{"id":4875,"date":"2018-04-12T14:31:27","date_gmt":"2018-04-12T14:31:27","guid":{"rendered":"http:\/\/devsec.smham2.org\/?page_id=4875"},"modified":"2018-09-13T16:55:04","modified_gmt":"2018-09-13T16:55:04","slug":"so-you-want-to-enter-into-information-security","status":"publish","type":"page","link":"https:\/\/devsec.smham2.org\/?page_id=4875","title":{"rendered":"So you want to enter into Information Security"},"content":{"rendered":"<p>I have seen the following question come up in mailing list that I am on: How can I get started in Information Security?<\/p>\n<p>This is a very valid question since there are many people interested in Information Security, but do not have any idea on how to enter into it.\u00a0 This post is designed to help answer that question and help you determine if you have what is needed now to enter into the field.\u00a0 The way I answer that is by looking into my background and how I entered into the field and what I have done to stay current and relevant.<\/p>\n<p>First, look at <a href=\"http:\/\/devsec.smham2.org\/?page_id=14\">my bio<\/a>. You will notice that I had some ups and downs in my career. I was a computer\/desktop technician and had system administration skills but went &#8220;down&#8221; to help desk technician. That was actually a good move on my part.\u00a0 I was at a job that had no forward\/upward mobility.\u00a0 There was a senior person on the team, but we started at the same time and he had no plans to leave (as of this post, he&#8217;s still there).\u00a0 Therefore, I was not moving into his position.\u00a0 We had an in-house programmer, but it was same situation.\u00a0 It was during my time as a computer technician that I got interested in Information Security.\u00a0 We had a firewall installation that I was interesting in learning. I studied the firewall configuration (Checkpoint) and even passed the <a href=\"http:\/\/store.checkpoint.com\/training-certification\/#\/\">CCSA<\/a> (that has since expired).\u00a0 However, I got some negative feedback from a co-worker.\u00a0 Basically he said that you cannot make the jump into Information Security. All of those combined reasons is why I made the downward move to help desk technician.\u00a0 However, the takeaway up to this part is (1) don&#8217;t think that if you are in a certain position you cannot move into Information Security and (2) sometimes you have to move down to move up.<\/p>\n<p>It was while I was a help desk technician that I eventually entered the Information Security field.\u00a0 The current Information Security administrator took a position at another company.\u00a0 I really wanted to learn this and enter into this position, so I spoke with the IT director.\u00a0 That is point number 3, if you are already in a company and know that a position is opening up in Information Security (or any position you are interested in), talk with the manager\/director in charge and express this to them.\u00a0 They may not know anyone internally is interested.\u00a0 They may also put more effort in training you since you know the inner workings of the company verses someone coming in from outside.\u00a0 I became the Information Security administrator in a dual role &#8211; I should note the outgoing Information Security administrator was in a dual role as well.\u00a0 I received training from the outgoing administrator and got <a href=\"https:\/\/www.sans.org\">SANS training<\/a> by doing self-study.\u00a0 Within my first year, I got my <a href=\"https:\/\/www.giac.org\">GIAC<\/a> in <a href=\"https:\/\/www.giac.org\/certification\/security-essentials-gsec\">GSEC<\/a> and learned a lot in that position.\u00a0 Point number 4 is be willing to learn. This is a fundamental point in Information Technology, but needs to be reiterated with Information Security &#8211; be willing to learn new things.<\/p>\n<p>I learned new things in each of the Information Security positions I took.\u00a0 I have SOC (Security Operations Center) experience specifically reading packets and identifying threats, skills that I still use today.\u00a0 I have experience with firewalls, IDS\/IPS (Intrusion Detection\/Prevention System), patch management, incident response, and end-user management.\u00a0 The interesting part of the experience I have relating to Information Security is that some of it is not specific to Information Security and some of it I learned or did while not specifically in an Information Security role.\u00a0 I did patch management and end-user management as a Linux Administrator.\u00a0 I also did this as a desktop technician.\u00a0 You could say I did disaster recovery\/business continuity work when I was computer operator backing up the IBM AS400, but I really did this work as a Linux Administrator.\u00a0 That is point 5; some of the work that you are doing now is preparing you for the Information Security field.\u00a0 Some would say that the best Information Security professionals were those who did systems\/network administration work.\u00a0 They know the systems and networks.\u00a0 Depending on the role, they have the information security foundation.<\/p>\n<p>One thing that helped me in my information security role is going to conferences and training.\u00a0 Some conferences are better than others; some have some insightful material and others are a glorified sales pitch.\u00a0 If you are paying your way, pick free or low cost conferences but skip expo badges.\u00a0 There is nothing meaningful with expo badges (IMO) unless you are looking for freebies from companies that will call you to no end.\u00a0 Think about joining different organizations.\u00a0 I have joined <a href=\"https:\/\/www.isaca.org\/pages\/default.aspx\">ISACA<\/a> and <a href=\"https:\/\/www.issa.org\">ISSA<\/a>.\u00a0 Some of these organizations have discounts for attending conferences, so this is a way to attend cheaply.\u00a0 They also have chapter meetings that are beneficial for learning and networking.\u00a0 There may be controversy with the following statement, but certificates can help especially for higher-level positions.\u00a0 I have <a href=\"https:\/\/www.giac.org\/certification\/security-essentials-gsec\">GIAC GSEC<\/a> that was employer paid.\u00a0 <a href=\"https:\/\/www.giac.org\/certification\/information-security-professional-gisp\">GIAC GISP<\/a> was self-paid but led to <a href=\"https:\/\/www.isc2.org\/Certifications\/CISSP\">CISSP<\/a>.\u00a0 <a href=\"https:\/\/www.giac.org\/certification\/critical-controls-certification-gccc\">GIAC GCCC<\/a> was self-paid as well and will probably be the last self-paid for a SANS training course (good courses, but expensive).\u00a0 However look at what you want to do and see what is available.\u00a0 If you want to be a penetration tester, check out <a href=\"https:\/\/www.offensive-security.com\/information-security-certifications\/oscp-offensive-security-certified-professional\/\">OSCP<\/a>. If you want to eventually manage or know the business side of information security, check out <a href=\"https:\/\/www.isc2.org\/Certifications\/CISSP\">CISSP<\/a> or <a href=\"http:\/\/www.isaca.org\/Certification\/CISM-Certified-Information-Security-Manager\/Pages\/default.aspx\">CISM<\/a>.\u00a0 If you want to be an IT auditor, check out <a href=\"http:\/\/www.isaca.org\/Certification\/CISA-Certified-Information-Systems-Auditor\/Pages\/default.aspx\">CISA<\/a>.\u00a0 If you want in-depth, hands on information security skills, check out SANS and specifically <a href=\"https:\/\/www.sans.org\/work-study\/\">SANS work-study<\/a> (I did this and it was a valuable experience).<\/p>\n<p>This was probably a long post that deviated from the purpose a few times, but I hope you got some valuable information from it.\u00a0 If anything, take away the following points from this post:<\/p>\n<ol>\n<li>Don&#8217;t think that you cannot move into an information security position if you are in a certain position. Desktop technicians and help desk technicians have become information security professionals.<\/li>\n<li>Depending on your position and the company, think about moving down in order to move up. Take a position that might be a level below you if it means that you might get to position a few levels higher than where you are now.<\/li>\n<li>Keep an eye out for openings in your current company and do not be afraid to express your interest to the manager or director over a certain position. Some would rather hire from within, than get someone outside and get him or her up to speed.<\/li>\n<li>Be willing to learn &#8211; go to conferences, join information technology\/information security organizations, attend chapter meetings, get certified, and keep learning.<\/li>\n<li>Don&#8217;t underestimate the work and experience you are doing now. You might be doing information security work in your everyday job as a desktop technician, systems or network administrator. Those skills will be valuable as you move into information security.<\/li>\n<\/ol>\n<p>I hope this help answer the question.\u00a0 I will also post some valuable tools and sites that can help you along your path.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I have seen the following question come up in mailing list that I am on: How can I get started in Information Security? This is a very valid question since there are many people interested in Information Security, but do not have any idea on how to enter into it.\u00a0 This post is designed to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-4875","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/pages\/4875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4875"}],"version-history":[{"count":3,"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/pages\/4875\/revisions"}],"predecessor-version":[{"id":6923,"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/pages\/4875\/revisions\/6923"}],"wp:attachment":[{"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}