The True Value of Cybersecurity Certifications

The Cyber Snapshot
22 May 202407:24

Summary

TLDRThe speaker reflects on their 30th year in the industry and their strong belief in the value of certifications. They highlight their own pursuit of top certifications like CISSP, CISA, and CCSP, emphasizing their role in validating skills and knowledge. The speaker advocates for the 'right way' to earn certifications, which involves more than just studying for the exam but also understanding the thought process behind them. They also discuss the benefits of classroom learning and the importance of vendor-neutral certifications for a holistic understanding of security controls. The conversation ends with the speaker's plans to continue pursuing certifications, aiming to complete the top 10.

Takeaways

  • 🎂 The speaker is entering their 30th year and feels old, but remains a strong supporter of certifications.
  • 📚 They have pursued certifications like CISSP and S Gack from the beginning of their career, emphasizing the importance of continuous learning.
  • 🔍 The speaker has been observing the top 10 certifications in the industry and has acquired six of them, highlighting their dedication to professional development.
  • 🛡️ Certifications are seen as a way to validate skills and knowledge, combating the imposter syndrome that many professionals face.
  • 📈 The right way to approach certifications involves respecting the credential, studying the material thoroughly, and not just memorizing exam questions.
  • 🤖 Certifications are not about memorizing commands but understanding situations, conflicts of interest, and best practices for information security.
  • 💼 Having certifications can help secure jobs as some organizations still require credentials as a form of validation.
  • 🏆 The speaker values the CISSP as a baseline certification that everyone in the industry should consider obtaining.
  • 👥 Recommending classroom or boot camp experiences for certifications, as they offer unique learning opportunities through peer collaboration.
  • 🌐 The speaker plans to continue pursuing certifications, focusing on vendor-neutral ones to understand the full context of security controls.
  • 🚀 There's a future plan to acquire more certifications, aiming to complete all top 10, showing a commitment to ongoing professional growth.

Q & A

  • What is the speaker's view on the importance of certifications in their career?

    -The speaker believes that certifications are valuable for several reasons, including validating skills and knowledge, combating imposter syndrome, and providing a baseline for understanding different areas within the industry.

  • What certifications does the speaker mention as being particularly valuable in the field of security?

    -The speaker specifically mentions CISSP, CISM, CISA, CRISC, Certified Ethical Hacker, and CCSP as some of the top certifications that are valuable in the security field.

  • How does the speaker feel about reaching their 30th year in the industry?

    -The speaker expresses that reaching their 30th year in the industry makes them feel old, but they also acknowledge it as a significant milestone.

  • What does the speaker consider as the 'right way' to approach certifications?

    -The speaker believes the right way to approach certifications is by respecting the credential, engaging with the material deeply, learning from various perspectives, and not just studying for the practice exam.

  • Why does the speaker emphasize the importance of not just relying on memorization for certification exams?

    -The speaker emphasizes this because they believe certifications should validate real understanding and skills, not just the ability to memorize and regurgitate information.

  • What does the speaker suggest about the value of certifications in securing jobs?

    -The speaker suggests that certifications can help secure jobs as some organizations and industries still ask for credentials as a form of validation from candidates.

  • How does the speaker view the role of certifications in building confidence in one's field?

    -The speaker views certifications as a way to build confidence by validating one's knowledge and skills, which can be reassuring, especially in a field as complex as security.

  • What is the speaker's opinion on the use of AI and its potential impact on understanding fundamental concepts?

    -The speaker is concerned that reliance on AI for tasks like searching for command lines could lead to a lack of understanding of fundamental concepts, which is crucial in the field.

  • Why does the speaker recommend attending a boot camp or classroom setting for certain certifications?

    -The speaker recommends this because of the collaboration and learning that can occur between peers, which can provide different perspectives and insights into various industries and scenarios.

  • What is the speaker's strategy for pursuing further certifications?

    -The speaker plans to focus on vendor-neutral certifications rather than vendor-specific ones to gain a broader understanding of technologies and security controls.

  • Does the speaker plan to pursue all of the top 10 certifications mentioned?

    -Yes, the speaker has plans to pursue all of the top 10 certifications, with a focus on continuing to learn and grow within their field.

Outlines

00:00

🎓 The Value of Certifications in Professional Development

The speaker reflects on their 30th year in the industry and their strong belief in the importance of certifications. They have pursued various certifications, including CISSP and S Gack, as a means to validate their skills and knowledge. The speaker emphasizes the right way to approach certifications, which involves more than just memorizing questions but also understanding the thought process and scenarios behind them. They highlight the benefits of certifications, such as building confidence, securing jobs, and validating one's expertise in the field. The speaker also discusses the value of in-person classes and boot camps for collaboration and learning from peers in different industries.

05:01

🚀 Pursuing Excellence Through Certifications

Continuing the discussion on certifications, the speaker shares their experience and views on the process and benefits of obtaining them. They mention the importance of passing certifications the right way, which demonstrates not only knowledge but also the ability to manage time, resources, and seek help when needed. The speaker believes that having certifications can indicate a person's capability to handle projects from start to finish. They also touch on the value of classroom settings for learning and networking across different industries. The speaker concludes by expressing their intention to pursue more vendor-neutral certifications to broaden their understanding of security controls and technologies, rather than specializing in a specific technology.

Mindmap

Keywords

💡Certifications

Certifications in the context of the video refer to professional qualifications awarded by various organizations to validate an individual's knowledge and skills in a specific area. They are crucial for career advancement in the IT and cybersecurity fields. The speaker mentions several certifications, including CISSP and CCSP, as a way to validate their skills and knowledge, emphasizing their importance in securing jobs and building confidence in the field.

💡CISSP

CISSP, or Certified Information Systems Security Professional, is a certification mentioned in the script that is highly valued in the cybersecurity industry. It signifies advanced knowledge in the field and is considered a 'baseline' or foundational certification for professionals looking to establish themselves in security roles. The speaker considers it a step up from base level certifications and has pursued it to validate their expertise.

💡SGack

The term 'SGack' appears to be a mispronunciation or typo in the transcript, likely referring to 'SysAdmin, Audit, Network, and Security (SANS)' which is a well-known organization that offers various cybersecurity certifications. The speaker mentions SGack alongside CISSP as part of their certification journey, indicating a focus on acquiring comprehensive security skills.

💡Baseline

In the video, 'baseline' is used to describe a fundamental level of knowledge or skill that one should have, particularly in the context of professional certifications. The speaker mentions that certifications like the CP (Certified Professional?) serve as a baseline layer for those entering the security field, suggesting that these certifications are essential for establishing a basic understanding and competence.

💡Imposter Syndrome

Imposter syndrome is a psychological pattern where individuals doubt their skills, abilities, or accomplishments and have a persistent fear of being exposed as a 'fraud'. In the script, the speaker relates this concept to the value of certifications, stating that they help to alleviate these feelings by providing validation of one's skills and knowledge within the industry.

💡CP

CP, likely referring to a certification like the Certified Professional, is mentioned as a baseline or entry-level certification for those wanting to get into the security field. The speaker views it as a necessary stepping stone and part of the foundational layer of certifications that validate one's basic skills in security.

💡CISA

CISA, or Certified Information Systems Auditor, is one of the top certifications listed by the speaker. It is highly regarded in the IT audit, control, and assurance domain. The speaker includes it in their list of important certifications, indicating its value in validating one's ability to perform audit, control, and assurance tasks within an organization.

💡CISM

CISM, or Certified Information Security Manager, is another top certification mentioned in the script. This certification is geared towards individuals who manage, develop, and oversee information security systems. The speaker's pursuit of this certification reflects their commitment to gaining a comprehensive understanding of security management practices.

💡CRISC

CRISC, or Certified in Risk and Information Systems Control, is a certification that the speaker has earned. It is designed for professionals who are responsible for designing, implementing, and managing risk within an organization's IT environment. The speaker's mention of CRISC underscores their focus on gaining a broad set of skills in risk management and control.

💡Certified Ethical Hacker

Certified Ethical Hacker (CEH) is a certification that validates an individual's ability to understand and exploit vulnerabilities in systems, with the aim of improving security. The speaker has this certification, which indicates their expertise in ethical hacking and contributes to their comprehensive skill set in the cybersecurity domain.

💡CCSP

CCSP, or Certified Cloud Security Professional, is a certification that focuses on cloud security. The speaker has earned this certification, demonstrating their knowledge and skills in securing cloud computing environments. It is one of the six top certifications the speaker has achieved, highlighting their commitment to staying current with evolving technology landscapes.

Highlights

The speaker is in their 30th year and is a big supporter of certifications.

They took sand certifications in Northwest Territories and looked at base level certifications in Alberta.

The speaker considers CISSP and S Gack certifications as the next step up from base level.

They have been watching the top 10 security certifications over the last few years.

The speaker has six of the top 10 certifications, including the CP, CISA, CISM, CRISC, CEH, and CCSP.

They believe certifications are valuable for validating skills and knowledge.

The right way to pursue certifications is to respect the credential and learn from different perspectives, not just studying for the exam.

Certifications help build confidence and sometimes secure jobs as some organizations still ask for them.

The speaker found the CSSP certification to be a great baseline that everyone wants.

They believe passing certifications the right way shows you can take on a project from beginning to end.

Attending a boot camp or classroom for certifications is recommended for collaboration and learning from peers.

Different industries have different approaches to security, and certifications can help understand that.

The speaker plans to pursue the remaining certifications, focusing on vendor-neutral ones.

They aim to understand the full context of technologies and security controls rather than being a subject matter expert in a specific technology.

Transcripts

play00:06

I realized that I am now in my 30th year

play00:09

in it this year which really sounds

play00:14

incredibly that's great which makes me

play00:17

feel very old though um but one thing

play00:19

that I've really been uh a you know big

play00:23

uh supporter of is certifications M um

play00:27

from the beginning I've

play00:30

when I was even in Northwest Territories

play00:31

I took some sand certifications when I

play00:34

moved to Alberta I I looked at what the

play00:38

base level I considered and I don't want

play00:40

to say entry level as base level but I

play00:42

mean the next step up uh what those are

play00:45

for certifications and to me it was the

play00:47

cissp and and the S gack things this

play00:50

nature now I haven't done a lot of what

play00:53

I call the industry level big search of

play00:55

a while but I've been watching you over

play00:58

the last three or four years and you're

play00:59

just nailing them off and I was actually

play01:02

looking at a list of the top 10 search

play01:04

and you have six of them okay you have

play01:07

your CP which is pretty much a a if you

play01:09

want to get into security nowadays and

play01:12

again I don't mean that it's entry I

play01:13

mean any um not entry level but that

play01:17

Baseline it's that Baseline layer

play01:19

because I do believe and there's always

play01:21

these talks on on LinkedIn that you

play01:23

can't ask for an entry-level position

play01:25

having a CSP which I agree with so

play01:27

there's that there is the cisa

play01:30

isaka CIS cism another isaka

play01:34

certifications uh there's a isaka crisk

play01:37

yes that you have um there's the

play01:41

certified ethical hacker which you have

play01:44

and then what's the cloud certification

play01:46

you have the ccsp which is the also from

play01:48

the IC Square okay yeah so you have six

play01:51

of what is considered the top 10

play01:53

certifications out there now so I was

play01:57

going to I I do like to ask people what

play01:59

what they take on certification is being

play02:01

that you have six of the top 10 I'm

play02:02

going to say you probably think

play02:03

certifications are valuable but why did

play02:06

you pursue the certifications 100% so uh

play02:11

do I think it's kind of like important

play02:13

or valuable yes I do uh for many reasons

play02:16

one is

play02:18

um it's help you validate your skills

play02:21

and help you validate your knowledge

play02:23

right so we are all in the industry

play02:25

probably having that imposter syndrome

play02:28

in terms of like um am I really um well

play02:33

educated or kind of like have the

play02:35

necessary skills or knowledge in certain

play02:37

areas and certificates or credentials

play02:40

they help you to validate that right if

play02:42

you are doing it the right way so if you

play02:44

are trying okay that's a key term there

play02:46

so let's yeah so what define the right

play02:48

way so the right way is basically you

play02:50

don't just go and study for the practice

play02:53

exam or kind of like some questions and

play02:55

you

play02:56

say exactly no you need you need really

play02:59

to to respect the certificates respect

play03:02

their credential and respect that many

play03:05

people spend a lot of time to build that

play03:07

certificates build the thought process

play03:09

behind it right and read the book uh

play03:12

check out resources learn from the

play03:15

perspective of different people and then

play03:17

definitely you need to do uh the

play03:20

questions the questions help you to

play03:22

understand different situations help you

play03:24

understand different scenarios and

play03:26

that's what I like about those

play03:27

certificates is basically it doesn't

play03:30

give you a multiple choice of like a

play03:31

command line or whatever you to kind of

play03:33

humorize which today you can Google it

play03:36

you can like use geni geni to kind of

play03:39

like I was just going to say AI now you

play03:41

can ask AI to do a lot for you uh what

play03:43

happens if everybody gets reliant on do

play03:46

using Ai and then they don't understand

play03:47

some of the fundamental SI you got there

play03:49

exactly okay but rather they really

play03:51

discuss situations they discuss conflict

play03:53

of interest they discuss what is the

play03:55

best action if you are trying to protect

play03:58

your environment or your dat sense

play04:00

information regulations all that stuff

play04:02

so I found the certificate validate my

play04:06

knowledge help me kind of like build

play04:08

confidence in in the field and sometimes

play04:11

even secure some uh some jobs like some

play04:14

organizations or some Industries they

play04:16

still ask for credentials they still ask

play04:19

for um um validation from you right so

play04:23

that's that's really the idea behind it

play04:25

yeah i' I've whenever I look back at the

play04:27

certifications I've taken I I I definely

play04:30

see the cssp as that Baseline one that

play04:32

everybody wants I personally have always

play04:34

and maybe I'm biased because I took the

play04:35

Sands course where you actually had to

play04:37

take like the actual class and you had

play04:39

to take the labs and use your challenge

play04:42

at the end I found that those to me were

play04:44

more worthwhile because I had to

play04:46

demonstrate actually skill set yes um

play04:49

but that's a a great base level um great

play04:53

base layer and I always also say

play04:56

that you know while I do see I do know

play04:59

people out there who try to brain dump

play05:01

stuff things of that nature uh I think

play05:04

you can usually you should be able to

play05:05

tell that through an interview process

play05:08

by just a very yeah you some

play05:11

very particular questions should Point

play05:14

some of that out um and the people who

play05:17

pass these exams the right way we'll

play05:19

talk about that right way not only do we

play05:21

understand that they have that base

play05:22

level but I also know that they can take

play05:26

on a project and if it's a some of these

play05:29

search might take three to six months

play05:30

again I know that they can budget time

play05:33

they can study they can get the right

play05:34

resources they can ask for help they've

play05:36

have a process and I know they could

play05:38

take on a project go from beginning to

play05:40

end they invested and that tells me a

play05:43

lot about uh individuals when they do uh

play05:46

when they you know they have these

play05:47

certifications absolutely true and um

play05:51

speaking about sense for example you are

play05:53

saying uh being in a classroom or um I

play05:57

definitely recommend that if your budget

play05:58

permits go for a boot camp go for

play06:01

because like the collaboration between

play06:03

you and your peers in the class is

play06:05

different you can ask about certain

play06:07

scenarios or situations they run into

play06:10

because we are usually work with one

play06:13

industry or maybe you shift to another

play06:14

industry but it's really nice to see how

play06:16

other people think in different

play06:18

Industries or different sectors what

play06:20

type of regulations they they need to

play06:22

handle or deal with what type of risks

play06:24

to the well Healthcare versus Financial

play06:26

both could use security for but have

play06:28

different exact um different approaches

play06:30

to it I think that's great and um I I

play06:34

kind of I wanted to finish off with just

play06:36

saying that you've got six out of 10 are

play06:38

you going to try to finish all 10 um I

play06:41

have plans yeah awesome I on yeah I have

play06:44

plans to move on definitely I still

play06:46

going to focus on vendor neutral

play06:48

certifications rather than vendor

play06:50

specific because I think it depends on

play06:53

your role what's your career goals in my

play06:55

in my case is basically um um I like to

play07:00

kind of like work on the whole context

play07:03

or understand the full context of

play07:05

Technologies the security controls

play07:06

rather than focusing on or being a

play07:09

subject Market expert in certain

play07:10

technology right yeah no sounds good I

play07:13

can't wait to see what you're going to

play07:14

do next for the certifications it's

play07:16

going to be um fun to watch yeah

play07:19

[Music]

Rate This

5.0 / 5 (0 votes)

Related Tags
CertificationsIT SecuritySkill ValidationCareer AdvancementCISSPCISACertified Ethical HackerCloud SecurityProfessional DevelopmentImposter SyndromeVendor Neutral