Penetration Testing mailing list archives

Re: Certifications: Not worth the paper they are printed on?


From: Jon Kibler <Jon.Kibler () aset com>
Date: Sun, 05 Oct 2008 21:50:57 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Jay D. Dyson wrote:
On Sun, 5 Oct 2008, Jon Kibler wrote:

Yesterday I was reading a blog where someone with no security
experience whatsoever was grousing that they flunked the Security+
exam. The blogger also claimed to have over 100 certifications. In my
opinion, that many certifications undoubtedly qualifies this blogger
to be the Poster Boy for everything that is wrong with the
certification process.

First off, let's see the URL.

http://certcities.com/editorial/columns/story.asp?EditorialsID=176


Secondly, let's see this list of certifications this blogger claims s/he
possesses.  Suffice it to say some fact-checking is in order before
flying off the handle about the certification process being "broken."

<SNIP!>

It was not on the basis of this individual's claims -- true or false may
they be -- that I based this commentary. It is based on personal
experience dealing with a seemingly endless stream of 'certified'
individuals that have zero real world ability. In fact, for the
non-hands-on certifications, in my personal experience, I would say that
more individuals having these 'book certifications' are incapable of
doing 'real work' that those that are good technical workers.

Too many people have simply decided that "if I get certified, then that
means I am qualified to do the work." Absolutely, completely, and
totally wrong in both my opinion and my experience.

The process today is completely backwards. For certifications to be
meaningful, you must first get the experience, then get the
certification that validates your experience. Not the other way around!

Jon Kibler
- --
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC  USA
o: 843-849-8214
c: 843-224-2494
s: 843-564-4224
http://www.linkedin.com/in/jonrkibler

My PGP Fingerprint is:
BAA2 1F2C 5543 5D25 4636 A392 515C 5045 CF39 4253


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkjpbuYACgkQUVxQRc85QlOnMACdHkk3fUvvAnvhbKwx98G3BlmI
vyAAn2basKj2MudaNKCvLHM0QHAoE6Tk
=tZdx
-----END PGP SIGNATURE-----




==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes in 
Securing Web Applications
Get 45 Min Video and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------

Current thread: