I have a question for the mid-to-upper level infosec guys. The article mentions lots of certifications and professional organizations. I can certainly see value in these associations and certifications, but I've always been leery of professional certifications. I felt that they were for mediocre players who didn't have "real" experience to show and needed some vocational training and certification. Am I way off? Are these certifications worthwhile when evaluating job applicants? Do they make you a more capable professional?
Like the article hints, it really depends on what you want to do. None of our engineers bother with certifications (and we don't look for them when evaluating applicants). The CSO, IR and managed services folks, on the other hand, collect them like Pokémon.
Comments
I have a question for the mid-to-upper level infosec guys. The article mentions lots of certifications and professional organizations. I can certainly see value in these associations and certifications, but I've always been leery of professional certifications. I felt that they were for mediocre players who didn't have "real" experience to show and needed some vocational training and certification. Am I way off? Are these certifications worthwhile when evaluating job applicants? Do they make you a more capable professional?
Like the article hints, it really depends on what you want to do. None of our engineers bother with certifications (and we don't look for them when evaluating applicants). The CSO, IR and managed services folks, on the other hand, collect them like Pokémon.