IT security industry 'to be professionalised'

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

IT security officers are to get their own professional body in the UK with the launch of the Institute of Information Security Professionals (IISP) next month.

The IISP, which was given the go-ahead by the Department for Trade and Industry at the end of last year, is due to officially launch in February.

Nick Coleman, the interim chief executive of the Institute, who is also IBM's head of security, told ZDNet UK that the goal of the institute is to "professionalise the industry" and ensure IT security officers reach a certain standard.

"We are increasingly dependent on information and its security — people working in this field are critical to the organisation. At the moment, there is no way of understanding if people are professionally competent," said Coleman.

He pointed out that although qualifications are important, people "can pass a qualification and don't need to worry about it again." The IISP plans to offer security professionals an "associate" or "full membership" dependent on a number of factors including industry experience and ongoing training.

The institute already has members on board from a number of companies, including BP, Royal Bank of Scotland, HBOS and Vodafone. Over the next few months it plans to build its membership base, set up a Web site and start a programme of masterclasses for chief information security officers, where they can share best practice on issues such as governance and risk assessment, according to Coleman.

Richard Starnes, the president of the Information Systems Security Association, said that the IT security industry needs a professional body similar to the Chartered Institute of Accounting and the Bar Council, which represents barristers.

"These institutions have the ability to regulate the profession, because the profession is so important to society as a whole. The information security profession is equally important in terms of its role in protecting critical national infrastructure," said Starnes.

The IISP will not initially have the power to remove the right of practice of a security officer who is deemed incompetent.

Coleman said IISP will discuss such issues in the future, but at present, it is focussing on "getting people to full membership". "If we do that a lot of other issues will be taken care of," he said.

Talkback

It is my opinion that there are too many "professional bodies" carrying on their business. Unless a body actually holds worthwhile recognised examinations and issues qualification certificates then it is no more than a "jobs for the boys" body. And as such it becomes a further uneccessary cash drain upon our society, whether it is through taxation, levy or per capita charge.
The question should be - Will the inception of this body make any difference at the customer level? If not then it is just another self deluding concern.
Surely it is incumbent upon an employer to ensure his IT employees hold suitable qualifiaction for their job and that such qualifications (and refreshers) are "in date" .

via Facebook 16 January, 2006 21:12
Reply

Ahh yes, yet ANOTHER group trying to get on the 'We Secure IT Security" band-wagon.
The ISC2 is already doing this, as are a myriad of other organisations.

Why do we need yet another organisation? I agree that IT Security professionals should be held as accountable as CPAs, Nuclear Technicains and Aircraft Mechanics but we already have bodies in place that are well positioned to do this.

Now those of us in the IT Security industry have to get yet another certification, pay another set of dues and report our ongoing training to yet another organisation.

via Facebook 17 January, 2006 00:26
Reply

This new group appears to be for those without any security qualifications. Security professionals that already have qualifications are members of ISC2 or ISACA or ISSA. Now we have ISSP, whats next ISSQ?

via Facebook 17 February, 2006 15:05
Reply

As another “latest" and "best ever" security certification hits the already saturated security certification space, one asks is it really needed. With vendor neutral certifications, not to mention the ubiquitous vendor ones already available one ask do we need another security certification, with all the requisite fees and CPEs to keep up with.

With ISC2 CISSP and ISACA CISA and now CISM well established, one must ask the rationale behinde The DTI’s and Cabinet Office’s support for yet another security certification, the form of IISP. Reading, what little material available so far on IISP, it does not seems to add anything over the aforementioned and established certificates. Being a CISSP of 4 years standing and having recently passed CISM, I only see IISP adding to confusion and undermining the existing hard earned designations.

Since Novell's CNA/E hit the certification market; accusations have been rife of vendors cynically using ever innovative and sometimes as a new and important income stream. It seems vendor neutral security certifications perhaps are also being used to generate nice little “earners” for the boys. Perhaps the people behind the IISP certification need to start by demonstrating Return On Security Investment (ROSI) for their existence. Until then I like many people will not be convinced that IISP will add anything to my existing skills and designations other than CPEs and FEES.

via Facebook 22 February, 2006 23:51
Reply

There is a professional body for IT in the UK - the British Computer Society ("BCS"). Why develop a separate body to govern IT security? Why not bring IT security certification under the BCS?

via Facebook 24 May, 2006 13:12
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

6 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

8 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

9 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

11 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

12 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

13 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

14 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

14 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

15 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

17 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

23 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 day ago by ramwellian on Cloud computing security: no more oxymoron?