Top IT Security Certifications: CISSP, CEH, and More
This paper surveys the most widely recognized information technology security certifications, drawing on sources such as Dice, CompTIA, Cisco, ISC², EC-Council, and GIAC. It examines entry-level credentials like CompTIA Security+ and GIAC GSEC alongside advanced designations such as CISSP, Certified Ethical Hacker (CEH), and the Cisco Certified Architect (CCAr). For each certification, the paper discusses prerequisites, exam structure, knowledge domains, and the job roles they support. The analysis concludes that IT security is a field requiring progressive, experience-backed credentialing rather than shortcut credentialing, and that professional dedication is essential for success in this demanding discipline.
- Introduction: Security breaches motivate IT certification overview
- Overview of Major IT Security Certifications: Dice top-six certifications briefly introduced
- Advanced and Vendor-Specific Certifications: CISSP, Cisco, Microsoft, and Red Hat examined
- Entry-Level and Ethical Hacking Certifications: Security+, CEH, and GIAC GSEC requirements
- Analysis and Implications: Experience-first career path and professional ethics
- Conclusion: Dedication and progressive learning are essential
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- Systematically surveys a broad range of certifications from entry-level to elite, giving readers a clear sense of the credentialing landscape.
- Uses concrete details—exam question counts, passing scores, required experience, and relevant job titles—to ground each certification in practical reality.
- The analysis section moves beyond description to argue a coherent point: IT security is a field that demands progressive, experience-backed development rather than credential-first shortcuts.
Key academic technique demonstrated
The paper demonstrates effective comparative synthesis: it presents multiple certifications from different vendors and independent bodies, then draws cross-cutting conclusions about prerequisites, career pathways, and professional ethics. Rather than treating each certification in isolation, the author identifies patterns (experience-before-certification, hierarchical credential structures) that apply across the entire field.
Structure breakdown
The paper opens with a rationale grounded in high-profile security breaches, then moves into a descriptive survey of top-tier and entry-level certifications (organized roughly from advanced to accessible). An analysis section interprets what the survey reveals about the profession as a whole. A brief conclusion reinforces the paper's normative claim—that genuine dedication, not superficial credentialing, is the foundation of competent IT security practice.
Introduction
As made clear by the Target and Home Depot retail data breaches, information security is critically important and can affect millions of people at once when it is not handled correctly. Given that reality, information technology certifications are widely seen as a way to establish whether someone truly possesses the knowledge required for information technology security protocols and standards. This view is held by many because of the third-party nature and comprehensiveness of most certification exams. While a degree of simple memorization is involved and the process is not perfect, knowing the "what" is at least a prerequisite for knowing the "why" and "how," and most people cannot fake their way into an information security job.
What follows is a survey of the most popular information technology security certifications, as defined by the IT job listing service Dice and the websites of several industry heavyweights that sponsor IT certifications. While certifications are not a cure-all for finding qualified and experienced talent, they are certainly a valuable tool in the hiring toolbox.
Overview of Major IT Security Certifications
Dice defines the top information technology certifications as the Amazon Web Services Solutions Architect, Cisco Certified Architect, EC-Council Computer Hacking Forensic Investigator, Microsoft Certified Solutions Expert, Red Hat Certified Architect, and VMware Certified Professional 5. These certifications span the largest online retail infrastructure (Amazon), the largest networking infrastructure provider (Cisco), a certification focused on forensic hacking investigation (EC-Council), the two most prevalent operating system environments (Linux/Red Hat and Microsoft Windows), and VMware, which represents the increasingly pervasive practice of running computers and software remotely rather than building fully local workstations (Dice, 2015).
One notable characteristic of at least some of these certifications is that candidates must accumulate real-world experience before they are eligible to sit for the exam, rather than obtaining the credential first and then seeking work. For example, the Amazon Web Services Solutions Architect certification involves knowledge of building web service infrastructures for Amazon and requires approximately one year of hands-on experience before a candidate should seriously attempt the exam (Dice, 2014).
Advanced and Vendor-Specific Certifications
The Cisco Certified Architect (CCAr) is even more demanding in this regard. The CCAr sits at the very top of Cisco's certification hierarchy. The CCENT and CCT represent entry-level credentials, while the CCDP, CCNP, and CCIE occupy the mid-range; the CCAr is reserved for the most senior professionals in the field (Cisco, 2015). Microsoft's certification offerings are organized around specific software products and infrastructure roles, including private cloud, SharePoint, and Microsoft server environments. The Red Hat Certified Architect credential is similarly positioned at the pinnacle of Red Hat's certification structure, not as an entry point. The VMware Certified Professional certification covers a comparatively focused body of knowledge but is by no means easy or quick to achieve (Dice, 2014).
In terms of certifications that are widely considered the most prestigious and difficult to obtain, the standout non-vendor-specific credential is the CISSP (Certified Information Systems Security Professional). Job titles typically held by CISSP holders include Security Consultant, Security Manager, IT Director, IT Manager, Security Auditor, Security Architect, Security Analyst, Security Systems Engineer, Chief Information Security Officer, Director of Security, and Network Architect. The certification is comprehensive, spanning ten distinct domains of information security: access control; telecommunications and network security; information security governance and risk management; software development security; cryptography; security architecture and design; operations security; business continuity and disaster recovery; legal, regulations, compliance, and investigations; and physical and environmental security (ISC², 2015).
This is not a certification that any novice IT professional can simply step into. However, more nascent professionals can begin with the Associate of ISC² designation, which is designed as a pathway toward certifications such as the CAP, CCFP, CISSP, CSSLP, HCISPP, and SSCP. The CISSP also offers advanced subclasses known as concentrations, covering architecture, engineering, and management (ISC², 2015).
Conclusion
Information technology security is one of those fields where not knowing one's job is, by its very definition, unethical and improper. It takes time to develop expertise, and there are many topics and subtopics that must be mastered for each certification level. Certain knowledge areas—such as wireless protocols and encryption—are foundational and should be understood by all IT security professionals regardless of specialization. Nevertheless, those who are willing and able to invest the necessary effort can be well compensated and can build highly rewarding careers in the field.
References
Cisco. (2015, January 18). Certifications – IT certification and career paths. Retrieved January 18, 2015, from http://www.cisco.com/web/learning/certifications/index.html
CompTIA. (2015, January 18). CompTIA Security+. Retrieved January 18, 2015, from http://certification.comptia.org/getCertified/certifications/security.aspx
Dice. (2014, September 8). 6 essential IT certifications for 2015. Retrieved January 18, 2015, from http://news.dice.com/2014/09/08/6-essential-it-certifications-for-2015/
EC-Council. (2015, January 18). Certified Ethical Hacker. Retrieved January 18, 2015, from https://www.eccouncil.org/Certification/certified-ethical-hacker
GIAC. (2015, January 18). Security certification: GSEC. Retrieved January 18, 2015, from http://www.giac.org/certification/security-essentials-gsec
ISC². (2015, January 18). CISSP. Retrieved January 18, 2015, from https://www.isc2.org/cissp/default.aspx
Create your account
Always verify citation format against your institution’s current style guide requirements.