Chapter 6

Becoming Certifiable

Education and training are important, but a professional certification demonstrates your commitment and proves your proficiency. The top graduate from the best law school can't get paid for chasing an ambulance until he or she passes a bar exam. Likewise, a PhD from the top accounting school can't count a real bean for a paying customer until he or she passes the CPA exam.

There's nothing like a professional certification to change the focus during an interview from whether you can do a particular job to other concerns, such as softer skills or, even better, your salary requirements and start date.

Which certifications are best for you and your goals? There are dozens of professional certifications in networking and related skills. Pursuing the wrong one is a waste of your time. Pursuing them all is impractical and a waste of your time.

This chapter gives you some background on certifications and provides you with enough information to help you determine which certifications will be most beneficial to your career aspirations.

Planning for a Certification

When determining which certification to pursue first, consider the following factors,:

  • What is the “best” certification for you? As mentioned, you have lots of choices. We present a good selection of options later in this chapter. What constitutes “best” is a personal decision combining the respect that the industry has for a given certification and whether the certification covers an area that is consistent with your interests and ambitions.
  • Can you make the time commitment? Every certification requires that you put aside a significant amount of time for studying and taking the test. Ask yourself whether you are in a situation to do this.
  • What is your studying style? Popular certifications have study guides and preparation courses. Some people learn by reading, others by hearing, and still others by doing. Find a class that fits your learning style.
  • What is your test-taking style? Some people struggle with answering multiple-choice questions. If that description fits you, a certification might be more frustration than it is worth. Be honest with yourself.
  • How much does it cost? No certification is free, but you may be able to get someone else to pay for it. Many companies have a budget to pay for certifications pursued by employees. If the training is associated with a particular vendor, your employer may have earned credits from past sales with a vendor that will pay for training on the vendor's equipment. Otherwise, the training will be on your own dime, and it costs much more than a dime.
  • Are you prepared to keep your certification current? Many certifications need to be renewed every two or three years. The sponsoring organizations of the certificates add new questions, delete obsolete questions, and change the answers as technology evolves. If you're not regularly using particular skills, you may need to refresh what you learned. Before you decide to pursue a certification, be aware that you are making a recurring commitment that often involves a least some cost for recertifiaction

Image It is bad form to claim on a job application that you have a certification if it has expired. Most certificate-sponsoring organizations have a search capability that can be used to easily confirm your stated certification. Most companies consider falsifying this information to be a dismissible offense.

Deciding Which Certifications Are Right for You

So what is the right certification for you? In addition to the factors mentioned in the preceding section, you need to consider some important issues.

The two categories of certifications are vendor-specific certifications, which relate to the products made by a specific vendor, and non-vendor-specific certifications, which are created and maintained by independent organizations, typically nonprofits.

Vendor-specific certifications are marketable, but only to firms that use products from that vendor. A Cisco certification is valuable because many companies have at least some Cisco equipment.

Vendors such as Huawei and ZTE also have certification programs, but their customer installed base in the United States is relatively small. As a result, the value of their certification is less among U.S. companies.

In addition, a given vendor may have multiple certification types. For example, as of this writing, Cisco has 28 certification types, most of which relate to networking. (We describe Cisco certifications in the next section.)

Microsoft has seven certification types, but networking is only part of the curriculum. Having a Master-level certification is great, but a Microsoft Office Specialist-Master certification will not help you much in the networking field.

Non-vendor-specific certifications are a different kettle of fish. Non-vendor specific certifications tend to be more general and contain a wider set of study topics or body of knowledge. A vendor's certifications is limited to their products or services and how to apply them to specific network situations. Non-vendor certifications cover more material and focus on the control to be implemented or the business problem to be solved, including combinations of vendor solutions.

Although some vendor-specific information is part of non-vendor specific testing, the intent is to offer prospective customers assurance that the person who has passed the certification has at least a minimal set of skills. A number of non-vendor-specific certifications are explored later, in the section “Winning with a Third-Party Networking Certification.”

So how do you decide which certification is best? In addition to the preceding considerations, also think about the following:

  • What does your boss want? If you have a boss now, it never hurts to ask what he or she wants. Having support in pursuing a particular certification is essential if you want your boss to pay for the certification.
  • What certification do my peers or mentors have or respect? Go ahead and ask them. They will be happy to share their experiences and opinions. Also talk to people who have gone through the certification process. They can warn you of any landmines, commiserate on the challenges, and let you know how this certification has helped in their career.
  • What certification sounds most interesting or fun? The rest of the chapter explores a number of vendor-specific and non-vendor-specific certifications. We provide a good sample, but we don't list all available certifications. Spend a little time on the Internet and find out whether one captures your imagination.

Choosing a Vendor-Specific Networking Certification

Lots of organizations offer training to customers on how to more fully use their products. This approach makes business sense. Often these classes last a few days and help customers with configuration and maintenance. Upon completion, the company offers attendees something to resemble a diploma.

Earning a training diploma is good, but training is different from certification. One distinction is that a certification requires a test. In most vendor-specific training courses, the diploma primarily means that a warm body was present for the duration of the training. Whether the individual who was sneaking sips from his hip flask got anything from the information is between him and his boss (you know who you are).

Another distinction between a training diploma and a certification is that a certification is recognized in the industry as offering some level of value. With vendor-specific training, sometimes a third party creates the training program; completing the program won't help you get a job if the hiring manager has never heard of the company.

Image The issue of value is meant as a cautionary tale. Some shady companies offer discounted certification courses. If prospective employers have never heard of these companies, completing their courses won't help you in your job search, regardless of how much you learn or how sincere the marketing materials sound. Check first with those in the industry.

In this section, we describe well-known vendor-specific certifications that carry value.

Cisco certifications

Arguably the best-known certifications in the networking biz are from Cisco. As mentioned, Cisco offers 27 kinds of certification. One almost needs a certification to tell what the different Cisco certifications mean.

The first distinction among the Cisco certifications is the level:

  • Entry: For individuals who are interested in getting started in networking
  • Associate: The first level for people with a few years of experience in networking
  • Professional: For people who want to impress the heck out of prospective bosses and in-laws
  • Expert: For those who seek to impress professionals
  • Architect: For those who are just showing off (but we're secretly jealous and want your autograph)

Entry level

The two certifications at the entry level are

  • Cisco Certified Entry Networking Technician (CCENT): This certification covers the skills necessary for supporting small and medium-sized businesses.
  • Cisco Certified Technician (CCT): A more hands-on certification for people who will perform physical installations and troubleshoot Cisco equipment in the field. Within this certification are specializations for technicians working in data centers, with switches and routers, and with telepresence equipment (used for voice and video).

Don't assume that these courses are simple because they include the word entry. These entry-level classes require several months of intense studying, lots of hands-on experience, and the successful completion of several rigorous tests.

Associate level

The Cisco Certified Network Associate (CCNA) certifications are the next step up from entry-level certifications. The associate level covers skills necessary to administer small or medium-sized networks with one of eight technology specializations:

  • Routing and switching
  • Data center
  • Security
  • Service provider
  • Service provider operations
  • Video
  • Voice
  • Wireless

The individual who earns one of these certifications would be, say, a Cisco Certified Network Associate (CCNA) Data Center or CCNA Routing and Switching.

Just to keep it a little confusing, another certification in the associate level is the Cisco Certified Design Associate (CCDA). This certification is suitable for network engineers and others who specify network environments.

Although associate sounds better than entry, it fails to capture the magnitude of the work involved. First, you need a few years of experience in the field. Then, to pass the exam, you need to devote six to nine months (depending on whether you have no or a minimal social life) to studying and taking classes. This timeframe is if you take a preparation class and spend many hours each day pursuing your goal. Your mileage may vary, but any of these certifications is a significant accomplishment and shows a commitment of 1000+ hours. Plan to retake this test every three years to keep your CCNA or CCDA certification valid.

Professional level

The professional level certification, Cisco Certified Network Professional (CCNP), covers the same specializations as the associate level with the exception of video technology. If you happen to specialize in video-networking technology, you may be happy to find out that the certification is only at the associate level.

The test is given in a series of steps, so you don't have to take all the tests at one time. Each test covers different technology areas (route, switch, and troubleshoot). Some people who have earned the professional-level certification say that they studied rigorously for nine months to a year.

The professional level has that same naming outlier for senior network design engineers, senior analysts, and principal systems engineers who design the networks. Rather than being consistent and, say, calling the certification for design professionals CCNP-Design, the certification at the professional level is called the Cisco Certified Design Professional (CCDP) certification.

Expert level

If the professional level isn't enough for you, you can get an expert-level certification. Most are called CCIE, for Cisco Certified Internetwork Expert, followed by the specialization. There's one change to again make things interesting. The step above CCNP Voice is CCIE Collaboration.

The old CCIE Voice was retired as of Valentine's Day 2014. (I am not sure of the significance of this date.) The CCIE Collaboration terminology reflects the idea that businesses use internal voice communication along with data and video technology to collaborate.

Again, there is the same naming outlier, the Cisco Certified Design Expert (CCDE). It sure would be a lot simpler if they called this CCIE Design, but they did not ask me.

The CCIE variants and CCDE require another year of study and hands-on practice beyond the time spent on the CCNP/CCDP. This level is pretty darn elite: In the United States, there are about 5500 CCIEs of all types.

Architect level

Let's put it this way. More people have fallen out of planes at altitudes above 10,000 feet and survived (157) than have earned the Cisco Certified Architect (CCAr) certification. More professional baseball players have hit four home runs in a single game (16) then have earned the CCAr. You get the idea.

But if not, more people have walked on the moon (12) than have earned the Cisco Certified Architect (CCAr) certification. Ten folks have earned the CCAr certification. We hope you become one. It looks very good on your resume. When you make it, send us a postcard about your accomplishment.

Microsoft

Microsoft makes a lot of software, but they also have technical certifications, specifically Microsoft Office certifications and Microsoft Technology certifications. The Microsoft Office certifications are good but are not our focus in this book.

The following Microsoft Technology certifications include topics that are relevant to networking:

  • Microsoft Technology Associate (MTA): Covers the basic skills IT of infrastructure, database, and application development
  • Microsoft Certified Solutions Associate (MCSA): Goes deeper into a particular piece of Microsoft technology
  • Microsoft Certified Solutions Expert (MCSE): Focuses on an application category

Microsoft Technology Associate (MTA)-IT Infrastructure

The Microsoft Technology Associate (MTA)-IT certification offers multiple tracks. Readers of this book will be most interested in the MTA IT infrastructure track, which has the following four tests:

  • Windows Operating System Fundamentals
  • Windows Server Administration Fundamentals
  • Networking Fundamentals
  • Security Fundamentals

This certification is an entry-level (no IT experience) kind of test that is a good way to get started in the certification world. There are no requirements to prepare for taking the test.

Microsoft Certified Solutions Associate (MCSA)

Microsoft Certified Solutions Associate (MCSA) is proudly listed as a prerequisite for becoming a Microsoft Certified Solutions Expert in much of the promotional literature. However, it looks pretty good as a certification by itself. The Solutions Associate specializes in configuring and maintaining one of the following systems:

  • Windows Server 2012
  • Windows Server 2008
  • Windows 8
  • Windows 7
  • SQL Server 2012
  • SQL Server 2008
  • Office 365

These certifications do not expire but the products in which you get the MCSA may expire. An MCSA in the Windows NT operating system will not open many doors for you these days.

All MCSA certifications involve multiple tests. You can take the tests in any order. A general guideline is that you should be able to take all three tests in 90 days if you focus on them. Hands-on experience with the technology is essential.

Microsoft Certified Solutions Expert (MCSE)

Now you are talking. Microsoft Certified Solutions Expert (MCSE) is a widely recognized certification that will impress the folks you want to impress. The MCSE can cover any of the following areas:

  • Server infrastructure
  • Desktop infrastructure
  • Private cloud
  • Enterprise devices and apps
  • Data platform
  • Business intelligence
  • Messaging
  • Communication
  • SharePoint

One of the good things about the MCSE is that you can go ahead and earn the MCSE and pick up the MCSA as you complete the first two or three tests.

The MCSE is the highest certification that Microsoft currently offers. They used to offer a Microsoft Certified Architect (MCA) certification but cancelled the program because there were only a few hundred MCAs.

Juniper Networks

Juniper Networks makes sure that Cisco doesn't have all the fun. Their product lineup offers high-speed switching for enterprises and Internet service providers (ISPs). Juniper Networks is frequently second or third in market share across their range of solutions, which is not shabby at all.

Describing the Juniper Networks Technical Certification Program (JNTCP) is not easy because they have 19 certifications. Understanding which one is right for you involves understanding Juniper's primary product lines, target markets, and sales channels. Buckle up and let's start breaking this down.

First, the four levels of certification, in order of increasing difficulty, are

  • Juniper Network Certified Internet Associate (JNCIA)
  • Juniper Network Certified Internet Specialist (JNCIS)
  • Juniper Network Certified Internet Professional (JNCIP)
  • Juniper Network Certified Internet Expert (JNCIE)

All Juniper networks certifications start with one of these four levels. For example, an associate-level certification in Junos (JNCIA-Junos), the operating system used by most Juniper Network products, is a prerequisite for most of the other certifications.

In addition, Juniper Networks sells to enterprises and service providers, primarily Internet service providers. There are important differences between private network belonging to an enterprise (ENT) and Internet service providers (SP). For example, most enterprises have slow periods when they can accept some downtime. ISPs must support traffic on an almost continuous basis. Also, ISPs need accurate information flow into the billing system but enterprises want to track usage.

One area that is similar for enterprises and service providers is the network's information security. The tools and strategies for ensuring information security are identical whether the customer is an enterprise or a service provider, so Juniper Networks has a single certification track for people responsible for information security.

Figure 6-1 is a matrix of ten of the certifications offered by Juniper Networks.

Image

Figure 6-1: Juniper Networks certifications for network engineers.

So far, so good. The next consideration is that Juniper Networks sells their solutions not only through a direct sales force to enterprises (ENTs) and service providers (SPs) but also through resellers. These resellers augment Juniper's direct sales force. Many of these resellers add value by offering network engineering services to their enterprise and service provider customers.

The network engineers employed by reseller organizations can earn the same certifications as everyone else at the associate and specialist levels. A source of confusion is that network engineers who work for these resellers are called support specialists, and it is easy to confuse this title with the level of Specialist used for the Juniper Network Certified Internet Specialist (JNCIS).

In other words, network engineers working for a reseller first earn their Juniper Network Certified Internet Associate for Junos (JNCIA-Junos) like everyone else. Next, they earn their Juniper Network Certified Internet Specialist-Enterprise (JNCIS-ENT) like everyone else.

Finally, these network engineers (also called service specialist) can pursue a certification strictly for resellers called Juniper Network Certified Service Professional-Enterprise (JNCSP-ENT) at the professional level. These service specialists can also earn JNCSP-SP to supporting ISPs and JNCSP-SP to become a professional on security issues.

That brings us to 13 certifications. The last several are related to specific product lines:

  • E-Series: The E-Series routers are broadband edge routers.
  • Firewall/VPN: Juniper makes a number of solutions for firewalls and to create VPNs.
  • Wireless LAN: In 2010, Juniper acquired Trapeze Networks, a company that makes wireless LANs.
  • QFabric: These products provide distributed connectivity for data centers.

The E-series has three levels of certification: associate (JNCIA-E), specialist (JNCIS-E), and professional (JNCIP-E). Do not confuse the E here with ENT, which refers to enterprise. And this brings us to 19 certifications for Juniper.

Palo Alto Networks

Palo Alto Networks specialize in firewalls and offer two certification programs based on their next-generation security products. (Yes, we know that this Dummies book focuses on networking and not information security, but you will help yourself by earning certifications in both.)

The Accredited Configuration Engineer (ACE) certification exam tests the candidate's knowledge of the core features and functions of the company's next-generation firewalls.

The Certified Network Security Engineer (CNSE) exam is a formal certification. Exam questions cover the following areas related to Palo Alto Networks firewalls:

  • Administration and management
  • Network architecture
  • Security architecture
  • Troubleshooting
  • User identification
  • Content identification
  • Application identification

Check Point

Check Point Software Technologies, Ltd. offers the Check Point Certified Professional Program for network security. This is a product-focused certification based on the popular, but unimaginatively named Check Point Firewall-1. Certifications from Check Point include the following:

  • Check Point Certified Security Administrator (CCSA): An entry-level certification for security administrators who have 6 to 12 months of work experience with Check Point security solutions. Candidates must pass an exam that covers the following topics:
    • Understanding Check Point technologies
    • Describing deployment platforms and security policies
    • Monitoring traffic and connections
    • Implementing network address translation (NAT)
    • Configuring user management and authentication
    • Using Check Point's SmartUpdate
    • Implementing identity awareness
    • Configuring virtual private network (VPN) tunnels
    • Resolving security administration issues
  • Check Point Certified Security Expert (CCSE): Candidates must first earn the CCSA certification, and then take an additional exam that covers the same topics as the CCSA exam but at a more advanced level.
  • Check Point Certified Managed Security Expert (CCMSE): For security administrators who manage large or virtualized network environments. The candidate must first earn the CCSE certification, and then pass an additional exam covering the following topics:
    • Installing, configuring, and managing a multi-domain management (MDM) environment
    • Understanding common deployment scenarios
    • Understanding the traffic inspection process
    • Configuring domain management server (DMS) high availability
    • Configuring and implementing a global policy
    • Applying common troubleshooting practices

Red Hat

The Red Hat Certificate of Expertise in Server Hardening is for security professionals with skills and experience in

  • Configuring file systems and volumes for more restrictive security policies
  • Implementing additional user account security and identity management
  • Configuring enhanced, secure logging, and audit capabilities
  • Identifying and performing appropriate package updates in response to Common Vulnerabilities and Exposure (CVE) and Red Hat Security Advisory (RHSA) reports

Other Vendor-specific certifications

The Cisco and Microsoft certifications are the best known but are by no means the only certification programs with street cred. Following is a sampling of other vendors offering certification programs related to networking:

  • Avaya
  • Apple
  • Hewlett-Packard
  • LANDesk
  • Novell
  • SolarWinds

Winning with a Third-Party Networking Certification

A number of organizations that are not affiliated with a particular vendor are well respected in certifying the abilities of their graduates. Typically, these certifications originate at nonprofit organizations seeking to ensure quality standards among technical or support professionals. Because these certifications are not affiliated with a particular vendor, they are referred to as third-party certifications.

CompTIA

The best-known organization for providing networking technology certifications is CompTIA (Computing Technology Industry Association), a nonprofit trade association. The original motivation for creating their certifications was to provide a minimal level of expertise among the workforce so that customers could have some degree of confidence that the holder of the certification is competent.

CompTIA started in 1982 and was then called the Association of Better Computer Dealers (ABCD). Keep in mind that Microsoft DOS was released in 1981. PCs were new technology, and computer dealers found that any schlub could hang up a shingle and claim to be qualified to repair the PCs that were just coming out on the market.

These so-called repair technicians were not suited to repair anything as intelligent as an 8086 computer. To prevent the industry from getting a bad reputation among customers, the dealers banded together to create standards. The ABCD consortium was the origin of CompTIA's A+ certification for computer technicians.

The current A+ certification, which was updated in 2012, is comprised of two tests: CompTIA Essentials and CompTIA Practical Application.

The Essentials portion of the exam covers the basics of computer technology, networking, and security for hardware and operating systems. The Practical Application portion demonstrates the use of current operating systems.

CompTIA is probably best known for the A+ certification, but their other certifications are highly respected and valued. Some certifications are difficult to categorize; we group them from the perspective of this book as follows:

  • Network-related technology certifications
  • Non-network technology certifications
  • Technology skills certifications
  • Strata certifications

Network-related technology certifications

Three certifications are relevant in one way or another to networking:

  • CompTIA Network+: A well-respected, vendor-neutral certification for networking professionals. To earn this honor, expect to put in a lot of work for about nine months, with hands-on training.
  • CompTIA Security+: A big benefit for those working in networking. Be ready for another nine months of classroom and hands-on training to get this one.
  • CompTIA Advanced Security Practitioner (CASP): Intended for people who have been working in security for more than five years or in IT for more than 10 years.

Non-network-technology certifications from CompTIA

Although the following certifications are not specifically network-centric, there are elements of networking and operating systems technology in them that would have value to an aspiring network engineer:

  • CompTIA Mobility+
  • CompTIA Mobile App Security+
  • CompTIA Server+
  • CompTIA Cloud Essentials
  • CompTIA Cloud+
  • CompTIA CTP+ (Convergence Technology Professional)
  • CompTIA Linux+ Powered by Linux Professional Institute
  • CompTIA Storage+ Powered by Storage Networking Industry Association

Technology skill certifications

Technology skill certifications may be useful for someone focused on or seeking a career in networking (more on this later in this chapter). Note that each of the following certifications involves a significant commitment of time and resources:

  • CompTIA CTT+: This certification is for technical trainers. Technical trainers, as the name implies, demonstrate skills for teaching technical audiences.
  • CompTIA Project+: Project management is an important skill, particularly in the IT environment. Project managers keep large-scale initiatives coordinated across a range of individuals, departments, and vendors. CompTIA provides a certification associated with learning these skills.
  • CompTIA PDI+: This certification is associated with printing and document imaging. Although the paperless office was first discussed in the 1960s, US Census data shows that the use of printing continues to grow. The implication is that businesses need more PDI+ers.
  • CompTIA CDIA+: Companies need advanced PDI+ers too. The certification above the CompTIA PDI+ certification is CompTIA CDIA+, which stands for Certified Document Imaging Architect.
  • CompTIA Social Media Security Professional: This professional certification helps companies against hackers who enter networks through social media.
  • CompTIA Healthcare IT Technician: Folks who work in the healthcare industry must comply with extra rules to ensure patient privacy and need to understand the industry's terminology. A prospective employer would know that a person with this certification has been exposed to all the relevant rules.

Strata certificates

CompTIA offers not only certifications but also certificates for particular areas of study. Earning a certification is more involved than earning a certificate, and therefore better. (Unfortunately, the names are similar.)

CompTIA certificates are prefaced with the Strata to distinguish them from certifications. They include the following:

  • Strata IT Fundamentals: A more basic certification than A+.
  • Strata for Sales: Ensures that the certificate holder has enough knowledge to talk to customers about their technical needs.
  • Strata Green IT: This certificate teaches the many small changes that an IT organization can enact that will help the environment and minimally affect cost or performance.

Network Professional Association

Network Professional Association (NPA) is a nonprofit association for computer network professionals that offers the Certified Network Professional (CNP) Program. The primary goal of NPA is to raise the awareness of technical people working in networking as a profession by setting standards for ethics, training, and performance.

This approach is slightly different than the vendor-specific and the third-party certification programs in that no moral judgments are associated with the other certifications. They are purely technical.

The Network Processionals Association, on the other hand, may have issues with a CNP who designs a network to trade in blood diamonds and speed the burning of the Amazon rainforest while taking bribes from vendors and spying on its critics. Certainly, all the organizations mentioned in this chapter would have concerns, but the technical certifications are independent of any ethical judgments.

Planet3 Wireless

Planet3 Wireless is an organization that certifies wireless LAN professionals. Their certification focus on 802.11 wireless LANs. The certifications, in approximate order of easiest to hardest, include:

  • Certified Wireless Network Administrator (CWNA): A basic course for individuals who will administer enterprise-class wireless LANs. CWNA is a prerequisite for the other certifications.
  • Certified Wireless Technology Specialist (CWTS): A more in-depth certification than CWNA.
  • Certified Wireless Analysis Professional (CWAP): Training on how to analyze, troubleshoot, and optimize an enterprise wireless LAN. Offered after you master the previous two certifications.
  • Certified Wireless Security Professional (CWSP): The certification to keep pesky hackers from entering the corporate network.
  • Certified Wireless Network Expert (CWNE): The top certification for 802.11 wireless LANs. It requires extensive experience operating wireless LANs in the corporate environment plus the previous four certifications and documented expertise.
  • Certified Wireless Network Trainer (CWNT): If you are so smart, you should teach the class, but not before you earn this certification.

Earning a Vendor-Neutral Security Certification

Even though you may not be looking for a security job or even a security career, security is important in every IT job, especially networking! Chances are you'll be managing the security aspect of systems, devices, or users, and you'll be far more marketable if you have one or more security certifications.

International Information Systems Security Certification Consortium (ISC)2

Founded in 1988, (ISC)2 (pronounced “I-S-C-squared”) was formed to create a global information security certification program. In 1994, the CISSP certification was established, and it has since been recognized as one of the top security certifications in the profession. Some of the certifications offered by (ISC)2 are described in this section.

Systems Security Certified Practitioner (SSCP)

Systems Security Certified Practitioner (SSCP) is the entry-level certification offered by (ISC)2. Requiring as little as one year of professional experience, the SSCP certification is great for professionals who are working to establish their security careers.

Certified Information Systems Security Professional (CISSP)

Universally recognized as the greatest of all information security certifications, Certified Information Systems Security Professional (CISSP) covers a broad swath of subject matter in its Common Body of Knowledge (CBK):

  • Access control
  • Telecommunications and network security
  • Information security governance and risk management
  • Software development security
  • Cryptography
  • Security architecture and design
  • Security operations
  • Business continuity and disaster recovery planning
  • Legal, regulations, investigations, and compliance
  • Physical (environmental) security

The CISSP exam contains 250 multiple-choice questions and may take you up to six hours to complete.

Several CISSP concentrations are now available to CISSP holders who want to extend their certification into one of three important specialties:

  • CISSP-ISSAP (Information Systems Security Architecture Professional)
  • CISSP-ISSEP (Information Systems Security Engineering Professional)
  • CISSP-ISSMP (Information Systems Security Management Professional)

Image You can learn more about the CISSP certification in CISSP For Dummies, 4th Edition, by Lawrence C. Miller and Peter Gregory.

Certified Software Security Lifecycle Professional (CSSLP)

The Certified Software Security Lifecycle Professional (CSSLP) certification recognizes expertise in the security development life cycle, which is the set of business processes and techniques that ensures the inclusion of security in every step of the software development process.

The range of subject matter in this certification includes

  • Secure software concepts
  • Security software requirements
  • Secure software design
  • Secure software implementation/coding
  • Secure software testing
  • Software acceptance
  • Software deployment, operations, maintenance, and disposal
  • Supply chain and software acquisition

Certified Cyber Forensics Professional (CCFP)

The Certified Cyber Forensics Professional (CCFP) certification is a recognition of skills and experience in the field of computer forensics, the science of conducting sound digital investigations that may be used in legal proceedings.

The range of subject matter in this certification includes

  • Legal and ethical principles
  • Investigations
  • Forensic science
  • Digital forensics
  • Application forensics
  • Hybrid and emerging technologies

Certified Authorization Professional (CAP)

The Certified Authorization Professional (CAP) certification recognizes skills and knowledge in the work of authorizing and maintaining information systems in the Risk Management Framework as defined in NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems.

The range of subject matter in this certification includes

  • Risk management framework (RMF)
  • Categorization of information systems
  • Selection of security controls
  • Security control implementation
  • Security control assessment
  • Information system authorization
  • Monitoring of security controls

Healthcare Information Security and Privacy Practitioner (HCISPP)

The Healthcare Information Security and Privacy Practitioner (HCISPP) certification recognizes expertise in the protection of personal health information. The range of subject matter in this certification includes

  • Healthcare industry
  • Regulatory environment
  • Privacy and security in healthcare
  • Information governance and risk management
  • Information risk assessment
  • Third-party risk management

Image (ISC)2 also offers an Associate of (ISC)2 Certification, for those who have passed CISSP, CSSLP, CAP, SSCP, CCFP, or HCISPP but do not yet have the required years of experience to be awarded the certificate.

ISACA

ISACA was formerly known as the Information Systems Audit and Control Association. They are now ISACA to show that they are known for more than just audits and controls. This nonprofit organization is dedicated to the development of frameworks, standards, guidance, education, and certifications for professionals in information systems audit and security management.

ISACA certification exams are conducted a limited number of times per year, at hundreds of locations around the world.

Certified Information Systems Auditor (CISA)

Enacted in 1978, the Certified Information Systems Auditor (CISA) certification is one of the most prestigious security certifications available in the industry. This certification covers the following subject matter:

  • Information systems audit
  • IT governance
  • Systems and infrastructure life cycle
  • IT service delivery and support
  • Protection of information assets
  • Business continuity and disaster recovery planning

Image The CISA certification is frequently required for IT audit professionals in positions focused on IT audit or IT audit management.

Certified Information Security Manager (CISM)

The Certified Information Security Manager (CISM) certification is recognition of the skills, knowledge, and experience of security managers. The CISM certification covers the following subject matter:

  • Information security governance
  • Information risk management and compliance
  • Information security program development and management
  • Information security incident management

Certified in the Governance of Enterprise IT (CGEIT)

Certified in the Governance of Enterprise IT (CGEIT) is a certification aligned more with IT management than IT security. The CGEIT certification covers the following domains:

  • Framework for the governance of enterprise IT
  • Strategic management
  • Benefits realization
  • Risk optimization
  • Resource optimization

Certified in Risk and Information Systems Control (CRISC)

Certified in Risk and Information Systems Control (CRISC) is ISACA's newest security-related certification. With heavy emphasis in risk management and controls, CRISC complements CISA and CISM, and the three together provide comprehensive control over information security management and operations.

The CRISC certification covers the following domains:

  • Risk identification
  • Risk assessment
  • Risk response and mitigation
  • Risk and control monitoring and reporting

SANS Institute

Along with the (ISC)2 Certified Information Systems Security Professional (CISSP) certification, discussed later in this chapter, Global Information Assurance Certification, or GIAC certifications are among the most widely known and respected security industry certifications today. The SANS (SysAdmin, Audit, Networking, and Security) Institute Global Information Assurance Certification (GIAC) program validates the skills and knowledge of security professionals, practitioners, and developers through nearly 30 certifications, which are grouped into the following categories:

  • Security administration:
    • GIAC Security Essentials (GSEC)
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Certified Intrusion Analyst (GCIA)
    • GIAC Certified Penetration Tester (GPEN)
    • GIAC Web Application Penetration Tester (GWAPT)
    • GIAC Certified Perimeter Protection Analyst (GPPA)
    • GIAC Certified Windows Security Administrator (GCWN)
    • GIAC Information Security Fundamentals (GISF)
    • GIAC Assessing and Auditing Wireless Networks (GAWN)
    • GIAC Certified Enterprise Defender (GCED)
    • GIAC Certified UNIX Security Administrator (GCUX)
    • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
    • GIAC Mobile Device Security Analyst (GMOB)
    • GIAC Global Industrial Cyber Security Professional (GICSP)
    • GIAC Critical Controls Certification (GCCC)
  • Forensics:
    • GIAC Certified Forensic Analyst (GCFA)
    • GIAC Certified Forensics Examiner (GCFE)
    • GIAC Reverse Engineering Malware (GREM)
    • GIAC Network Forensic Analyst (GNFA)
  • Management:
    • GIAC Security Leadership Certification (GSLC)
    • GIAC Information Security Professional (GISP)
    • GIAC Certified Project Manager Certification (GCPM)
  • Audit:
    • GIAC Systems and Network Auditor (GSNA)
  • Software security:
    • GIAC Secure Software Programmer — .NET (GSSP-NET)
    • GIAC Secure Software Programmer — Java (GSSP-JAVA)
    • GIAC Certified Web Application Defender (GWEB)
  • Legal:
    • GIAC Law of Data Security & Investigations (GLEG)
  • Security expert:
    • GIAC Security Expert (GSE)

The GSE is the most prestigious certification in the GIAC family. To earn the GSE, you must successfully complete a 75-question, three-hour exam, followed by a two-day lab exam. Prerequisites include the GSEC, GCIH, and GCIA certifications.

Most GIAC certifications correspond to SANS Institute training courses. However, attending a SANS course is not required to earn GIAC certification. SANS GIAC recommends a minimum of 55 hours of study (in addition to any formal training courses) to prepare for a GIAC certification exam.

Earning Other Relevant Certifications

As if these certifications weren't enough, other certifications can help you professionally in the networking space. Some of these specializations include the following:

  • Technical training: All of us have had at least one disappointing experience in receiving technical training. The trainer probably did not have a certificate in training techniques. If you want to become a technical trainer, seriously consider earning a certificate that demonstrates your capability in this area.
  • Project management: If you're a Boy Scout who has earned his Eagle badge, you have run a project. The rest of us either figure out on-the-fly how to keep a complex project on track or take a course in project management. The best-known project management certification is the Project Management Institute's Project Management Professional (PMP).
  • IT quality auditing: ISO 9001 is a business evaluation that measures the quality of management systems in general. An important IT component ensures that IT systems are consistent with quality programs throughout the organization. Many certification options are available for quality systems implementation and auditing.
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset