Network execs are naturals for the information security fields

Opinion
Feb 7, 20073 mins

* Considering transferring into the information security field?

Networking executives interested in entering the security field, or just want to formalize their security knowledge should consider taking training for (ISC)2’s Systems Security Certified Practitioner certification. Network pros could use SSCP as a stepping stone to other (ISC)2 credentials, such as Certified Information Systems Security Professional (CISSP), which has topped many recent salary surveys and is the gateway to chief information system officer-level roles.

Networking executives interested in entering the security field, or just want to formalize their security knowledge should consider taking training for (ISC)2’s Systems Security Certified Practitioner certification. Network pros could use SSCP as a stepping stone to other (ISC)2 credentials, such as Certified Information Systems Security Professional (CISSP), which has topped many recent salary surveys and is the gateway to chief information security officer-level roles.

Network engineers need to have a solid understanding of the risks that affect the network and are naturals to get into the security field, says Ed Zeitler, who was named the security professional organization’s new executive director in January. Formerly a security exec at VW Credit, Charles Schwab, Fidelity Investments, Bank of America and Security Pacific National Bank, Zeitler says network execs already have a good understanding of the IT infrastructure and are likely to already participate in the types of training and conferences that are required to maintain (ISC)2’s security certifications.

And even if network execs have no interest in transferring into the security field, getting educated in security would be useful to a network pro’s job in many cases, says (ISC)2, and could be a requirement in some roles. The U.S. Department of Defense, for example, mandates that its “information assurance” workers obtain a commercial certification that has been accredited by various standards organizations.

The directive, which was put into action a year ago, could affect 100,000 people who are either full- or part-time military service members, contractors or foreign employees with privileged access to a Defense Department system, according to the office of Human Resources and Training Division within the Defense-Wide Information Assurance Program (DIAP). The mandate also requires those same employees to maintain their certified status with a certain number of hours of continuing professional education each year. (ISC)2’s SSCP and CISSP certifications qualify under this directive.

So what does it take to get SSCP certified? Before taking the exam, candidates must subscribe to the (ISC)2 Code of Ethics, and have at least one year of cumulative work experience in one or more of the seven domains in information security: access control; administration; audit and monitoring; cryptography; data communications; malicious code/malware; and risk, response and recovery. Certified professional are required to recertify every three years. More about SSCP can be found here.

* (ISC)2 has just released its 2007 resource guide for security professionals. The free guide contains information about security-focused professional associations, conferences and trade shows, Web sites, online and print publications, and educational institutions and organizations around the world.