- 对本书的赞誉
- 序一
- 序二
- 序三
- 前言
- 第一部分 安全架构
- 第 1 章 企业信息安全建设简介
- 第 2 章 金融行业的信息安全
- 第 3 章 安全规划
- 第 4 章 内控合规管理
- 第 5 章 安全团队建设
- 第 6 章 安全培训
- 第 7 章 外包安全管理
- 第 8 章 安全考核
- 第 9 章 安全认证
- 第 10 章 安全预算、总结与汇报
- 第二部分 安全技术实战
- 第 11 章 互联网应用安全
- 第 12 章 移动应用安全
- 第 13 章 企业内网安全
- 第 14 章 数据安全
- 第 15 章 业务安全
- 第 16 章 邮件安全
- 第 17 章 活动目录安全
- 第 18 章 安全热点解决方案
- 第 19 章 安全检测
- 第 20 章 安全运营
- 第 21 章 安全运营中心
- 第 22 章 安全资产管理和矩阵式监控
- 第 23 章 应急响应
- 第 24 章 安全趋势和安全从业者的未来
- 附录
9.2 认证概述
9.2.1 认证分类
安全认证分成以下六类,第三、四、六类我们平常接触较多,最近几年第一、二类认证也逐步开始多起来,第五类参与的人比较少。
第一类:Hacking&Pen Testing certifications
主要是与渗透测试有关的认证,包括:
·Mile2 CPTC-Certified Penetration Testing Consultant
·Mile2 CPTE-Certified Penetration Testing Engineer
·CompTIA Security+(Introduction/Beginner)
·ISACA CSX CYBERSECURITY FUNDAMENTALS CERTIFICATE(Introduction/Beginner)
·ISACA CSX PRACTITIONER
·7Safe CSTA-Certified Security Testing Associate(British CEH)
·GIAC/SANS GIAC Penetration Tester(GPEN)
·Offensive Security Certified Professional–OSCP
·Offensive Security Wireless Professional–OSWP
·Offensive Security Certified Expert–OSCE
·Offensive Security Exploitation Expert–OSEE
·EC-Council CEH-Certified Ethical Hacker
·EC-Council ECSA-EC-Council Certified Security Analyst
·IACRB Certified Expert Penetration Tester(CEPT)
·IACRB Certified Penetration Tester(CPT)
·ISFCE Certified Computer Examiner(CCE)
·Logical Operations CyberSec First Responder(CFR)
第二类:Computer Forensics certifications
主要是与计算机取证有关的认证,包括:
·Mile2 CDFE-Certified Digital Forensics Examiner
·Mile2 CNFE-Certified Network Forensics Examiner
·GIAC/SANS GCFA:GIAC Certified Forensic Analyst
·GIAC/SANS GCFE:GIAC Certified Forensic Examiner
·GIAC/SANS GREM:GIAC Reverse Engineering Malware
·GIAC/SANS GNFA:GIAC Network Forensic Analyst
·GIAC/SANS GASF:GIAC Advanced Smartphone Forensics
·ISC2 CCFP-Certified Cyber Forensics Professional
·EC-Council CHFI-Computer Hacking Forensic Investigator
·EnCe:EnCase Certified Examiner.
·IACIS Certified Forensic Computer Examiner(CFCE)
·CyberSecurity Forensic Analyst CSFA
第三类:Management/Others certifications
主要是与信息安全管理有关的认证,包括:
·Mile2 CISSO-Certified Information Systems Security Officer
·Mile2 CIHE-Certified Incident Handling Engineer
·Mile2 CHISSP-Certified Healthcare IS Security Practitioner
·CompTIA CASP CompTIA Advanced Security Practitioner
·GIAC/SANS GSLC:GIAC Security Leadership
·GIAC/SANS GISP:GIAC Information Security Professional
·GIAC/SANS GCPM:GIAC Certified Project Manager
·GIAC/SANS GCIH:GIAC Certified Incident Handler
·ISC2 SSCP-Systems Security Certified Practitioner
·ISC2 CISSP-Certified Information Systems Security Professional
·ISC2 CCSP-Certified Cloud Security Professional
·ISC2 CSSLP-Certified Secure Software Lifecycle Professional
·ISC2 HCISPP-HealthCare Information Security and Privacy Practitioner
·EC-Council CCISO-Certified Cheif Information security Officer
·IACRB Certified SCADA Security Architect(CSSA)
·ISACA Certified in Risk and Information Systems Control TM (CRISC TM )
·ISACA Certified Information Security Manager ® (CISM ® )
·ISACA Certified in the Governance of Enterprise IT ® (CGEIT ® )
第四类:Auditing Certifications
主要是与信息安全审计有关的认证,包括:
·Mile2 CISMS-LA-Information Security Management Systems Lead Auditor
·Mile2 CISMS-LI-Information Security Management Systems Lead Implementer
·GIAC/SANS GSNA:GIAC Systems and Network Auditor
·ISACA Certified Information Systems Auditor(CISA)
第五类:Web Applications Security certifications
主要是与 Web 安全有关的认证,包括:
·Mile2 CSWAE-Certified Secure Web Application Engineer
·Offensive Security Web Expert-OSWE
·GIAC/SANS GWEB:GIAC Certified Web Application Defender
第六类:Vendor's certifications
主要是思科、CheckPoint、Juniper 等厂商推出的认证,包括:
·Cisco CCNA Cyber Ops
·Cisco CCNA Security
·Cisco CCNP Security
·Cisco CCIE Security
·Fortinet Network Security Expert(NSE)1 to 8
·Check Point Certified Security Administrator(CCSA)
·Palo Alto Accredited Configuration Engineer(ACE)
·Palo Alto Networks Certified Network Security Engineer(PCNSE)
·Symantec Certified Specialist(SCS)
·Blue Coat X-Series Certified Specialist(BCXCS)
·Blue Coat X-Series Certified Expert(BCXCE)
·Juniper Networks Certified Specialist Security(JNCIS-SEC)
·Juniper Networks Certified Professional Security(JNCIP-SEC)
·Juniper Networks Certified Expert Security(JNCIE-SEC)
9.2.2 认证机构
认证机构主要包括:(ISC)2、CompTIA、Offensive Security、ISACA、GIAC、Mile2、EC-Council 等,认证机构和其推出的认证如表 9-1 所示。
表 9-1 认证机构及其推出的认证
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论