Front Office Football Central  

Go Back   Front Office Football Central > Archives > FOFC Archive
Register FAQ Members List Calendar Mark Forums Read Statistics

Reply
 
Thread Tools
Old 11-28-2004, 07:09 AM   #1
Galaril
Pro Starter
 
Join Date: Jan 2004
IT certifications in Security/Networking?

This is a question for those who work in the IT sector especially Info Security and anything else like system analysis, network or DB admin.I am completing (last semester) of my Masters in MIS(management info systems concentration) in Information security and am also finishing up the SANS (GIAC) Security Essentials(GSEC) certification.I am 35 yeras old and currently am working in South Korea for the local government as a contractorand. My current job gives me some job experience(basic) in the area of monitoring network traffic, training staff on security patching and other security related tasks.So, enough to put down on a resume.The problem is I lack much programming experience alittle Java, XML, SQL, and UML. I will be looking for a job in the general area of Info security or maybe analysis, network .My question is any recommendation on the next certification to take.I was leaning strongly towards SANS Securing Windows Servers and Clients but wondered if anyone else had other recommendationsie MCSE, MCSA ETC. I would like to get something that will help translate into improving my chances of breaking into this field or a related one. If you are not in the IT field sorry to bore you with this stuff.
Thanks.

Dan

Galaril is offline   Reply With Quote
Old 11-28-2004, 09:18 AM   #2
finkenst
College Benchwarmer
 
Join Date: Jul 2003
Location: usually sunny SoCal
cissp
finkenst is offline   Reply With Quote
Old 11-28-2004, 09:32 AM   #3
Galaril
Pro Starter
 
Join Date: Jan 2004
Yes, I thought of that also but I don't have the 4 years of security experience needed just 2 1/2.
Galaril is offline   Reply With Quote
Old 11-28-2004, 12:16 PM   #4
finkenst
College Benchwarmer
 
Join Date: Jul 2003
Location: usually sunny SoCal
Quote:
Originally Posted by Galaril
Yes, I thought of that also but I don't have the 4 years of security experience needed just 2 1/2.

minor detail that.

i know that my employer is getting people their cissp's.
finkenst is offline   Reply With Quote
Old 11-28-2004, 12:36 PM   #5
Galaril
Pro Starter
 
Join Date: Jan 2004
So, are you saying that the experience requirement is not that big of a deal.I heard that the certifying agency is checking the background of candidates to be sure they have the experience.
Galaril is offline   Reply With Quote
Old 11-28-2004, 12:53 PM   #6
finkenst
College Benchwarmer
 
Join Date: Jul 2003
Location: usually sunny SoCal
Quote:
Originally Posted by Galaril
So, are you saying that the experience requirement is not that big of a deal.I heard that the certifying agency is checking the background of candidates to be sure they have the experience.

i'm noy entirely sure as i don't have any of my certifications... but i'll check with some colleagues tomrrow.
finkenst is offline   Reply With Quote
Old 11-28-2004, 07:14 PM   #7
Galaril
Pro Starter
 
Join Date: Jan 2004
Thanks appreciated it .
Galaril is offline   Reply With Quote
Old 11-28-2004, 07:22 PM   #8
primelord
Pro Rookie
 
Join Date: Oct 2000
The CISSP is certainly the most well known of the security certifications, but the GIAC certifications are well respected in the industry as well. The GSEC is a good starting point, but I would suggest finishing another track such as the GCWN that you mentioned. The GSEC is a little too broad to get much attention. I currently hold a GCUX certification.

Once you have been in the industry a few years it would be in your best interest to look into the CISSP and maybe even Security+.

FWIW here is a thread from eariler in the year where we discussed this topic.

http://dynamic2.gamespy.com/~fof/for...+certification

Edit: I forgot to post the link.

Last edited by primelord : 11-28-2004 at 07:23 PM.
primelord is offline   Reply With Quote
Old 11-29-2004, 04:11 AM   #9
Galaril
Pro Starter
 
Join Date: Jan 2004
Primelord,
Thanks for the info.I think I will follow your advice.Should I look into any particular programming language to browse up on I was think of trying to learn some PERL or would SQL be better.I already know it alittle and have some programming experience in JAVA.Most likely I will be going for a windows based job after the GCWN.Also, I am curious about what part of It you are in.Thanks.

Dan.
Galaril is offline   Reply With Quote
Old 11-29-2004, 07:04 AM   #10
Alf
Pro Starter
 
Join Date: Jan 2001
Location: Rennes, France
Galaril : I would definitely recommend PHP + MySQL if you want to improve your programming language and web based knowledge. Both are easy to learn (via www.php.net and dev.mysql.com where you have online manuals). If you have already developped, it is quite easy and it's becoming some sort of standard combo.

Definitely not perl + sql, but with php + mysql you will get an head start, and then if you want to go the perl route (and any other sql server) you would already have the experience.
__________________
FOFL - GML - IHOF - FranceStats
Alf is offline   Reply With Quote
Old 11-29-2004, 10:06 AM   #11
primelord
Pro Rookie
 
Join Date: Oct 2000
Quote:
Originally Posted by Galaril
Primelord,
Thanks for the info.I think I will follow your advice.Should I look into any particular programming language to browse up on I was think of trying to learn some PERL or would SQL be better.I already know it alittle and have some programming experience in JAVA.Most likely I will be going for a windows based job after the GCWN.Also, I am curious about what part of It you are in.Thanks.

Dan.

I work in information security. Most of the patforms I support are Unix based platforms (FreeBSD and Solaris), but we have a few Windows platforms as well.
primelord is offline   Reply With Quote
Old 11-29-2004, 10:12 AM   #12
primelord
Pro Rookie
 
Join Date: Oct 2000
Quote:
Originally Posted by Galaril
Should I look into any particular programming language to browse up on I was think of trying to learn some PERL or would SQL be better.

Deciding on what language to learn really depends on what type of programs you want to write. Perl and PHP (especially in Windows) are best suited for web based applications. Although they can be used for standard apps. (My player_tracker program is written in perl) If you think you are going to be doing some serious Windows development though then you really want to learn C++.

If you are going to be going into an information security position then Perl may be all you need. It is the only language I ever learned. It is very good for writing small programs to parse log files and handle other small security tasks.
primelord is offline   Reply With Quote
Old 01-24-2005, 09:57 AM   #13
Galaril
Pro Starter
 
Join Date: Jan 2004
Well,
I have finally completed my MIS masters this April Graduating and also am just finidhing my SANS GSEC certification. I , as mentioned above am looking to get a job in InfoSec maybe security analyst or auditing. I am gonna try to pick up more PERL programing knowledge which should help me understand PHP somewhat.So I also want to get a book or two to learn more about a few other common industry technologies that are important for InfoSec people to know about. I am looking at get a more in depth understanding of oracle databases and cisco routers especially from a information security stand point. I may also being look at jobs that are working witht he health industry like a hospital so HIPAA will be a area to learn more about. Can anyone recommend ood books on any of these topics. Primelord? anyone else?
Galaril is offline   Reply With Quote
Old 01-24-2005, 12:59 PM   #14
primelord
Pro Rookie
 
Join Date: Oct 2000
Is your goal to learn PHP? If so I don't think you need to start with Perl. I personally prefer Perl, but they have a similar syntax in many areas and PHP is not an exceptionally difficult language to pick up. If you are only learning Perl to give yourself a good base for PHP I would just start with PHP. Now of course if you are wanting to learn both languages there is nothing wrong with that.

As far as books on additional security topics I would say you probably need to have an idea of exactly what you want to do. Is it going to be security for strictly the network or will you also be doing some server security. If you will be doing host based security on servers and workstations what operating system are they running?

Most Oracle administration books should have a security section in them. However if you want soemthing that is specifically about security and orace you can check out Oracle Security. It looks like the book is out of print, but it is still available throught he safari service I mentioned in the other thread. It is a bit dated, but will give you a good overall background on database security and the security sections in more recent Oracle books should suffice to get you running.

As for cisco security books there are a ton of them. Here are just a few:
CCIE Practical Studies: Security
Hardening Cisco Routers

And a lot of the more general Network Security books are going to cover information on Cisco solutions. Just look in the networking section of your local Borders and you will find a ton of books on security.

If you are looking for some broad topics it is worth it to pick up a CISSP book even if you don't plan on completeing the certification.
primelord is offline   Reply With Quote
Old 01-24-2005, 09:51 PM   #15
Galaril
Pro Starter
 
Join Date: Jan 2004
I am in a pickle because I just really want to get a job in infosec. I am not specific looking at any particular area. But, I would be working with both networks and servers with the OS most likely being Microsoft since I have zero experience in Linux/Unix.AS far as the PHP and PERL stuff goes. I am interested in learning both since I have heard they are both very important for Infosec professionals to know. My graduate degree and the GSEC cetification gave me a good broad view of tye technical topics especially in CISSP.I am especially interested to pick up PERL.Basically I am trying to initially learn skills and knowledge that seems to be in high demand for most infosec positions.In other words I am trying to make myself more technically marketable to potentail employees.

Dan G.

Last edited by Galaril : 01-24-2005 at 09:53 PM.
Galaril is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT -5. The time now is 09:57 PM.



Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.