Information Security Certification Guide

Friday, June 27, 2008 by Mistlee


Can't see any images? -Click To View!



Recent Articles

ISP Suggested As Certification Standard
By paying a few fees and sacrificing a handful of stamps, it's possible to get several degrees within a single month. Tell anybody about those degrees, though, and you'll hear laughter instead of congratulations.

The Technology Or The Presenter?
Another interesting presentation today at the iLinc Customer Summit came from Barb Nead-Nylander of the Dow Chemical Company. She talked about Dow's requirement for all of their online instructors (well over one hundred of them) to take an internal training...

Studying For Certification Exams
Well, I'd signed up to take the CompTIA A+ exam at the end of November but things got very out of control business-wise (one got busier, and the other got sold) so I hadn't done a lot in terms of getting ready.

Prince2 Practitioner New Exam Format
The new Prince2 Practitioner exam is in multiple choice format. Don't be fooled into thinking this is going to make it easier. It's still three hours long and now you are tested across nine topics rather than the original l three. These topics are: Processes. Business Case...


06.27.08

Information Security Certification Guide

By Dan Morrill

Information Security Certifications are part of the credentialing landscape for an information security professional, and in many ways, those just generally interested in the subject.

Search Security writers Ed Tittel and Kim Lindros have put together the definitive list of the top 50 information security certificates and certification paths for those who are serious about getting their information security certification.

In fact, the sheer number of credentials can make navigating the security certification landscape a dizzying experience. Simply identifying the vast array of offerings can be time consuming and overwhelming -- never mind determining which certification best fits your situation. Source: Search Security

There is always going to be concerns about the money, the time, and the value of a security certificate. The question comes in as to how much you want to have any hope at job security. There is job security in information security by keeping your skills up and adopting life long learning. That is a reality, even if you get canned from one company, having a string of letters after your name can help, as long as it is not too many. If you have a dozen use only the three latest ones on your title, while interesting, if you have a dozen, it looks like all you did was go to school.


The very good part about the Search Security article is that they really do cover the whole certificate landscape in line with what people might want to do. Do you want a generalist or a specialized certificate? One thing they do not do is go into the comparable wage process for each security certificate (you have to make sure there is a payoff for the certificate, if there is no bump in dollars for having it, then it is not worth getting because everyone else has it and the market is diluted).

This is one of those career planning articles that would do folks looking to start out, or those seasons veterans looking for something new, to plan and plot out their information security careers. The key here is to keep on learning, keep on being challenged, and keep on building your marketability always.

Comments


About the Author:
Dan Morrill has been in the information security field for 18 years, both civilian and military, and is currently working on his Doctor of Management. Dan shares his insights on the important security issues of today through his blog, Managing Intellectual Property & IT Security, and is an active participant in the ITtoolbox blogging community.

About ITCertificationNews
A collection of resources designed to assist IT professionals evaluating various certification programs within the IT world. IT Certification Articles and UPdates

ITCertificationNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
DevNewz.com WirelessProNews.com
CProgrammingTrends.com ITmanagementNews.com


-- ITCertificationNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2008 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


Unsubscribe from ITCertificationNews.
To unsubscribe from ITCertificationNews or any other iEntry publication, simply send an email request to: support@ientry.com

IT Certification Articles and UPdates ITCertificationNews News Archives About Us Feedback ITCertificationNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact

Clipperz's Zero-Knowledge Web Application

Friday, June 20, 2008 by Mistlee

Clipperz's Zero-Knowledge Web Application

By Savio Rodrigues

I previously wrote about Clipperz because I really think Marco and team at Clipperz have a great idea. To summarize, Clipperz has technology for "zero-knowledge web applications" which they have applied to an online password manager as a proof of concept. Marco writes:

"We simply meant that Clipperz knows nothing about its users and their data!

As a consequence of the "learn nothing" mantra, every zero-knowledge application should be completely anonymous, or at least it should make it impossible to relate the real name or email of a user to his data"

It seems that Richard Stallman agrees that Clipperz technology could be very useful in the cloud-based computing world that awaits us.

The guys at Clipperz and RMS have been talking about how Clipperz's technology could provide freedom and privacy in the cloud. To that end, they suggest (summarized from here):

Choose AGPL: If your services are based on software with an AGPL license, you have to make the source code available to anyone that uses the service

Add zero-knowledge sauce: The server hosting the web app could know nothing of its users, not even their usernames

Build a smarter brower: We still need to provide users of web apps with an even more flexible and secure environment.


To expand on #3, Marco writes:

"Stallman suggests adding a feature to the browser allowing a user to say: "When you get URL X, use the Javascript from URL Y as if it came from URL X." If the user does invoke this feature, he can run his copy of the Javascript and still being able to exchange data with the server hosting the web application.

A browser with such capabilities could also easily verify if the Javascript from URL X is different from the alternative Javascript stored at URL Y. If the user trusts the present release of the Javascript code from URL X, he could make a copy of it at URL Y and be alerted if any change occurs.

This solution protects the user from malicious code that could be unknowingly executed by his browser, stealing his data and destroying the whole zero-knowledge architecture "

Personally, I think #2 and #3 are great ideas. I'm having trouble with #1, the AGPL requirement. From an academic standpoint, I can agree with it. But if we're asking Google, Amazon, Microsoft, IBM, Sun, HP, etc. to use AGPL'd code, it could become an uphill battle.

Using the AGPL'd widget (from Clipperz in this case) that enables a "zero knowledge web application" is not the problem. However, the viral nature of the AGPL would be a concern for any vendor who intends to drive revenue from their proprietary code/application delivered via a SaaS from a Cloud. I guess that these vendors could always license the Clipperz technology...
News Archives About Us Feedback WebDeveloperNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact