Five Ways CompTIA Certifications Have a Positive Impact on You and Your Career

Earning certifications to prove your knowledge and skills is the norm in the IT landscape, and that doesn’t look to be changing anytime soon. Still, often it requires time and money to earn those certifications. Exactly what difference do they make?

Well the results are in. The CompTIA 2016 IT Career Insights study asked current certification holders about their experiences post-certification, and shows that CompTIA certifications make a world of difference, both for career and self-growth. Check out five ways they do so.

Personal Satisfaction / Confidence

According to the 2016 IT Career Insights Study, the number one area impacted by earning a CompTIA certification is personal satisfaction. It may not be the first thing that comes to mind in helping find a job, but you’d be surprised! Those who have confidence in their skills and abilities are more likely to come across as effusive and competent, whether it’s socializing at job fairs or listing accomplishments during an interview. Having a healthy level of self-confidence is essential to landing, and keeping, the job you want.

Professional Development

Following a career path means you need the room and training opportunities to grow your profession. It’s all about tackling more responsibilities, upward mobility and the potential for a larger salary. CompTIA certification holders picked professional development as the second most important area their certifications helped. With no limit as to how many CompTIA certifications you can earn, the certifications’ different areas of expertise are perfect for long-term professional growth.

Career Satisfaction

We all know the importance of holding down a job, but you should also keep your future career path in mind. CompTIA certifications can help with both short- and long-term career goals! For now, a certification can increase the likelihood of landing a job. In the future, the number of different CompTIA certifications, and their different areas of focus, represent a series of solid career building opportunities that are there whenever you are ready.

Job Attainment

Anyone who has been job hunting knows it’s difficult to stand out from other applicants — especially when you and the other applicants all have similar skill-sets. Adding a CompTIA certification to your LinkedIn profile and resume goes a long way. It’s a great way to prove your skill-set and help your resume avoid the rejected pile! Most importantly, it verifies your knowledge and proves to potential employers that you’re motivated in maintaining and developing your skills.

The Right Job

Feeling motivated and eager to work every morning is a vital part of a satisfying job. But it can be hard to find a balance between easily managed tasks and tackling those that challenge you to grow your skills. Earning different CompTIA certifications can help find that sweet spot, thanks to the designated skills and knowledge they focus on. It can help employers, and you, find the right job level according to what certs, and thus what skills, you already have.

The categories above represent the international findings of the CompTIA 2016 IT Career Insights Study. If looking only at the U.S., the findings differ slightly, with job satisfaction ranking higher than career satisfaction. That job satisfaction ranks higher in the U.S. does not come as a total surprise – it’s tougher to find a job in the first place, as the U.S. has been experiencing high numbers of unemployment, nearly 10 percent in April 2009, since the 2008 economic recession. Overall though, the categories of highest importance remain consistent to both domestic and international CompTIA certificate holders.

Are you curious to experience what kind of a difference a CompTIA certification could make for you? Check out our certifications and find one or more that could be right for you.

[CompTIA IT Career News]

ISACA Now Chats with EuroCACS 2016 Keynote Speaker Mark Stevenson

ISACA Now recently spoke with Mark Stevenson, the closing keynote address for EuroCACS in Dublin 30 May-June 1 2016. Stevenson is the founder of We Do Things Differently, and the author of An Optimist’s Tour of the Future and the upcoming We Do Things Differently. He is also an advisor to the Virgin Earth Challenge, Atlas of the Future, Comic Relief and Institution of Mechanical Engineers.

ISACA Now:  In Principle 7 of your 8 Principles for Thinking About the Future, you discuss how pragmatic optimists will experience significant rejection and ridicule when starting new endeavors. What practical advice do you have for getting through all that rejection without becoming defeated and cynical?
Stevenson:  By understanding that you will lose more often than you will win until half way through the game—and that’s OK. Persistence (driven by the optimism that a better future is possible) is the secret sauce of success. Cynicism by contrast is just a recipe for laziness dressed up as wisdom. Every great leader you can think of is an optimist. As the saying goes, “The road to success is littered with corpses, but they’re all suicides.” Also remember that that rejection is often a sign you’re on the right track. As the computer scientist Howard Aitken sagely remarked: “Don’t worry about people stealing your ideas. If your ideas are any good, you’ll have to ram them down people’s throats.”

ISACA Now:  For many, cynicism is deeply embedded. How is it possible for those long-term cynics to kick out their cynicism?
Stevenson:  By looking in the mirror and asking themselves if they want to continue being unhappy. Cynicism is obedience. As the author Richard Bach put it, “Shop for security over happiness and you buy it, at that price.” Cynics reinforce the status quo they complain about by refusing to imagine it can be different. But the antidote is doing something bigger than you for which the dividends emotionally (and often financially) are handsome. It’s a choice. Comfortable miserable cynicism, or uncomfortable happy optimism? It’s your life.

ISACA Now:  Your pragmatic optimist’s view of the future should come in handy for cybersecurity professionals as they work to address the avalanche of cybercrimes and criminals. What is your advice for those who may be growing weary of the world’s seeming inability to overcome cybercrime? What historic parallels can you draw from this?
Stevenson:  The question is what are we protecting? One has to ask what the roots of crime are, and they are based in scarcity and distrust. In a world of abundance and transparency, crime and war are far less likely (indeed history teaches us this time and time again). The cybersecurity profession has to ask itself whether it is on the side of people, or Mossack Fonseca (the Panamanian law firm that recently had 11.5 million confidential documents leaked) and its clients. Who are you paymasters and what are their morals? We overcome violence and addiction by being more connected, not less so. We will overcome cybercrime most effectively by working to reduce inequality. So, the question is, what are you doing about that and whose side are you on?

ISACA Now:  You will be speaking at the EuroCACS conference 30 May-1 June 2016 in Dublin. Give us a brief preview of what you’ll discuss and what attendees will take away.
Stevenson:  I’ll be explaining why all bets are off, how the next 30 years will be some of the most turbulent in history and how to navigate that in the service of making the world better for your children.

[ISACA Now Blog]

(ISC)² to Host International Standards Organisation Meeting

Many of you will know that (ISC)² is hosting a major event this month – in downtown Tampa, Florida – and I’m sure that you’ve also heard the phrases ISO and SC27. But what does this all mean?

ISO is the International Standards Organisation, set up in 1947, which oversees the creation, publication and maintenance of standards covering everything from acid-free paper to quality management systems, smart cities to information, and cybersecurity. ISO has committees of experts – drawn from around the world – who volunteer their time and share their knowledge to create and maintain standards. Each committee has a particular subject area or topic it specialises in and JTC1/SC27 (or SC27) is the committee that specialises in information security. Standards help set the bar for organisations by defining good practice and setting targets to be met.

Many cybersecurity professionals have used, or at least are familiar with, ISO standards produced by SC27 (for example, ISO/IEC 27001) and (ISC)²’s CBKs reference standards as part of the knowledge required by a security professional. But we don’t just passively write about ISO standards in our textbooks. (ISC)² is a ‘category A liaison organisation,’ which carries significant influence and allows us to propose new standards, provide comments, draft text for inclusion in standards and suggest changes to existing standards. (ISC)² staff regularly attend ISO meetings and we invite our members to the same meetings; as a result, we actively share knowledge and expertise to ensure these standards reflect good practices. Our contributions help form the basis of these standards; build processes and frameworks using real world experience; and assist with the writing of text to help individuals implement the standards. So our contributions – in person or in written submissions – help form the foundations on which information security can be built. Our work with ISO shows our commitment to a safe and secure cyber world.

The creation and maintenance of new standards follows a set pattern, in which face-to-face meetings are held twice a year. These meetings – such as the one (ISC)² is hosting– bring together experts from around the globe who collaborate, share insights and experience, codify good practices and draft the text that will become part of a new standard, or modify and enhance an existing one. In the time between the face-to-face meetings, experts are invited to comment on the outputs of the meeting and prepare for the next meeting. ISO experts are drawn from industry, academia and from other standards organisations (such as NIST or BSI). ISO experts can also be appointed as ‘editors’ for an international standard. This role is fundamental to the standards process and editors are ultimately responsible for project managing, writing, collaborating and delivering the international standard. Being an editor is a voluntary role and requires tact, diplomacy and the ability to synthesise agreement from varying opinions. An editor also has to be able to write using the, sometimes arcane, language of international standards.

So, what are the meetings like? They can be great fun, insightful, difficult and procedural in turn or at the same time. They are a great forum to learn, share and network as these meetings draw around 400 experts together for a week.

It’s worth remembering that much of the discussions this month will eventually find their way into information security practice, how we deploy information security in our own offices, our members’ work and (ISC)² educational materials. — Dr. Adrian Davis, CISSP, Managing Director, EMEA, (ISC)²

[(ISC)² Blog]

How to Get C-suite Support for Insider Threat Prevention

If you’re not getting support and adequate funding from the C-suite to address insider threats, a recent report highlights a powerful persuasive tool you may have overlooked: money—as in fines (cha-ching), lawsuits (cha-ching) and credit monitoring services (cha-ching) you’ll have to pay as the result of a data breach.

The IDC report, “Endpoint Data Protection for Extensible DLP Strategies,” cites two health-care groups that paid six figures each in fines for data breaches as a result of improper employee behaviors. Here are even more powerful examples of the price your organization could pay for not addressing insider data security threats:

Target insider breach costs could reach $1 billion
Target may have skirted an SEC fine, but the retailer is still paying a hefty price because cyber thieves were able to access customer credit card data via a subcontractor’s systems. Breach costs included $10 million to settle a class action lawsuit, $39 million to financial institutions that had to reimburse customers who lost money, and $67 million to Visa for charges it incurred reissuing compromised cards. For 2014, Target had $191 million in breach costs on its books; estimated totals could reach $1 billion after everything shakes out.

AT&T fined $25 million for employee breach
In 2015, AT&T paid a $25 million fine to the Federal Communications Commission after three call center employees sold information about 68,000 customers to a third party. The cyber thieves used the information to unlock customers’ AT&T phones.

On top of the fine, AT&T was required to do things it should have done in the first place:

  • Appoint a senior compliance manager who is a certified privacy professional.
  • Conduct a privacy risk assessment.
  • Implement an information security program.
  • Create a compliance manual and regularly train employees.
  • File regular compliance reports with the FCC.

AvMed paid $3 million in settlement
While the health plan company avoided a HIPAA fine, it paid $3 million in settlements to 460,000 customers whose personal information was on two stolen, unencrypted laptops. On top of that were costs to reimburse customers’ actual monetary losses.

In addition, the company had to:

  • Provide mandatory security awareness and training programs for all company employees.
  • Provide mandatory training on appropriate laptop use and security.
  • Upgrade all company laptops with additional security mechanisms, including GPS tracking technology.
  • Add new password protocols and full-disk encryption technology on all company desktops and laptops so that electronic data stored on the devices would be encrypted at rest.
  • Upgrade physical security to further safeguard workstations from theft.
  • Review and revise written policies and procedures to enhance information security.

The lesson here should be obvious. It’s far cheaper to act now—by implementing available endpoint protection technology and instituting a security-aware culture—than to wait for a breach that forces you into action.

As security expert Philip Lieberman noted in the AT&T case, the penalty cost AT&T much more than the steps it should have taken to prevent the insider breach: “The C-level staff will have to explain this to the board as to why they did not implement a control when the cost would be trivial.”

To learn more about “Endpoint Data Protection for Extensible DLP Strategies” get the IDC analyst report.

By Susan Richardson, Manager/Content Strategy, Code42

[Cloud Security Alliance Blog]

The Privacy Landscape in 2016

Privacy has made headlines for years now, and the rise of social platforms like Facebook has brought the issue into focus. In 2016, I expect privacy to remain at the forefront of technology news, especially with increasing digitization and technology innovations like Smart Cities, digitized transport and the Internet of Things (IoT). These technologies are generating amounts of data previously unknown. IT analysts International Data Corporation (IDC) state that by 2020 the IoT will account for 10% of all the data generated on Earth.

One of the most impactful changes in recent years, which affects privacy gravely, is the massive increase in data theft. Since 2013 there have been a staggering 3.7 billion records stolen. This heady mix of technology innovation, data generation and sophisticated cyber threats is creating new challenges for the privacy agenda.

Here are the key privacy issues emerging or consolidating in 2016:

Blurred Lines:  Data and the Corporation
The lines between data ownership are blurring. Personal data under the corporation umbrella become a corporate asset, yet they are still owned by the individual, and there can be serious impacts on that individual if the data gets into the wrong hands. And data are valuable to all interested parties, from the original owner, to the corporation that can potentially use or sell those data, to the cybercriminal who can extort money from the data through the black market. The privacy implication of this triad of interests is clearly complex, creating blurred lines of responsibility and ownership.

The way privacy is addressing these complexities in 2016 and beyond involves technology, visibility, laws, regulations and guidelines.

Corporate Obligations and the Privacy Policy 
Obligations are most often set out in a privacy policy. However, the issue of privacy policy creation has been in flux for years, creating confusion amongst the general public. The evolution of the privacy policy has greater importance as data sharing has increased with social platforms. This evolution took off in 2008 when the Patient Privacy Rights (PPR) Trust Framework was developed. The PPR Framework gave a working set of guidelines, which could be applied to privacy policies to create a clear, user-accessible policy.

Since then, platforms such as Facebook and Google have pushed the limits of privacy policy politics to the nth degree, and much debate within the technology and legal communities has ensued. The Federal Trade Commission (FTC) has instigated a number of legal actions against technology platforms, including Google, for misuse of users’ data. These actions have been partly responsible for a more respectful view of user data by the likes of Facebook and Google, who are starting to take heed and create better privacy policies which, at least on paper, make the companies look like they take user privacy seriously.

While the US continues to have no overarching privacy law, relying instead on a mosaic of federal and state laws, the humble privacy policy remains a very important legal document for redressing privacy violations. In 2016, more than any time in history, the privacy policy needs to be a means of privacy respect and control, as it sets corporate obligations and practices. However, privacy policies issues go beyond words on the page. There should be a user-centric approach to privacy policy engagement that ensures the user understands what the policy covers and how their personal data may be used.

Privacy Laws and Regulations
As I said, the US lacks a holistic privacy legal framework. A number of industry specific guidelines and regulations, such as the Health Insurance Portability and Accountability Act (HIPAA), the Children’s Online Privacy Protection Act (COPPA) and the Americans with Disabilities Act (ADA), can be used to develop privacy approaches within a given context, but no single law exists. It will be interesting to see how recent events, such as the Snowden episode and the Apple vs. FBI privacy battle, shape the privacy landscape. The time feels right for a single US privacy law, and the work done in California might be the template. The state of California is setting standards across the board in privacy, including the handling of personal data by online services and online protection of minors.

It looks like 2016 will be the year where at least EU-US communications and privacy will have some positive outcome. The infamous Safe Harbor collapse of last year left EU-US data communications in flux, affecting many companies on both sides of the Atlantic. However, the announcement on 29 February by the European Commission of the EU-US Privacy Shield, which will replace Safe Harbor, is good progress. This agreement sets out the obligations and mechanisms needed to guarantee safety and privacy respecting EU-US data transmissions.

Privacy Challenges Ahead
Visibility of data:  As data generation increases, we need to understand where these data are stored, between whom they are transmitted and the end points being used. Data visibility is one of the keys areas that we need to be aware of to plan for privacy. For example, according to a recent IDC report, around 60% of all data generated by the IoT were duplicate data. Without understanding the data life cycle and where data flow, you can’t begin to truly protect an individual’s personally identifiable information.

The jurisdiction challenge:  The differing approaches to privacy, by jurisdiction within the USA, are a challenge that needs to be met in 2016. Bringing together a common law to manage public expectations is long overdue. The alignment of the planets, such as social media, increased public awareness of privacy, mass data generation and increased cyber threats, is bringing this need to the fore. The US government is taking cyber security threats seriously, with the introduction of the Cyber Intelligence and Protection Sharing Act (CISPA). Perhaps it is time for a similar action to protect privacy across the board.

Desai will speak on Data Privacy at the 2016 North America CACS Conference in New Orleans, 2-4 May.

Avani M. Desai CISSP, CISA, CIA, CIPP, Executive Vice President, Schellman & Company, Inc.

[ISACA Now Blog]

English
Exit mobile version