IMO that should be avoid current certification. Avoiding all certification for all eternity would imply that training decent pentesters/hackers is something that cannot be done in a controlled methodical way. Which would be a setback for the entire infosec industry, IMO, because I do think that such a thing (infosec is not a special snowflake) is possible.
I think OSCP is actually a big step in the right direction. The harder challenges in their training network force you (and encourage you) to deeply investigate the underlying security issue. That part of the training actually focuses on the underlying conditioning that you need to become a good pentester, as shown by their slogan 'try harder'.
It's the same thing that armies the world over do. The army also realized that knowing everything there's to know about tactics and how to operate a weapon is not enough, soldiers also need to be aggressive and need to be conditioned to be able to effectively engage an enemy. So there's training designed to increase a soldier's willingness to fire upon enemies when ordered to.
The same goes a bit for this training, where underlying simple technical guidance is provided at the start of the training, and later a trainee is left to themselves and pushed to investigate on their own, something that I'd recognize as one of the cornerstones of a successful hacker.
Still, I'd also avoid hiring a person for a technical position if all they can show is a CISM/CISP/w\e
Heh I tried that a few times, but I found that many of them have devolved into hopelessly contrived abominations of true security issues. Fun games to be sure, but of trivial usefulness for actually building up skills I think.
I do like the ones that offer memory corruption/exploitation challenges, but those are few and far between.
IMO that should be avoid current certification. Avoiding all certification for all eternity would imply that training decent pentesters/hackers is something that cannot be done in a controlled methodical way. Which would be a setback for the entire infosec industry, IMO, because I do think that such a thing (infosec is not a special snowflake) is possible.
I think OSCP is actually a big step in the right direction. The harder challenges in their training network force you (and encourage you) to deeply investigate the underlying security issue. That part of the training actually focuses on the underlying conditioning that you need to become a good pentester, as shown by their slogan 'try harder'.
It's the same thing that armies the world over do. The army also realized that knowing everything there's to know about tactics and how to operate a weapon is not enough, soldiers also need to be aggressive and need to be conditioned to be able to effectively engage an enemy. So there's training designed to increase a soldier's willingness to fire upon enemies when ordered to.
The same goes a bit for this training, where underlying simple technical guidance is provided at the start of the training, and later a trainee is left to themselves and pushed to investigate on their own, something that I'd recognize as one of the cornerstones of a successful hacker.
Still, I'd also avoid hiring a person for a technical position if all they can show is a CISM/CISP/w\e