covers so much, I don't know if you can use it other than just an initial qualification," he adds.

When she worked at Bank of America, Rhonda MacLean says she didn't get hung up on whether consulting candidates had security certifications. Rather, she wanted to make sure she was comfortable with their level of experience and that they were suited for the job.

ADVERTISEMENT

"When you pay a consultant … you're looking for someone who is seasoned and can hit the ground running," says MacLean, who now runs a consulting firm.

Outside of routine tasks, certifications are probably among the weakest criteria to use in judging whether someone is qualified for a security project, says Jon Gossels, president and CEO of consulting firm SystemExperts. "The trouble is that they tend to be relatively low-level or journeyman certifications," he says. "There's no certification that says security expert."

Aric Perminter, partner at Secure Technology Integration Group, advises: "Don't let certifications be a show stopper to hiring a contractor. Let real-world experience be a key driver."

Content provided by TechTarget

Special Reports & Profiles

Computer data recovery: An essential guide for IT professionals
Computer data recovery can be a tricky business, usually requiring the help of hard drive data recovery experts. But in all hard drive recovery situations, experts advise users remain calm and not act in a way that will make matters worse.
Security think tank Computer Weekly Security Think Tank
Information security questions answered by experts from: (ISC)2, British Computer Society, Gartner, National Computing Centre, Information Security Forum, Information Systems Security Association, and The Corporate Information Forum
Heathrow Terminal 5 Heathrow Terminal 5 - the latest from Computer Weekly
BAA’s latest London airport terminal, Heathrow Terminal 5 is based on ambitious and innovative use of IT, despite its currebt difficulties. Catch up on the background and latest news
ADVERTISEMENT
ADVERTISEMENT
Advertisements