US Army: Military finds IT security certification difficulties
Network World - The U.S. Army is having a hard time manning its IT staff because it cannot find military personnel with the right networking and IT security qualifications.
The Department of Defense (DOD) Directive 8570.01-M is a military regulation first published in 2005 that puts forward considerable detail on the workplace and related training and certifications that military personnel -- and now contractors as well -- must have to operate DOD-related information systems for information assurance purposes. But the problem for the Army at this point is that it doesn't have enough personnel with the required training, said Lisa Lee, information assurance program manager, Program Executive Office, Enterprise Information Systems in the U.S. Army.
STUPID TECH SUPPORT TRICKS: IT calls of shame
To cope with the shortage of certified personnel, the Army is altering its guidelines so that not as many individuals working in areas it calls "an enclave boundary" -- defined as a specific set of routers and firewalls -- will have to meet the previous requirements, said Lee, who spoke on the topic on behalf of the Army at the recent FOSE Conference in Washington, D.C.
With that change, the individuals who have the higher security credentials the military wants will be granted higher network administrative privileges and those at a lower certification level will have less, and likely make less money, she noted. "I was forced to do it," she said. "We have some good people having trouble passing the tests. They're just not good test takers."
The alphabet-soup of security certifications, many of them well-known to the private sector, include specific sets of requirements oriented toward various designated security levels and network and operating environment, as listed on the Defense Information Systems Agency website www.disa.mil. The certifications include A+CE, Network+CE, SSCP, GSEC, CISA, GSE, CISSP, GSLC and several more.
The Army pays for a lot of baseline training and certification for personnel through vouchers, but the problem now is that "the vouchers run out" and the Army is on the lookout for "as much free stuff" as it can get, Lee said. Contractors are responsible for paying for their own training, she said. And for some types of certifications, Army personnel have to shell out on their own, she added.
Lee also noted that if someone is a "valued employee, they'll put you in another job" if you fail to get specified certification. She said she's seen people with IT security certifications who weren't as good in their jobs as those who weren't similarly certified.
Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security.
Read more about wide area network in Network World's Wide Area Network section.
- 18 Hot IT Certifications for 2014
- CIOs Opting for IT Contractors Over Hiring Full-Time Staff
- 12 Best Free iOS 7 Holiday Shopping Apps
- For CMOs Big Data Can Lead to Big Profits
- Slideshow: 5 ways to lock down your mobile device
- Slideshow: 10 mistakes companies make after a data breach
- How to rob a bank: A social engineering walk through
- Which smartphone is the most secure?
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Mitigating DDoS Attacks with F5 Technology
- This document examines various DDoS attack methods and the application of specific ADC technologies to block attacks in the DDoS threat spectrum while...
- The DDoS Threat Spectrum
- Bolstered by favorable economics, today's global botnets are using distributed denial-of-service (DDoS) attacks to target firewalls, web services, and applications, often simultaneously.
- Defending Against Denial of Service Attacks
- By utilizing end-user interviews, this whitepaper explores a deeper understanding of DDoS defense plans and reveals the knowledge gaps around the Denial of...
- Strategic Solutions for Government IT
- This paper outlines why F5 is the optimum partner to help achieve the levels of security, performance and availability that are vital to...
- Leveraging Managed Security Services to Fight Growing Cybersecurity Threats
- IT Infrastructure-as-a-Service enables agile responses to constantly changing threats. All Government IT White Papers
- Modernizing SAP environments with minimum risk - a path to Big Data Hear from top IDC analyst, Richard Villars, about the path you can start taking now to enable your organization to get the benefits...
- The Power of the Citrix Mobility Solution, XenMobile Does everything become a smartphone? Or does the smartphone begin to do everything? How can we afford to support BYOD? Rather, how can...
- BYOD Happens: How to Secure Mobility How to navigate the journey of securing mobility, including the BYOD corruption of IT, the top ten mobility strategies, and the mobility management...
- HR and Finance Were made for Each Other View now >>
- The Value of Human Capital for Finance Professionals View now >>
- All Government IT Webcasts
Does your organization offer extensive benefits, cool perks, competitive salaries, opportunities for training and advancement? Then get it recognized!
Nominate your company or another deserving organization for Computerworld's 2014 Best Places to Work in IT list now through Dec. 12, 2013.