2016 Recruiting Forecast for IT Professionals

When thinking about the recruiting landscape for 2016, my first thought is that it all depends on which side of the interview you are on. 2015 has shown the strongest demand for skillsets that ISACA members have (IT audit, governance, security and risk) that we have seen since 2005-2007, during the first years of Sarbanes-Oxley Act (SOX) compliance. Currently, conditions are extremely tough for hiring managers who are trying to lure top talent to their teams, and I do not expect this to change anytime soon.

Why the talent shortage? IT audit, governance, security and risk skillsets are an increasingly bright spot on the radar of organizational leaders. This is partly due to increasing regulatory and compliance requirements and high-profile data breaches, but also because of years of efforts to transform IT audit from a “necessary evil” to a value center.

Because of the increased understanding of the value IT risk and controls professionals provide, there has been a significant uptick in non-audit positions since 2012—especially IT risk and compliance roles. These “second line of defense” roles were gaining traction in 2007-2008, but funding in this space tightened (or just plain vanished) during the recession in the US. Now, in a steadily improving economy, budgets for these roles have replenished and the resulting demand has stretched a thin talent pool even thinner by recruiting heavily from IT audit groups.

Another factor is that some of the primary talent generators in our field, the “Big 4” and similar client service firms, made deep staffing cuts during the recession and also dramatically reduced hiring off college campuses from 2009-2012.

These factors have created rosy conditions for most IT professionals seeking new opportunities. Barring a significant global political or economic disturbance, I expect the strong demand in our space to extend at least through 2016.

I am often asked, “What are the top skills in demand?” That is a difficult question to answer for a constituency as diverse as ISACA’s, for example, which covers many disciplines in the IT controls world, ranging from the deeply technical to more general relationship management roles. Cyber security is the word on almost everyone’s lips right now. You can question whether or not cyber security is “new” or just the next iteration of complexity in technology assurance, but regardless, rebranding your skillset toward cyber security activities is a sound career strategy in the near term.

In the long term, whether you are focused on IT audit, governance, risk, compliance, or security, your success will depend on aptitude, attitude, and altitude. By aptitude, I mean your ability to continually learn and adapt quickly to technology and business developments in an increasingly complex and competitive business climate. By attitude, I mean approaching your work with dedication, resilience, optimism and empathy. By altitude, I mean seeing IT risks from the viewpoint of the C-suite, and communicating the impact of risks in business language to a variety of stakeholders.

So, how do you position yourself for continued success in 2016? You have heard the saying, “if it ain’t broke, don’t fix it.” I say, “if it ain’t broke, do preventative maintenance.” Each of you probably knows at least one professional who learned a painful lesson during the recession. Many faced involuntarily unemployment for the first time, and were caught having allowed their skills to get stagnant. Now is the time to do preventative maintenance and to be proactive about future-proofing your skillset. Earn an additional certification. Seek out a mentor to help you determine three specific soft and hard skills for you to acquire or improve, and then put an action plan in place to achieve those goals.

Some people will read this and think, “I should do that,” but then it will get shuffled to the side, as life’s many professional and personal demands take a higher priority. I understand. I will leave you with this: I am optimistic that the steady climb in demand for the discussed IT skillsets will continue in 2016, but go ahead and plan your career as if it will not. Either way, you will be a winner.

Derek Duval, CPC
Duval Search Associates, LLC

[ISACA Now Blog]

(ISC)² GAP Instructor’s Mantra: “Never Stop Learning”

Meet Donnie Grimes, (ISC)² Global Academic Program (GAP) instructor and vice president of information systems and creator of the master’s program in cybersecurity for the University of the Cumberlands. Oh, and budding sound man. When he’s not teaching, Donnie works on sound engineering and mixing at live events. He’s also starting to learn about staging and lighting.

As a teacher, his favorite classroom moments are those times when he’s able to witness students’ reactions as they realize they start to grasp a difficult concept. He reflects, “Seeing their faces light up and being a small part of contributing to a student’s development makes teaching the best job in the world.” He especially enjoys teaching information security courses, where the field is constantly evolving as the threat landscape changes.

His university launched its graduate cybersecurity program in 2012, thanks in large part to Grimes, who spearheaded curriculum development. Donnie shares (ISC)2’s belief that aligning curriculum with industry certifications is a key to closing the skills gap and will ultimately result in a stronger, more employable workforce.

Seeing the value in aligning courses with industry certifications, he based the school’s curriculum upon the CISSP, with one course centered upon each of the CISSP CBK domains. He did so because he believes that helping students graduate with certifications will help them get their feet in the door when applying for jobs. When he heard about the (ISC)2 Global Academic Program, Grimes said, “I instantly knew that I wanted to associate my university’s graduate program with the GAP.”

A key philosophy that drives his teaching is that lifelong learning is essential not only to securing a job, but also to being effective once you’ve got one. He believes the education and certification approach provides students with the best chance of both employability and professional success. “Certifications do not replace education,” he asserts, “but they do help to validate a candidate’s knowledge in a given domain and puts him/her on a path for continual learning.”

He advises, “Never forget that you’re in a field that will require you to update your education continually. Graduate programs, like the one we offer, will provide you the skills that you will need throughout your career. Certifications, which GAP schools provide opportunities for, will hold you accountable and force you to keep your skills fresh.”

Read our recent blog about GAP school the University of the Cumberlands here. And if you’re ever in Williamsburg, Kentucky, be sure to attend a show Donnie is working. You just might like what you hear.

For more information on the (ISC)2 Global Academic Program, please visit https://www.isc2.org/global-academic-program/default.aspx.

[(ISC)2 Blog]

APT Study: The Good, the Bad and the Key Takeaways

Today at the CSX North America conference in Washington DC, ISACA released its annual Advanced Persistent Threat Survey of 660 cybersecurity professionals across the globe. Advanced persistent threats (APTs) continue to capture the spotlight in the wake of their successful use to launch several high-profile data breaches. The third in a series of studies from ISACA’s Cybersecurity Nexus (CSX ) that are designed to uncover information security professionals’ understanding and opinions of APTs, technical controls, internal incidents, policy adherence and management support, this report reveals positive trends since the 2014 survey.

The good news is that improvements can be seen in the level of awareness of the unique aspects of APTs and the benefits of addressing them through a variety of countermeasures. A strong correlation clearly exists between the perceived likelihood of an APT attack on the enterprise and the enterprise’s adoption of improved cybersecurity practices. Yet, not all avenues for APT intrusion are fully locked down. Mobile device security is lagging, despite acknowledgment that the “bring your own device” (BYOD) trend increases APT risk, and a preference is seen for technical controls over education and training, even though many successful APT attacks gain entry by manipulating individuals’ innate trust and/or lack of understanding.

Every year, the damage and costs related to cyberattacks multiply at a shocking rate. Major cyberattacks targeting financial, retail, healthcare, government and the entertainment industries have resulted in tens of millions of exposed records, billions spent on remediation and significant damage to many brands. Cybercriminals continue to exploit individuals and enterprises while increasing profits from more than US $300 billion in 2012 to an estimated US $1 trillion in 2014. Juniper Research has predicted that their profits will top US $2 trillion in 2019.

Social engineering remains at the center of APT activity to gain footholds into information systems. Early efforts began with phishing, then evolved to spear phishing, and proceeded on to whaling, which often included an attachment or a link that contained malware or an exploit. However, over the past three years APTs have moved on to the Internet as the main attack vector (e.g., web sites, social media and mobile applications).

As the threat vector continues to evolve, concern remains due to the fact that many organizations are dependent on interconnected relationships to perform key business functions, yet 75 percent of respondents have not updated agreements with third parties for protection against APTs. Gaps in third-party relationships have resulted in many significant breaches because attack visibility is limited. This may be a contributing factor to survey data indicating that 28 percent of respondents have been subject to an APT attack.

However, overall positive change is occurring as a result of the recent high-profile breaches. There has been a significant increase in leadership involvement. Nearly two-thirds of the survey participants (62 percent) indicate that their organizational leadership is becoming more involved in cybersecurity-related activities, and 80 percent see a visible increase in support by senior management. This is a significant positive first-step in the combating the APT.

One thing is clear: to ensure organization cyber resiliency, action is needed from the boardroom to the break room. Everyone plays an important part.

Montana Williams
Senior Manager of Cybersecurity Practices, ISACA

[ISACA Now Blog]

Securing Tomorrow: Society Must Wake Up and Take Ownership of Identity

There are trends that have been on the industry’s radar for a while now; social, mobile, applications and cloud. However, within the next year, we’ll see more of an emphasis on one of the key underpinnings of these trends – identity. The issues with data management and security are often told and understood from an industry, business or sector perspective; but society as a whole is still arguably not at a point where it is fully awake to these issues and how they directly affect individuals. Next year, I believe we will begin to see people recognising the need to make big decisions around privacy. This is especially true when it comes to how much of their identity and data they are and should be willing to ‘give away’ or hold back, and balancing this with the convenience of their rapidly developing online lives.

Many of us recently updated to iOS 9 and downloaded it without hesitation. Today you can ask Siri or Cortana to access your holiday pictures in an instant, pay for your shopping with your phone or check your heart rate or symptoms on a health application if you’re unwell. Every time we use one of these conveniences, we are giving away more and more information about our lifestyles, and increasingly becoming owned by the ecosystems that we choose.

We are still largely unaware of where and how our data can be accessed; and the consequences can be potentially dangerous. A study published in BMC Medicine recently revealed that 20 percent of the health apps it looked at did not have a privacy policy, most of the apps communicated with one or more third party services, and four of the apps even sent identifying and confidential health information without encryption. The general invasion of privacy isn’t the only problem. The data could fall into the hands of parties who could be actively seeking it out (e.g., insurance companies).

While society as a whole isn’t in a state of security and privacy awareness that it needs to be, there are signs that this is beginning to change and industry is beginning to respond. Following its launch of iOS 9, Apple recently launched a new section of their website dedicated to explaining to customers its approach to privacy and how it manages data.

Society is still not catching up fast enough, and there is currently a fundamental disconnect between what motivates product and technology development and what is needed to truly secure it. Organisations are putting their efforts into protecting corporate reputation, rather than investing in prevention with a ‘security-by-design’ approach. The speed at which new applications and devices are brought to market is faster than ever before and we are dealing with more data than ever. A culture of making security a staple part of development processes and programming needs to be embedded within every organisation that has a service to offer involving storing or managing consumer data. Such requirements are too often considered down the line. As a body of certified cyber, information, software and infrastructure security professionals, (ISC)² recently took steps to promote such a culture by working with the government, the Council of Professors and Heads of Computing, BCS, the Institute for IT and other industry bodies to create course guidelines to enable cybersecurity to become a core component of UK computing degrees. The result was a set of guidelines that detail aspects of defensive programming to defend against basic risks, as well as having core modules such as secure systems and products, and cybersecurity management.

By taking steps like these, society can move to a culture of ‘security first’ over time.  The key is to start with future IT professionals before they enter the workforce to engrain security within them for any programming or development. This will ultimately enable the future workforce to respond to the needs of a more security aware general public (customer base) that will be ready to take control over their own data and identity.

Dr. Davis will be asking a panel of experts, including Oracle’s Director of Security for EMEA Georg Freundorfer; CISO for Deutsche Flugsicherung Dr. Sebastian Broecker; and former U.S. White House Advisor and current Executive Director at Safecode Prof. Howard Schmidt their visions looking forward in 2016 and beyond as he moderates the opening keynote, “How Can we Secure Tomorrow Today?” at (ISC)² Security Congress EMEA in Munich 20-21 October. — Dr. Adrian Davis, CISSP, Managing Director, (ISC)² EMEA

[(ISC)² Blog]

10 Security Certifications To Boost Your Career

Earning a security credential can help you open the door to a great job. But you need to know which certification is the right one for you.

GIAC Security Essentials (GSEC)

Global Information Assurance Certification (GIAC) is the leading provider and developer of Cyber Security Certifications, globally recognized by government, military and industry leaders. GIAC tests and validates the ability of practitioners in areas including security administration, forensics, management, audits, software security, and legal.

Description
This certification is designed for candidates who want to demonstrate skills in IT systems roles with respect to security tasks. Ideal candidates for this certification possess an understanding of information security beyond simple terminology and concepts.

Prerequisites: None

Exam: GIAC Security Essentials (GSEC)
(180 questions, 5 hours, 73% passing score)

Approx. Cost for Exam
$1,099 USD, administered by Pearson VUE (Affiliate Pricing for GIAC Certification in conjunction with SANS training is $629 USD)

Available Courses
Recommended course SEC401: Security Essentials Bootcamp Style,

Self-Study Material
Training events ($5,950 USD), Self-study books and DVDs ($5,350 USD), Videos from Dr. Cole

Online Practice Test
SANS Security Essentials Assessment Test, (Login credentials required)

(Image source: GIAC)

(ISC)² certifications are globally acknowledged as the Gold Standard in for educating and certifying information security professionals. (ISC)2 provides certification in areas such as information security, system security, authorization, software development, digital forensics and healthcare. The two key certifications are Certified Information Systems Security Professional (CISSP) and Systems Security Certified Practitioner (SSCP).

This certification is designed for candidates interested in the field of information security. The ideal candidates are those who are information assurance professionals and know how to define the information system architecture, design, management and controls that can assure the security of business environments.

Prerequisites
Candidates must have a minimum of 5 years of paid full-time work experience in 2 of the 8 domains of the CISSP Common Body of Knowledge (CBK), which covers critical topics in security including risk management, cloud computing, mobile security, application development security, and more.

Exam
CISSP – Certified Information Systems Security Professional (250 questions, 6 hours, 70% passing score)

Approximate Cost for Exam
$599 USD (For Americas, Asia Pacific, Middle East and Africa regions), administered by Pearson VUE

URL
https://www.isc2.org/cissp/default.aspx

Available Courses
CISSP Course Overview

Self-Study Material
Exam Outline Official (ISC)² Guide to the CISSP
— Official (ISC)² CISSP CBK Training Seminar, and SSCP CBK Training Seminars
–(ISC)²’s Live Online course

Online Practice Tests
–(ISC)² Practice Tests App is available for iOS users: NOTE: The CISSP and SSCP practice test questions are not currently aligned with the domain refresh. New questions will be available in mid-2015.

Image Source: (ISC)²

This certification is designed for candidates interested in the field of information security. The ideal candidates are those who are information assurance professionals and know how to define the information system architecture, design, management and controls that can assure the security of business environments.

Prerequisites
Candidate is required to have a minimum of one year of cumulative paid full-time work experience in one or more of the seven domains of the SSCP CBK. If candidates do not have the required experience, they may still sit for the exam and become an Associate of (ISC)² until they have gained the required experience.

Exam
SSCP – Systems Security Certified Practitioner (125 questions, 3 hours, 70% passing score)

Approximate Cost for Exam
$250 USD (For Americas, Asia Pacific, Middle East and Africa regions), administered by Pearson VUE

URL
https://www.isc2.org/sscp/default.aspx

Available Courses
SSCP Course Overview

URL Self-Study Material
Exam Outline
(ISC)² Guide to the CISSP
(ISC)² CISSP CBK Training Seminar and SSCP CBK Training Seminars
(ISC)²’s Live Online course.

Online Practice Tests
(ISC)² Practice Tests App is available for iOS users. NOTE: The CISSP and SSCP practice test questions are not currently aligned with the domain refresh. New questions will be available in mid-2015.

Image Source: (ISC)²

 

Information Systems Audit and Control Association (ISACA) certifications are globally accepted and recognized, and are known for helping candidates combine the achievement of passing an exam with credit for their work and educational experience.

The key certifications offered by ISACA are Certified Information Security Manager (CISM) and Certified Information Systems Auditor (CISA). Other certifications offered include Certified in the Governance of Enterprise IT (CGEIT) and Certified in Risk and Information Systems Control (CRISC).

Description
This certification is for candidates who have an inclination towards organizational security and want to demonstrate the ability to create a relationship between an information security program and broader business goals and objectives. This certification ensures knowledge of information security, as well as development and management of an information security program.

Prerequisites
Candidates must have five years of work experience in the field of information security, with at least three years in the role of information security manager.

Exam
Certified Information Security Manager (CISM) (200 questions, 4 hours, 450 as the passing mark for the exams required)

Approximate Cost for Exam
Applicant can register for an ISACA exam via online registration or a hard copy registration form. Note: There is an additional $50 USD processing fee for applying for certification. Cost of online registrations: $490 USD (for ISACA members) and $675 USD (for Non-ISACA members).

URL
http://www.isaca.org/certification/cism-certified-information-security-manager/pages/default.aspx

Available Courses
ISACA offers CISM Review courses for various regions.

Self-Study Material
CISM exam preparation, including prep resources, certification job practice, terminology, a glossary, study material and review courses in required area.

Online Practice Tests
CISM Self-Assessment Exam

Image Source: ISACA

 

 

The CISA certification is a globally recognized certification for IS audit control, assurance and security professionals. With this certification, candidates can showcase their audit experience, skills and knowledge, and demonstrate the capability to assess vulnerabilities, report on compliance and institute controls within their enterprise.

Prerequisites
Candidates must have five years of work experience in the fields of Information Systems Auditing, Control, Assurance or Security.

Exam
Certified Information Systems Auditor (CISA) (200 questions, 4 hours, 450 as the passing mark for the exams required)

Approximate Cost for Exam
Applicant can register for an ISACA exam online registration with

URL
http://www.isaca.org/Certification/CISA-Certified-Information-Systems-Auditor/Pages/default.aspx

Available Courses
http://www.isaca.org/Certification/CISA-Certified-Information-Systems-Auditor/Prepare-for-the-Exam/Review-Courses/Pages/default.aspx.ISACA offers CISA Review courses for various regions.

URL Self-Study Material
CISA exam preparation, including prep resources, certification job practice, terminology, a glossary, study material and review courses in required area.

Online Practice Tests
CISA Self-Assessment Exam

Image Source: ISACA

 

EC-Council is a member-based organization that certifies individuals in various e-business and information security skills. Here is a list of all the certifications that EC-Council provides: Certified Ethical Hacker (CEH); Computer Hacking Forensic Investigator (CHFI); EC-Council Certified Security Analyst (ECSA); Licensed Penetration Tester (LPT); EC-Council Network Security Administrator (ENSA); EC-Council Certified Incident Handler (ECIH); EC-Council Certified Security Specialist (ECSP); EC-council Certified Disaster Recovery Professional (EDRP); Chief Information Security Officer (CISO); Certified Secure Computer User (CSCU); Certified Ethical Hacker (CEH) is the most common and widely used certification.

Description
CEHv8 is a comprehensive Ethical Hacking and Information Systems Security Auditing program, suitable for candidates who want to acquaint themselves with the latest security threats, advanced attack vectors, and practical real time demonstrations of the latest hacking techniques, methodologies, tools, tricks, and security measures.

Prerequisites
Candidates must attend official training or have at least two years of information security related experience.

Exam
Certified Ethical Hacker (CEH) Exam 312-50 (125 questions, 4 hours, 70% passing score)

Approximate Cost for Exam
The version 8 exam costs $500 USD for the actual test and $100 USD as a nonrefundable fee for registration, administered by Prometric Prime/ Prometric APTC/VUE.

URL
http://www.eccouncil.org/Certification/certified-ethical-hacker

Available Courses
CEH Courseware– US Market Only ($825 USD): course outline, exam.

Self-Study Material
iLearn (Self-Paced $664 USD), Live, Online, Instructor-led ($2,895 USD)

Online Practice Tests
Online Practice Tests

Image Source: EC-Council

EC-Council Certified Security Analyst (ECSA) is an advanced ethical hacking certification and a step ahead of a CEH. This certification helps analysts validate the analytical phase of ethical hacking by being able to analyze the outcome of hacking tools and technologies. By making use of innovational network penetration testing methods and techniques, an ECSA can perform the intensive assessments required to effectively identify and mitigate risks to the information security of the infrastructure. The ECSA certification is designed for candidates who are Network Server Administrators, Firewall Administrators, Information Security Testers, System Administrators and Risk Assessment Professionals.

Prerequisites
Candidates must attend official training or have at least two years of information security related experience.

Exam
ECSA v8 (150 questions, 4 hours, 70% passing score)

Approximate Cost for Exam
The version 8 exam costs $500 USD for the actual test and $100 USD as a nonrefundable fee for registration, administered by Prometric Prime/ Prometric APTC/VUE.

URL
https://cert.eccouncil.org/ec-council-certified-security-analyst.html

Available Courses
ECSA/LPT v8 Courseware + iLabs – US Market Only ($700 USD). Course outline

Self-Study Material
iLearn (Self-Paced $559.65 USD), Live, Online, Instructor-led ($2,889 USD)

Online Practice Tests http://www.eccouncil.org/Training/ecsa-assessment

Image Source: EC-Council

 

CompTIA is the leading provider of vendor-neutral IT certifications, offering 16 certification exams in PC support, networking, servers, Linux, security, cloud, mobile and more. CompTIA provides certification series that test various knowledge standards, from entry-level to expert. For security specifically, CompTIA offers the CompTIA Security+ certification.

Prerequisites
Candidates must have a minimum of two years of experience in IT administration with a focus on security. Network+ certification is recommended before taking the Security+ exam.

Exam
SY0-401 CompTIA Security+ certification (90 questions, 90 minutes)

Approximate Cost for Exam
$302 USD

URL
http://certification.comptia.org/getCertified/certifications/security.aspx

Available Courses
To see what the exam covers, fill out this form.

Self-Study Material
Online learning tool, classroom training, study material, e-learning

Online Practice Tests
Click here.

Image Source: CompTIA

CWNP is a non-profit organization that sets the IT industry standard for vendor-neutral enterprise Wi-Fi certification and training. Currently, CWNP focuses on 802.11 wireless networking technologies and offers 6 levels (Entry to Expert levels) of career certification for Enterprise Wi-Fi in areas including fundamentals, administration, security, analysis, design, mastery and instruction.

The CWSP certification is a professional level wireless LAN certification that ensures candidates have the skills to successfully secure enterprise Wi-Fi networks from hackers, without dependency on the brand of Wi-Fi gear deployed in the organization.

Prerequisites
Applicant must hold a current and valid Certified Wireless Network Administrator (CWNA) credential.

Exam
CWSP-205 exam administered by Pearson VUE (60 questions, 90 minutes, 70% passing score, 80% passing score for instructors)

Approximate Cost for Exam
$225 USD

URL
https://www.cwnp.com/certifications/cwsp

Available Courses
None

Self-Study Material
CWNP offers self-study products for CWNP certification exams including books, practice tests, and kits.

Online Practice Tests
CWSP practice test questions

Image Source: CWNP

[DarkReading]

English
Exit mobile version