Are IT certifications just a vendors ploy for money?! Do they have any validity?
The validity of industry certifications has been a controversial topic for years – some say certifications are a reasonable measure of an individual’s technical or non-technical skillset, whereas, others believe certifications prove that you can memorize and regurgitate information without truly understanding the material. The US government has made a push with 8570.1 Directive (written in 2005 but updated in 2008) that requires individual’s handling a certain classification of data in Information Assurance to pass certain certifications. According to several websites here is the recommended level and certification:
I have a laundry list of cert complaints ranging from lack of realism to the amount of industry credibility some carry – news flash folks the CISSP is NOT a technical cert. I’m an avid believer that industry certifications are not an ‘end all’ true evaluation of a person’s InfoSec intellect. My corrupt view stems mainly from people’s primary reason to obtain them – if I get cert X I get a salary bump. They aren’t looking to learn the material, as much as, quickly memorize it. Several years ago a colleague of mine got his MCSE (which is now being called MCITP to provide more cert granularity) by simply memorizing the order of the answers for each question identified in the Brain Dumps. He said he didn’t even read the question but just focused on the multiple choice answers and which one was correct. He got the cert is less than 2 months (if I remember correctly) and since the MSCE requires the passing of several exams…case in point, the memorizing technique worked.
To corrupt the certification ‘gene pool’ even more vendors have started creating meaningless certifications that really have no credibility other then proving you can sit through a training course and score a greater than ~60% passing score on an exam the instructor might as well have taken for you! You might ask, “Instructors take the exam for you? What do you mean?” Everybody has sat through a training with the meaningless cert tied on at the end…the instructor basically highlights nearly every question on the exam throughout the course. Not much needed intelligence in that!!! If you think about it…vendors (instructors) really need you to pass because it makes them look good.
Don’t get me wrong…there are some certs that carry a bit more weight in my opinion. Although I don’t have any Cisco certs, I have heard they require the individual to prove their skillset by ‘defending their network configuration’ in front of a panel (much like a PhD’s dissertation review). Unfortunately, certs requiring that level of minimum knowledge are few and far between. [Rumor has it since Cisco owns a substantial piece of VMWare – more challenging VMWare certifications will have the same ‘panel review’.]
Cert Corruption Case #1:
About a year ago, I signed up for a 1-day virtualization seminar focusing on security. At the end of the training the instructor offered a certification exam. I was dumbfounded…a certification exam after only a day of lecturing. USELESS!!! I was actually mildly offended that the vendor to create a certification based around a single day of training.
Cert Corruption Case #2:
Everybody has certifications now…Sourcefire, Nessus, even compliance vendors are creating them. Earlier this week I was surfing a vendor’s website and came across this statement “…will award the student the CHSS certification credential without the student having to take the CHSS exam if they have one of the below credentials.”
1) CISSP/SSCP from (ISC)²
2) SCNP/SCNA from SCP
3) Security+ from CompTIA
4) CISA/CISM® from ISACA
5) CSCS from ecfirst
So basically it’s a buy one, get one free!!! I cringe to think what certification justification the vendors think of next. And my advice to the younger generation of readers…do some due diligence before getting a certification. Determine how sought after it is in the industry…at the very least hit up dice.com and perform a search for it in the job skillsets.




