Home page logo
/

pen-test logo Penetration Testing mailing list archives

Re: OSCP
From: s0h0us <s0h0us () yahoo com>
Date: Fri, 19 Dec 2008 04:57:09 -0800 (PST)

JB,
couldn't agree with you more...
thanks



----- Original Message ----
From: JB <pentest () jitonline net>
To: infosigmer () inbox com
Cc: pen-test () securityfocus com; pen-test-return-1078487582 () securityfocus com
Sent: Wednesday, December 17, 2008 7:45:04 AM
Subject: Re: OSCP

I hold both a CISSP and a OSCP... here is why:

The CISSP does not claim technical competence... it means that
1. The holder knows at least a little about each of the 10 domains and has
proved it
2. That the holder is committed to continuing security education
3. The holder has held some role with security responsibilities for at
least 3-4 years

It is an easy way to weed out people who are actually willing to put in
the time on security and really have the interest.

A CISSP is NOT a technical certification

The OSCP is a certification that demonstrate that the holder at least has
a semblance of a clue how to use common security tools. To pass the OSCP,
you actually have to PERFORM a penetration test - that means get SYSTEM or
root on multiple machines using only the basic tools (Nessus, Core Impact,
etc are not permitted, and the vulnerabilities do not have metasploit
modules written for them). It is not a point and click certification. That
being said... you do not have to be the most skilled hacker to get
certified.

So why certify? Certification demonstrates active commitment to the
trade... not that the holder is the most worthy candidate for a job. That
is what the interview and recommendations are for!!! When I interview a
candidate for employment, I tend to ask situational questions to assess
whether the person before me actually knows what he is talking about, or
pulling it out of his a$$. I also ask the candidate to discuss challenges
that he has faced in his performance of security duties (and we have all
faced challenges). In the end, I will make my decision based not solely on
a certification. That being said... if I have two EQUALLY qualified
candidates (experience, interview, etc match up closely), then yes -
certification may become a tie breaker as the one who has spent the
additional time to obtain and maintain the certification shows a stronger
commitment to security.

JB


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Security Trends Report from Cenzic
Stay Ahead of the Hacker Curve!
Get the latest Q2 2008 Trends Report now

www.cenzic.com/landing/trends-report
------------------------------------------------------------------------


      

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Security Trends Report from Cenzic
Stay Ahead of the Hacker Curve!
Get the latest Q2 2008 Trends Report now

www.cenzic.com/landing/trends-report
------------------------------------------------------------------------


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault