Questions tagged [certification]

We use the certification tag for questions about programs designed to vouch for an individual's competence in security-related work. Use the "compliance" tag for programs like PCI-DSS that assess the security of a server.

94 questions
3
votes
2 answers

Course Material for GPEN Certification?

I am planning for GPEN certification, although i have been extensively involved in penetration projects, still looking at the topics it seems a bit difficult.. what could be good study guide for preparation?
3
votes
0 answers

Suggested books to study for CISSP?

Possible Duplicate: Good (preferably free) resource for CISSP practice questions I intend to study to take the CISSP exam within the next few months. Could anyone who's taken the CISSP please list the most helpful book you read to prepare for it?…
T. Webster
  • 2,301
  • 3
  • 19
  • 18
3
votes
4 answers

Definitive certification list

What are a list of useful certificates for someone who wants to work on the information security field? I have heard of CISSP but from what I have understood it is way too advanced for someone new to the field, as it is representing years of…
NlightNFotis
  • 1,130
  • 1
  • 10
  • 18
3
votes
2 answers

AppSec Developer Certifications

I've noticed that certifications seem to be a big part of the IT Security Professional (non-development), but have not seen the same attention being given/required of the software development engineer that focuses on application security or building…
3
votes
2 answers

Certification 27001 Issue

My department already got certification for ISO 27001:2013 last year (2016). But for a particular reason, my department should move to new building. How would be the status for my ISO 27001:2013 Certification. Do we have to take another…
user155860
  • 31
  • 1
3
votes
2 answers

Coverage of OSCP training

Is there any part related to penetration that OSCP/OSCE fail to cover in their training programs? How much will I be exposed to penetration techniques after completing OSCP/OSCE?
3
votes
2 answers

Securely expose WebService from Enterprise Network to Internet Client

(coming from stackoverflow) Are there any standards (or certified solutions) to expose a (Web-)Service to the internet from a very security-sensitive network (e.g. Banking/Finance)? I am not specifically talking about WS-* or any other…
hotzen
  • 131
  • 3
3
votes
1 answer

ISSA vs ISACA vs (ISC)2

I am an aspiring information security professional. I have asked various professionals in the community for advice and one common theme in responses to my inquiries is "Get to know the community!" They advised me to join my local chapter of one of…
ma77c
  • 325
  • 1
  • 5
  • 14
2
votes
2 answers

What certifications do I need to become a Malware Analyst?

I've previously posted here on how to get started as a malware analyst, and wanted to say thanks on getting me started. How much do certifications help me on my resume and which one(s) should I get? Will experience ultimately be better than a cert?…
Nick Williams
  • 47
  • 1
  • 4
2
votes
1 answer

help developer choose correct path to go down for security certifications

Sorry if this is a duplicate however I felt it was a little more unique than the answers I found. Basically I am a software developer and I have moved recently into an architecture role. Throughout my short career I have worked with PCI auditors etc…
OliverBS
  • 445
  • 5
  • 14
2
votes
3 answers

GSEC or GCIH, for a Security Analyst?

I've been with this confusion of getting a certification for a long time!! With the aim of becoming a Security Analyst/Tester, and for a good kick start, which one of these two is good? GSEC or GHIC?? I took a look at the objectives of both these…
Karthik
  • 2,254
  • 4
  • 19
  • 19
2
votes
1 answer

What is the relationship between Suite B and FIPS 140-2?

What is the relationship between the Suite B algorithms and FIPS 140-2 certification? Does OpenSSL meet both criteria? From what I've read, it seems that OpenSSL's crypto library implements many algorithms, and the FIPS 140-2 Object Module covers a…
Finer Recliner
  • 121
  • 1
  • 3
2
votes
3 answers

Certifications that involve practical knowledge

After a lot of googling and searches on forums, it was apparent that certificates like CEH and CISSP incorporated a lot of theory in them and were useful as an added for job. Are there any certificates that give real time practice with the system…
TheSB
  • 21
  • 1
2
votes
1 answer

Are GIAC exams open book (Unlike CISSP)?

I am currently CompTIA A+, Network+, and Security+ certified. As part of maintaining compliance with the DoDD 8570, I will also be sitting for the ISC^2 CISSP exam in the near future. I have noticed that GIAC offers certifications with open-book…
Abdu
  • 511
  • 4
  • 12
2
votes
4 answers

Why is the public key in a certificate not signed?

I have a naive question about certificates. I know the hash of the public key is signed with the CA's private key. I have an alternative design. Because the public key is being transmitted anyway, so why don't we sign the public key directly and…
user231806
  • 21
  • 1