Braindumps free sample questions
Home | Study Guides | View Dumps | Gold Membership | FAQ | Member Login | Signup
Categories
 
Poll
Braindumps Poll
What are you doing to keep your systems protected against Conficker?
We're updating daily and patching as fixes are released.
We've been updating systems, weekly or monthly.
Not much; Conficker poses no real threat to us.
We worry about other dangerous threats than Conficker.
 
 
Advertisement
 

 
 
 
Security Certification Rules Could Shake Up IT Management

Requirements for professional security certification for IT workers in civilian agencies, now being readied by the Office of Management and Budget (OMB), would have a major impact on how government and industry recruit, train and manage their IT staffs, a security expert said Wednesday.

"They are going to affect every one of us in the field," contractors and government employees, said a senior manager at Noblis Inc., a nonprofit high-tech consultant.

Datesman -- who holds a masters degree in criminology and has 30 years experience in law enforcement, including a stint with the Justice Department -- said at a Digital Government Institute conference on cybersecurity that OMB is finalizing minimum requirements for professional certification. He had no time frame for their release.

As IT security has become professionalized, a number of certifications have achieved general recognition industrywide, including a suite from the International Information Systems Security Certification Consortium (ISC2). ISC2 maintains and administers examinations for:

  • CISSP: Certified Information Systems Security Professional
  • ISSEP: Information Systems Security Engineering Professional
  • ISSAP: Information Systems Security Architecture Professional
  • SSCP: Systems Security Certified Practitioner

Organizations awarding certifications would have to be accredited to meet a federal mandate. Datesman likened the situation to the law-enforcement field, which still is sorting out how to fully implement requirements for increased professional training and education 30 years after the movement began. Not only would there be new hiring requirements, there also could be increased responsibility and legal liability for workers and their employers.

"This is a change we have not faced in the IT security industry before," he added.

The closest parallel has been in the Defense Department, which anticipated OMBs reaction in this area. The DODs Directive 8570 on information assurance, approved in December 2005, requires all of the departments information assurance workers to obtain an accredited commercial certification in computer security. The DOD has approved 13 certifications for the directive.

The DOD requirement already has thrown what one conference attendee called a giant monkey wrench into the IT security manpower market.

"If OMB issues a similar requirement, its going to throw the supply-and-demand curve even more out of balance," he said.

Datesman agreed, saying it probably would take years for the supply of certified workers to catch up with demand. A CISSP certification, for example, requires five years experience. "You dont mint them out of college," he said.

The requirement is likely to drive up the cost of recruiting professionals, not only in government but among government contractors, who also would have to meet the requirements in staffing government contracts. Government contract language also would have to change to reflect the requirements.

Other practical considerations would be the need to formally define IT security roles and jobs and spell out the knowledge, skills and abilities needed for each. Certification and training also would have to be verified by employers, possibly creating a backlog much like that for background checks in issuing personal-identity verification cards to government workers and contactors under Homeland Security Presidential Directive 12.

No amount of education and certification will completely fulfill the need for IT security professionalism, Datesman said.

"When we did this in law enforcement 30 years ago, what we learned was that 60 percent of what they needed to know is learned on the job," he said.

 
Best Features
  1810 Q&A Exams
  129 Study Guides
  28 e-Books
  Instant Access
  Latest Updates
  1 Year Free Updates
  100% Success Guaranteed
  All in $79.95
 
Sponsored Sites
 
 
TestKing
 
ExamSheets
 
 
Featured Exams
 
Microsoft
70-562 70-433
70-564
 
CompTIA
N10-004 SY0-201
XK0-002 220-603
220-601 220-602
N10-003 220-604
SK0-002 RF0-001
 
CISCO
642-845 642-611
642-642 350-001
646-203 642-812
642-821 642-892
642-901 642-825
650-393 642-381
640-802 642-054
642-055 350-018
642-143 642-162
642-353 642-354
640-811 642-591
642-425 350-024
646-202 352-001
650-621 640-821
650-575 650-251
650-178 650-173
650-059 642-432
642-511 350-040
640-801 642-071
642-502 642-452
642-801 642-522
642-532 642-582
 
Oracle
1Z0-311 1Z0-232
1Z0-233 1Z0-108
1Z0-200 1Z0-007
1Z0-055 1Z0-042
1Z0-043 1Z0-045
1Z0-036 1Z0-040
1Z0-213 1Z0-211
1Z0-208 1Z0-221
 
CIW
1D0-525 1D0-532
 
Novell
50-688 50-686
50-695 50-694
50-662
 
Citrix
1Y0-326 1Y0-256
 
LOTUS
190-835 190-822
190-803 190-804
190-836 190-832
190-821 190-831
 
IBM
000-071 000-012
000-939 000-042
000-070 000-041
000-062 000-011
000-M30 000-M24
000-R03 000-M23
 
HP
HP0-S11 HP0-J18
HP0-Y15 HP0-790
HP0-A01 HP0-Y12
HP0-S01 HP0-W03
HP0-S12 HP0-T01
HP0-W02 HP0-W01
HP0-X01 HP0-Y11
HP0-X02 HP0-791
 
CWNA
PW0-050 PW0-300
PW0-205 PW0-200
 
EMC
E22-183 E20-840
E20-830 E20-825
E20-820 E22-181
E22-141 E22-106
 
Exin
EX0-101 EX0-103
EX0-102 EX0-100
 
Mysql
005-002 006-002
 

Constant Contact

 
 
Join Mailing List
 -Get Free Study Guides
 -Certification News
 
Tell Your Friends
  Tell a friend about us!
 
Top Resources
  SelfExamEngine
  TestKing
  ExamSheets
  RealExams
  CertTools
 
 

   
   
Add Web Site | Advertise | Contact Us |
© 2001-2010 braindumps.biz. All rights reserved.