Network Enhancers - "Delivering Beyond Boundaries" Headline Animator

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, December 4, 2017

New OWASP Top 10 is finally here, injections still dominate


New Open Web Application Security Project 'top-ten risks' list highlights series of common failings, as well as a trio of new risks

The Open Web Application Security Project (OWASP) has revealed an updated ‘top ten’ most urgent application security issues facing organisations, a list that has stood for four years since the last update.
The infamous vulnerability ranking was last updated in 2014, and although not a formal standard has been widely adopted by security professionals and bug bounty platforms.

In spite of the four year hiatus, command injection is still the biggest threat to business applications today, followed by Broken Authentication and Data exposure.



There are three newcomers to the top ten, XML External Entities (XXE), Insecure Deserialization, and Insufficient Logging and Monitoring. The full top ten is here.

XML External Entities (XXE) has been added as a result of data from source code analysis tools, which have created a range of vulnerabilities including internal file or shares disclosure, internal port scanning, remote code execution (RCE) or denial of service (DoS).
Insecure deserialisation is also a new category, which can lead to replay attacks, injection attacks, and privilege escalation.

Finally, Insufficient logging and monitoring has made the list, as it makes it difficult for admins to detect and respond to attacks. The Project analysts pointed out in some situations it can take up to 200 days to detect a breach.

Other areas to watch for the future include architectural changes, according to the analysts, particularly in “single page applications” written with Angular or React, where functionality has been moved from the server side to the client which “brings its own security challenges”. Another new risk area is in microservices, where old code is put behind RESTful or other APIs, but was never designed to be exposed externally: “The base assumptions behind the code, such as trusted callers, are no longer valid”, the report said.

Ilia Kolochenko, CEO, High-Tech Bridge welcomed the new top 10, but also pointed out that the best practice principles of application security development are unchanged: "There are many different best practices to tackle application security at the early stage of software development. First of all, you need to ascertain that your developers are aware of the most recent secure coding techniques, and do properly apply them. Many qualified developers tend to ignore "minor" (in their perception) flaws, such as XSS or XSRF, putting the entire application at risk.”

Others candidly believe that if they have a WAF or RASP, no code security is ever required. Therefore, regular training on new attacking techniques and exploitation vectors are very helpful to highlight the practical side of security.”
Application security starts with secure and clear design of the application and related components. Before starting development, you need to plan how to handle security, reliability, compliance requirements (if any) and data encryption. Otherwise, any substantial corrections at later stages can easily get extremely expensive.
Don't forget to implement continuous security monitoring and testing once the application is deployed to production: what is secure today - can easily become vulnerable tomorrow”, he summarised.

Sunday, August 20, 2017

"C" is the center of Security


After every major breach, there is a wave of information on security technologies which could have prevented it. Conferences have hundreds of companies exhibiting their cool technologies, differentiators and success stories. The research firms publish informative findings, guides, quadrants, waves etc. and most products and solutions are good if implemented and used well. So, in some ways, we have abundance of security controls and technologies. 
We often talk about coming together to fight the bad actors. Industry groups of companies sharing experiences, Government and industry partnerships etc. are examples. These initiatives have been successful to the extent possible considering business and competitive pressures. 
There is a need for collaboration between security vendors to help clients manage risk. Risk managers don’t create a single dimensional posture with dependence on one technology, that goes against the basic principles of risk management. So, naturally the collaboration between security technologies is important.
This collaboration, the “C” in Security, is manifesting itself in three models:
  1. The Security Marketplaces: Large platform players have marketplaces (Splunkbase, IBM AppExchange, Cisco etc.) enabling other security products to publish their “apps”. The idea is clients of the platform's can simply download the apps for desired functionality. 
  2. The Security API’s: Companies have published API’s, enabling relevant integrations with other technologies. These API’s typically provide information & data which can be ingested for enhancements or actions.
  3. The Security Apps: To enhance its functionality and value, companies are creating apps for the marketplaces & integrations to the API's. This provides an excellent platform for niche companies to join the ecosystem, the Digital business of security.
The good news is that these models are not just driven out of the “good to have” need of collaboration, but have the “must have” commercial model and are utilizing the Digital way.
The “C” in Security is here to stay and grow. 


Friday, March 10, 2017

Addressing pain points in governance, risk and compliance (GRC)


In this day and age, it seems as though every business has some form of alphabet soup or acronym salad that shapes the decisions they make as it pertains to their information security programs. Between data privacy laws, regulations on the financial industry, calls for a healthcare focused cybersecurity framework, and regular updates to the PCI DSS, the ever-growing need for a well-established information security program is apparent.

As enterprises exercise their appetite for risk, their ability to assure the board of directors (and inherently the shareholders) that the appropriate controls are in place to protect their critical information and assets is crucial. The days of setting, forgetting, and burying our heads in the proverbial sand are long past. Accountable parties are under ever-increasing pressure to validate the effectiveness of the programs they have in place and provide actionable assurances that due care was taken.

Where is this heading?

We understand the motivations, the want, and the need, yet the reality of the situation doesn’t always align with what we would expect. Cybercrime is not just the elephant in the room; it’s the elephant in the room that’s been tagged with a Banksy-esque portrayal of modern gangsters kicking back and laughing. Criminal organizations are swelling like a tidal wave that is crashing down on the corporate landscape, yet many businesses are still operating under a reactive as opposed to proactive methodology when it comes to their Information Technology/Information Security (IT/IS) GRC needs. Perhaps this is because we have yet to see a nation-wide regulation mandate that controls across multiple business verticals instead of specific industry-related specifications.

Now we combine that reactive approach to traditional spreadsheet-based GRC with understaffed, over-used personnel. Too often these employees are slammed with audits out of nowhere—from business leaders who trickle down high-level policies such as “We’re gonna be ISO certified”—without truly understanding the workloads they just tossed down the org-chart. The elephant grows. How can one or two people in an enterprise tackle the elephant in the room and drag it outside where it belongs?

Give me some hope

It is likely that the challenges and pain derived from GRC activities will continue to grow, which will further motivate market trends that we are already seeing. In the IT/IS GRC market segment, my clients face a lack of time to dedicate towards keeping up with the rapidly changing onslaught of privacy and data security regulations.

As I hinted above, it is good that governments are impressing a need to protect the private information trusted unto businesses by its customers. However, those businesses will continue to be burdened, either through time sink or fines, by this trend.

In addition to the external changes shaping the internal governance policies that businesses put into place, the IT/IS systems within enterprise architectures are in a state of regular flux. It is rare that a system is in a static state for any significant period, and with every change, the same question must be asked: “Is the current machine state compliant?” Answering this question becomes its own burden, without the correct tools in place, and any manual tracking in a spreadsheet becomes impossible at a certain point.

Still waiting for that hope…

Thankfully, we are living in a time where the options available for GRC tools are growing. The market was traditionally dominated by large scale—and expensive—systems. We are now seeing disruptive companies entering and offering reasonable alternatives to the status quo. However, as with any tool selection, there is a fair amount of vendor fatigue that can come from evaluation.

It is best to have a short list of what you want to get out of this investment. When navigating the path of GRC vendor courtship, I advise to check off as many as the following boxes as possible:

Affordability – Ask yourself, “is this affordable?” Not everyone can afford a high-end global enterprise-class implementation, but most organizations will benefit from a tool.

Mitigation, Remediation, and Delegation – Does the tool support tracking of remediation efforts, risk analysis processes, and an ability to seamlessly delegate accountability to system owners for remediation and mitigation of identified risks?

Streamlined Vendor Risk Management – Can this tool help reduce the probability of a Target-like breach by giving you the ability to semi-automate the evaluation of a third-party vendor’s risk profile?

Policy Libraries – Does the tool support dynamic updates of policies within a library to ease the burden of manually tracking changes to governing regulations, standards, and other best practice publications?

Policy Mapping – Can internal policies be easily mapped or overlaid with regulating policies or standards such as HIPAA, COBIT, ISO, etc.?

Views – Can multiple views be established for critical visibility to information that is reasonably valuable for multiple business organizations within your enterprise?

The end goal with the implementation of any tool is to streamline the general day-to-day processes of GRC activities, support collaborative efforts between departments, and offer a central repository for documentation that validates compliance with both internal policies and external regulatory governance. The key part is the collaborative portion. An effective GRC disciple requires a company-wide buy-in. The easier you make it for your colleagues, the easier you make it for yourself. That way, when the time comes to jump into the next audit wave, you can prove once and for all that GRC isn’t just another four-letter word.

Wednesday, March 8, 2017

Six best practices for managing cyber alerts


Security professionals know that the number of cyber alerts is growing at a frantic pace. Even a mid-sized company can face tens of thousands of alerts every month. As the 2011 Target breach demonstrated, failing to investigate alerts adequately and responding to them effectively can have serious consequences for a business as well as its customers.

Ignoring alerts is not an option, so how can busy professionals help their staff members manage the increasing volume without jeopardizing the security of the organization? Here is a list of six best practices that can help.

1. Automate, collaborate and streamline responses

By automating responses to routine issues, security analysts have more time to devote to priority issues that present the most risk to the company. Security analysts are then free to focus on keeping the company secure rather than manually processing tickets, assigning them and tracking progress.

Automating collaboration allows senior staff members to provide additional training to new hires in a relaxed, productive manner. Bottom line: All staff members become more efficient with automation and collaboration.

2. Guard against employee fatigue

Every day, three staff members face 300 or more alerts, according to a study by the industry analyst firm IDC. The study also found that 500 hours per month were spent responding to alarms at more than 35 percent of the respondents’ companies. In short, security professionals are exhausted, giving hackers an unfair advantage.

Hiring more security staff is not always a solution. Instead, a well-organized team focused on priority issues ensures the least amount of burn-out. For smaller companies, partnering with an outside managed security services provider may be the best approach.

3. Harness the power of big data for behavioral analytics

Analytics that detect suspicious activity without assigning priorities are yielding to behavioral analytics that use historical data to determine what is normal for the company.

4. Develop an incident response plan and keep it updated

Be sure to include procedures for handling false positives, duplicates, and assigning alerts to staff members for evaluation and tracking progress. Automation saves significant time in these areas, but the plan should also define the types of incidents to be handled by key personnel.

5. Automate the common analysis of logged activity

An alert may not signify an infection. But, the only way to know if a device is infected is to correlate the alert with additional logged activity and look at other sources of information like threat feeds. By the time the step has been handled manually, the infection could worsen. Automating this step alone could save many hours of work for every alert handled by a staff member.

6. Remember the human factor

Experts estimate that 95 percent of all data breaches can be attributed to human error or recklessness. Ensuring that users are properly trained on security measures may help reduce the number of alerts. However, it’s also crucial that staff members receive proper training that stresses the importance of investigating all alerts. Security experts who feel overworked and unappreciated may develop a belief that they only need to investigate a small part of the alerts to fulfill their obligations.

Hackers will always be on the cutting edge of technology. And attacks will continue to increase across all organizations, both large and small. Therefore, developing an effective strategy for handling alerts will ensure future scalability when dealing with the volume generated.


Tuesday, March 7, 2017

The six stages of a cyber attack lifecycle


The traditional approach to cybersecurity has been to use a prevention-centric strategy focused on blocking attacks. While important, many of today’s advanced and motivated threat actors are circumventing perimeter based defences with creative, stealthy, targeted, and persistent attacks that often go undetected for significant periods of time.

In response to the shortcomings of prevention-centric security strategies, and the challenges of securing an increasingly complex IT environment, organisations should be shifting their resources and focusing towards strategies centred on threat detection and response. Security teams that can reduce their mean time to detect (MTTD) and mean time to respond (MTTR) can decrease their risk of experiencing a high-impact cyber incident or data breach.

Fortunately, high-impact cyber incidents can be avoided if you detect and respond quickly with end-to-end threat management processes. When a hacker targets an environment, a process unfolds from initial intrusion through to eventual data breach, if that threat actor is left undetected. The modern approach to cybersecurity requires a focus on reducing MTTD and MTTR where threats are detected and killed early in their lifecycle, thereby avoiding downstream consequences and costs.

Cyber attack lifecycle steps

The typical steps involved in a breach are:

Phase 1: Reconnaissance – The first stage is identifying potential targets that satisfy the mission of the attackers (e.g. financial gain, targeted access to sensitive information, brand damage). Once they determine what defences are in place, they choose their weapon, whether it’s a zero-day exploit, a spear-phishing campaign, bribing an employee, or some other.

Phase 2: Initial compromise – The initial compromise is usually in the form of hackers bypassing perimeter defences and gaining access to the internal network through a compromised system or user account.

Phase 3: Command & control – The compromised device is then used as a beachhead into an organisation. Typically, this involves the attacker downloading and installing a remote-access Trojan (RAT) so they can establish persistent, long-term, remote access to your environment.

Phase 4: Lateral movement – Once the attacker has an established connection to the internal network, they seek to compromise additional systems and user accounts. Because the attacker is often impersonating an authorised user, evidence of their existence can be hard to see.

Phase 5: Target attainment – At this stage, the attacker typically has multiple remote access entry points and may have compromised hundreds (or even thousands) of internal systems and user accounts. They deeply understand the aspects of the IT environment and are within reach of their target(s).

Phase 6: Exfiltration, corruption, and disruption – The final stage is where cost to businesses rise exponentially if the attack is not defeated. This is when the attacker executes the final aspects of their mission, stealing intellectual property or other sensitive data, corrupting mission-critical systems, and generally disrupting the operations of your business.

The ability to detect and respond to threats early on is the key to protecting a network from large-scale impact. The earlier an attack is detected and mitigated, the less the ultimate cost to the business will be. To reduce the MTTD and MTTR, an end-to-end detection and response process—referred to as Threat Lifecycle Management (TLM) needs to be implemented.

Threat lifecycle management

Threat Lifecycle Management is a series of aligned security operations capabilities and processes that begins with the ability to “see” broadly and deeply across the IT environment, and ends with the ability to quickly mitigate and recover from a security incident.

Before any threat can be detected, evidence of the attack within the IT environment must be visible. Threats target all aspects of the IT infrastructure, so the more you can see, the better you can detect. There are three principle types of data that should have focus, generally in the following priority; security event and alarm data, log and machine data, forensic sensor data.

While security event and alarm data is typically the most valuable source of data for a security team, there can be a challenge in rapidly identifying which events or alarms to focus on. Log data can provide deeper visibility into an IT environment to illustrate who did what, when and where. Once an organisation is effectively collecting their security log data, forensic sensors can provide even deeper and broader visibility.

Once visibility has been established, companies can detect and respond to threats. Discovery of potential threats is accomplished through a blend of search and machine analytics. Discovered threats must be quickly qualified to assess the potential impact to the business and the urgency of response efforts. When an incident is qualified, mitigations to reduce and eventually eliminate risk to the business must be implemented. Once the incident has been neutralised and risk to the business is under control, full recovery efforts can commence.

By investing in Threat Lifecycle Management, the risk of experiencing a damaging cyber incident or data breach is greatly reduced. Although internal and external threats will exist, the key to managing their impact within an environment and reducing the likelihood of costly consequences is through faster detection and response capabilities.


Wednesday, August 27, 2014

Best Computer Forensics Certifications for 2014


Computer forensics is one of the more challenging IT disciplines, and certified professionals remain in high demand. Yet computer forensic certifications remain something of a "wild" frontier. From two dozen available credentials, we list the five best options for 2014.

Today, there are a number of high-quality certification programs that focus on digital investigations and computer forensics. However, there are also certifications and programs in this area that are far less transparent, well-documented and widely known.

What's creating this demand for new programs in computer forensics? Consider the following:
  • Computer crime continues to be a major growth area. As more cyber crimes get reported, more investigations and qualified investigators are needed. This is good news for law enforcement and private investigators who specialize in computer forensics.
  • There's a high demand for qualified computer forensics professionals as nearly every police department is in need of a trained candidate with suitable credentials.
  • IT professionals interested in working for the federal government (either as full-time employees or private contractors) must meet certain minimum training standards in information security.Computer forensics qualifies as part of the mix needed to meet such requirements, which further adds to the demand for certified computer forensics professionals.

As a result, there is a continuing rise of companies that offer computer forensic training and certifications, many of which are "private label" credentials that are not well recognized. Making sense of all the options and finding the certification that's right for you might be more difficult than it seems.
A recent survey we conducted for SearchSecurity.com (June 2013) on available information security certifications turned up just under two dozen computer forensics and anti-hacking credentials.And these are all somewhat well-known, and on the up-and-up. But in pulling those materials together, we deliberately ignored programs that didn't publish the sizes of their certified populations or that are associated with mandatory high-dollar training. (A small certified population usually means the program is just getting started or not doing very well. We generally look for programs with no fewer than 5,000 certified professionals, by contrast. Expensive training sometimes indicates there's a strong profit or financial motive in signing people up for certification.)
After a closer analysis of all of the available programs out there, we've identified the five best computer forensics certifications for 2014.
Certified Computer Examiner (CCE)

The Certified Computer Examiner (CCE) comes from the International Society of Forensic Computer Examiners, aka ISFCE.
It is well-recognized in the industry and in the law enforcement community as a leading credential for computer forensics professionals. Private-sector holders usually include security officers and managers, IT administrators or managers, security or forensics consultants, systems and data security analysts and investigators, and even some lawyers and HR managers. Law enforcement holders usually serve as forensic investigators, analysts, or technicians, and conduct official investigations to research or prosecute computer crimes.
The certification process for the CCE includes both a proctored online multiple-choice exam and hands-on forensic analysis of a floppy or CD-R optical disk. When the online exam is completed, applicants conduct a thorough forensic examination of the test media with which they are supplied. Together, both written and hands-on portions are intended to verify a candidate’s skills and knowledge in the area of computer forensics.
The CCE training classes usually run for 5 days in the classroom (or 40 hours of online or self-paced materials). Instructor-led versions generally cost $2,500 to $3,500 in North America, and are highly regarded. Online or self-paced versions may be somewhat less expensive but don’t always deliver direct instructor contact.
Table 1: Certified Computer Examiner (CCE)
Certification Name
Certified Computer Examiner (CCE)
Prerequisites/
Required courses
One of the following is required:
  • Training at a CCE Bootcamp Authorized Training Center
  • Proof of other digital forensics training (can be self-study); must be approved by the Certification Board
  • At least 18 months of verifiable experience conducting digital forensic examinations
Candidates cannot have a criminal record.
Number of Exams
2 exams are required to earn the CCE:
  • Online Written Exam (75 questions in 45 minutes; 70% passing score required to proceed to Practical Examination)
  • Practical Examination (three actual scenarios to investigate)
Average score of 80% for both exams is required to earn the CCE
Cost per Exam
$395 USD for both exams in the USA; prices vary by location elsewhere
URL
Self-study Materials
There are no books or Exam Crams available for this topic, but the ISFCE publishes a complete list of suggested study materials (books and online materials), all of which are readily available to the public:www.isfce.com/study.htm

Certified Hacking Forensic Investigator (CHFI)

The International Council of E-Commerce Consultants, aka EC-Council, is a well-known training and certification organization that specializes in the areas of anti-hacking, computer forensics, and penetration testing.
The Certified Hacking Forensic Investigator (CHFI) certification emphasizes forensics tools, analytical techniques, and procedures involved in obtaining, maintaining, and presenting computer forensic evidence and data in a court of law. EC-Council offers training for this credential but permits candidates to challenge the exam without taking the course, though payment of a non-refundable $100 application fee is required.
The CHFI course runs for 5 days and covers a wide range of topics and tools (a detailed course description is available). Topics include a comprehensive cyber-crime overview, in-depth coverage of the computer forensics investigation process, search and seizure of computers, working with digital evidence, incident handling and first responder procedures, gathering volatile and non-volatile data from a Windows computer, recovering deleted files and partitions from Windows, Macintosh, and Linux systems, using AccessData FTK and Encase Steganography, password cracking, log capturing tools and techniques, investigating network traffic, wireless attacks, Web attacks, and e-mail crimes. Courseware is available, as well as instructor-led classroom training.
EC-Council also offers numerous other related certifications of potential value to readers interested in the CHFI. These include the Certified Ethical Hacker (CEH), EC-Council Certified Security Analyst (ECSA), EC-Council Certified Incident Handler (ECIH), and Licensed Penetration Tester (LPT). Visit the EC-Council site for more information on these popular and respected credentials.
Table 2: Certified Hacking Forensic Investigator (CHFI)
Certification Name
Certified Hacking Forensic Investigator (CHFI)
Prerequisites/Required Courses
Training is not mandated to earn the CHFI, but it is both available and recommended. The training class costs about $3,000 for instructor-led classroom training, $1,600 for online self-paced training, or $650 for self-study courseware. Mobile courses are also available, which start at $2,000.
Number of Exams
1 exam: 312-49 or EC0-349 (150 questions, 4 hours, passing score 70%, multiple choice)
Cost per Exam
$500 (or local currency equivalent) at either Prometric or Pearson VUE testing centers
URL
Self-study Materials
CHFI Study Guide available at Amazon; some practice exams also available.
Certified Forensic Computer Examiner (CFCE)

The International Association of Computer Investigative Specialists (IACIS) is the organization behind the Certified Forensic Computer Examiner (CFCE) credential. This organization caters primarily to law enforcement personnel (and you must be employed in law enforcement to qualify for regular IACIS membership), but the organization also offers associate membership to retired law enforcement personnel and to full-time contractors to law-enforcement organizations.
A formal application form, along with an application fee, is necessary to join IACIS. Those who are not current or former government or law enforcement employees or are not forensic contractors to a government agency can apply for Associate Membership to IACIS, provided they can pass a background check.
Earning the CFCE requires passing a two-step testing process that includes a Peer Review and CFCE certification testing. Peer Review consists of accepting and completing assigned problems based on core knowledge and skills areas for the credential. These must be solved, and presented to a mentor for initial evaluation (and assistance, where needed) before being presented for peer review. Upon successful conclusion of peer review, candidates must work independently to analyze and report upon a forensic image of a hard drive provided to them. Following specific instructions, a written report is prepared to document the candidate’s activities and findings.
Once that report is accepted and passed, the process concludes with a written examination. A passing score of 80 percent or better is required for both the forensic report and the written exam to earn the CFCE.
Despite the time and expense involved in earning a CFCE, this credential enjoys high value and excellent name recognition in the computer forensics field. Many forensics professionals consider the CFCE to be a necessary "merit badge" to earn, especially for those who work in or for law enforcement.
Table 3: Certified Forensic Computer Examiner (CFCE)
Certification Name
Certified Forensic Computer Examiner (CFCE)
Prerequisites/Required Courses
Training is not mandated to earn the CFCE, but it is both available and recommended. The two-week Basic Computer Forensic Examiner (BCFE) instructor-led classroom training costs $2,795. (IACIS membership is required to take IACIS courses.)
If you choose not to attend the training, you can enter the program by registering and paying the $750 registration fee.
Number of Exams
The CFCE involves a two-part process, taken in this order: Peer Review problems and practical examination, and a written certification exam. Satisfactory performance on the Peer Review phase is required to advance to the certification exam. Satisfactory completion of both phases is required to earn the CFCE.
Cost per Exam
$750 for the entire examination process (non-refundable once an application is submitted)
URL
Self-study Materials
IACIS is the primary conduit for training and study materials for this certification. No books or practice tests are currently available for the CFCE, but Ed2Go offers an online preparation class.

GIAC Certified Forensic Analyst (GCFA)

SANS is the organization behind the Global Information Assurance Certification (GIAC) programs, and is a well-respected and highly regarded player in the information security field in general. SANS not only teaches and researches in this area, it also provides breaking news, operates a security alert service, and serves on all kinds of government, research, and academic information security task forces, working groups, and industry organizations.
The organization's forensics credentials include the intermediate-level GIAC Certified Forensic Analyst (GCFA) and the more senior GIAC Certified Forensic Examiner (GCFE). Neither credential requires taking SANS courses (which enjoy a strong reputation as among the best in the information security community, with high-powered instructors to match) but they are recommended to candidates, and often offered before, during, or after SANS conferences held around the USA at regular intervals.
Both GCFA and GCFE focus on computer forensics in the context of investigation and incident response, and thus also focus on the skills and knowledge need to collect and analyze data from Windows and Linux computer systems in the course of such activities. Candidates must possess the necessary skills, knowledge, and ability to conduct formal incident investigations and advanced incident handling, including dealing with internal and external data breaches, intrusions, and advanced persistent threats, understanding anti-forensic techniques, and building and documenting advanced digital forensic cases.
The SANS GIAC program encompasses more than 60 information security certifications across a broad range of topics and disciplines. IT professionals interested in information security in general, as well as computer forensics in particular, would be well advised to investigate further at the GIAC home page.
Table 4: GIAC GCFA and GCFE
Certification name
GIAC Certified Forensic Analyst (GCFA)
GIAC Certified Forensic Examiner (GCFE)
Prerequisites/Required Courses
None.
Course FOR508: Advanced Computer Forensic Analysis and Incident Response is recommended for the GCFA
Course FOR408: Computer Forensic Investigations – Windows In-Depth is recommended for the GCFE
Number of Exams
1 exam for each credential (115 questions, 3 hours)
Passing score of 69% for GCFA
Passing score of 71% for GCFE
Cost per Exam
$999 (or local currency equivalent) for challenge exam (no training). GCFA and GCFE certifications taken in conjunction with the SANS training class, which range from $5,000 to $5,500) are $579. Recertification attempts are $399.
URL
Self-study Materials
Study guides and practice exams are available for both GCFA and GCFE, through Amazon and other typical channels.

Professional Certified Investigator (PCI)

The parent organization for Professional Certified Investigator (PCI), the senior level computer investigations and forensics credential is known as ASIS International.
Founded in 1955, with more than 38,000 members world-wide, the former American Society for Industrial Security (now known simply as ASIS International) is one of the oldest and best-known information security bodies around. The PCI's primary focus is on investigations and includes coverage of case management, investigative techniques and procedures, along with case presentation.
ASIS adopted a book called The Professional Investigator’s Manual as its sole information source for this exam.
The PCI exam devotes 29% of its coverage to case management (analyze for ethical conflicts, analyze and assess case elements and strategies, determine and develop strategy through review of procedural options, manage and implement necessary investigative resources), 50% to investigative techniques and procedures (electronic and physical surveillance, interviews and interrogations, collect and preserve objects and data, research by physical and electronic means, collect and report relevant information, use computers and digital media to gather information and evidence, and more), and 21% on case presentation (prepare report to substantiate investigative findings, and prepare and present testimony). This is the only credential in this article that really teaches people how to analyze and present information for expert reports and testimony.
For practiced or aspiring computer forensics professionals who wish to work on legal cases involving their expertise, especially if they wish to appear in depositions or at trial, the PCI is THE absolute credential to have. It makes sure holders are ready to withstand the rigors of the legal system, and present themselves and their evidence with best results in the courtroom.
Table 5: Professional Certified Investigator (PCI)
Certification Name
Professional Certified Investigator (PCI)
Prerequisites/Required Courses
Candidates must meet qualification requirements for PCI as well, which include:
  • 5 years of investigation experience, with two or more years in case management
  • High school diploma or GED equivalent
No course is required but the following training is available from ASIS:
  • An online review course ($400 for members, $550 for non-members)
  • A CD ($500 for members, $650 for non-members)
  • A two-day classroom review ($725 for members, $925 for non-members; discounts apply for early sign-up)
Number of Exams
1 exam (125 multiple-choice questions, no info about duration)
Cost per Exam
Computer-based testing: $300 ($450 for non-members); $200 ($350 for non-members) for subsequent retesting
Pencil and paper testing: $200; $100 for subsequent retesting
URL
Self-study Materials
Professional Investigator's Manual, ISBN 978-1-934904-02-2 (hardcover $105 member, $175 non-member; softcover $64 member, $93 non-member)

Beyond the top 5 computer forensics certifications listed in this article, there are lots of other certification programs that can help to further the careers of IT professionals who work in computer forensics. 
In particular, credentials from Access Data (Access Data Certified Examiner: ACE) and EnCase(EnCase Certified Examiner: EnCE) are worth pursuing for those who already use (or plan to use) the forensics toolsets and platforms available from those vendors. Access is well known for its FTK Forensic Toolkit, which enjoys considerable use in law enforcement and private research and consulting firms. The same goes for the EnCase Guidance software, which is also very widely used in the field as well.
And if you look around online, you'll find numerous other forensics hardware and software vendors that offer certifications and plenty of other organizations that didn't make the cut for the 2014 list of the best computer forensics certifications. But before you wander outside the items already mentioned in this article, you might want to research the sponsoring organization's history, the number of people who've earned its credentials, and determine whether or not the sponsor not only requires training but stands to profit from its purchase.
You might also want to discuss with a practicing computer forensics professional as a final check, to ask them if (a) they've heard of your other candidate and (b) if so, what they think of their offerings.
If you do your homework, you won't get burned. Certified computer forensics professionals are sure to remain in high demand for 2014 and beyond.


My Blog List

Networking Domain Jobs