
Dailydave mailing list archives
Re: Information security certifications diversity andgetting lost
From: Paul Wouters <paul () xelerance com>
Date: Mon, 10 Sep 2007 22:02:29 -0400 (EDT)
On Tue, 11 Sep 2007, nnp wrote:
Sounds like yet another way for a vendor to make money of stupid people to be honest. I mean come on, a certificate saying you can write a stupid Windows 2000 overflow? Who cares? I mean really, who actually cares that you can do something that any donkey with an hour or so free time, a basic understanding of software architecture and a quick guide from one of several sites can do?
I agree, and I have that problem with the security community in general. Exploits == Media == Attention == Money Blackhat for instance, has drifted more and more to "give us a cool exploit" instead of focussing on the larger picture. So do most other "different from the other conferences" security conferences. And on the other end, we are seeing overly complex super-management 3D representations of technical/policy/legal requirements, and virtual pentesting software that misses the point completely about security. For all its criticism, PCI-DSS is decent. It is a standard to try and develop your security policies. It does not go overboard with management-heavy stuff, and it does more then just asking someone to run nmap/nessus/metasploit/autopwn. If security managers complied with the PCI-DSS for all their servers, things would look much better. CISSP is an okay general background, though it contains too much dated cruft, is not up to date with the latest technologies, and is too US-centric. And the exam is more an exercise in double negatives and mapping the OSI model on TCP/IP and remembering obscure names for modern ciphers, then a test of someone's security skills. But as long as companies pay PWC and co $40k for a nessus scan, even the rudimentary security of CISSP is not going to be applied on a larger scale. Paul _______________________________________________ Dailydave mailing list Dailydave () lists immunitysec com http://lists.immunitysec.com/mailman/listinfo/dailydave
Current thread:
- Re: Information security certifications diversity and getting lost, (continued)
- Re: Information security certifications diversity and getting lost Andre Gironda (Sep 03)
- Re: Information security certifications diversity andgetting lost J.M. Seitz (Sep 04)
- Re: Information security certifications diversity andgetting lost Security Admin (NetSec) (Sep 06)
- Re: Information security certifications diversity andgetting lost Dave Aitel (Sep 10)
- Re: Information security certifications diversity andgetting lost Thomas Ptacek (Sep 10)
- Re: Information security certifications diversity and getting lost Dave Aitel (Sep 10)
- Re: Information security certifications diversity and getting lost Andre Gironda (Sep 10)
- Re: Information security certifications diversity Lindley James R (Sep 10)
- Re: Information security certifications diversity andgetting lost Weston, David (Sep 10)
- Re: Information security certifications diversity andgetting lost nnp (Sep 10)
- Re: Information security certifications diversity andgetting lost Paul Wouters (Sep 11)
- Re: Information security certifications diversity andgetting lost matthew wollenweber (Sep 11)
- Re: Information security certifications diversity and getting lost Darren Spruell (Sep 10)
- Re: Information security certifications diversity and getting lost Thomas Ptacek (Sep 10)
- Re: Information security certifications diversity and getting lost Bruce Ediger (Sep 10)
- Re: Information security certifications diversity and getting lost Jason Alexander (Sep 11)
- Re: Information security certifications diversity and getting lost Andre Gironda (Sep 11)