Credentials are hugely important to practice; 87% of polled UK employers indicated that they would look for the CISSP when recruiting staff (DBIS 2014b). Today’s IT practitioner in search of qualifications does not lack choice, both in provider (for example amongst many others IISP, (ISC)², BCS, City and Guilds, CREST and ISACA3) and grades of membership and examination. Some such as CREST cover a narrow band of practice, others such as the CISSP are more broad. Many have strong emphases on ethical behaviour, continuing professional development and professional practice skills. It is not proposed to review the entire credentials market; it is important simply to note its existence, properties, intent and range and move on to why they are offered and by whom.
The evolution of Information Security into a domain with constituent non-technical aspects has occurred very rapidly; so much so that many workers have predominantly had to acquire the new “soft” skills mid-career, rather than during their initial education and socialisation process,
3Full names given on page ix, however many of these no longer use their expanded form.
as would be the case for the more established professions (Siponen, 2000; Ashenden, 2008;
NRC, 2013; Stewart and Lacey, 2012; E-Skills UK, 2013; Lacey, 2006). Although key aspects of their role, current practitioners lack confidence in their command of these new competencies (Ashenden and Sasse, 2013). This leaves a particular challenge for how to attain and establish competence for the modern professional, which is mainly achieved – fully in line with the sociological analyses of formation seen above – through certification by a professional body.
Without a common body of knowledge enforced by the profession, there cannot be a unified professional identity (Everett, 2011; Burley et al., 2014; Orlikowski and Baroudi, 1988). The definition and delineation of a formal body of knowledge which can be assessed through certification is a fundamental part of claiming professional status (Griffiths et al., 2010). Indeed professional identity is clearly the aim of many certifications, requiring both examinations and qualifying periods of experience. Since tests of knowledge should not require a mandatory preparatory period, these credentials are clearly meant to be the foundation to a professional claim of experience, skill and judgement, not simply the recall of learned facts. Whilst DBIS (2014a; 2014b) has investigated this from industry and academia to frame its next steps, this work was based on questionnaires and did not support a deeper analysis to discuss the point further.
The substantial range of certification schemes for security professionals available in the UK (issued by both international and national bodies) is not currently regulated by a single, national governing body authorised and delegated by government. When challenged to rationalise them during its own research, government refused to disrupt what it saw as a purely commercial marketplace (DBIS, 2014b). Knowles et al. (2016) however found that penetration testers saw visible CESG and CREST involvement as crucial to the standardisation of that part of the industry. Whilst it was seen above that this reticence to interfere in a profession unless necessary is common, it has hindered professional recognition since there is no clear single certification to recognise as a standard (Furnell, 2004; Tate et al., 2008; Schultz, 2005; Everett, 2009) partially because of the wide variation in rigour and study time (Mansfield-Devine, 2013).
If these certifications can appeal to a sufficiently distinguished market based on some differentiated branding or emphasis then the status quo may be maintained, otherwise it may tip in favour of one particular qualification (Katz and Shapiro, 1994) making that organisation a de facto controller of entry to practice. This effect has been studied with interest in relation to IT standards, since the relatively swift rate of development and the degree to which standards interoperate and feed back within different sub-disciplines makes network effects particularly noticeable (Heinrich, 2013).
Why does this matter? A central organisation plays a critical role in advancing professionalisation; it distils member opinion, directs and represents their ambition, centralises their campaign, provides resources for development and facilitates networking (Millerson, 1964). By forming a society of practitioners apparently adhering to certain principles and of certified levels of competence, the institution provides legitimacy (Bloland, 1997). To that end, Lacey (2006) sets out the agenda for the IISP, founded in the UK in 2005:
“A new profession is struggling to emerge, in an ad hoc and piecemeal fashion, with little formality and structure. The contemporary scene is one of largely self-trained industry leaders supported by an up-and-coming group of ambitious individuals … There is a need for a greater emphasis on professional development to develop future generations of well-rounded, fully trained leaders who can demonstrate … that they are competent and effective”
(Lacey, 2006) Lacey also builds an argument for the increasing importance of security (citing the increasing threat and increasing regulation) and thus the importance of ensuring competent management through better regulation and more formalised training. The latter part, supported by a complaint that security practitioners are self-taught invaders from other IT disciplines, is most interesting seen through the work of Abbott (1988), reviewed above.
Furthermore, the UK has a computing charter body (the BCS) with an active security chapter, therefore it is interesting that the IISP has also formed in the spaces around computer security, audit and computer law. The BCS also maintains qualifications and would appear to have a claim for supremacy from its Royal charter:
“to establish and maintain appropriate standards of education and experience for persons engaged in the profession of Computing or entering upon courses of study in Computing and allied subjects”
(Privy Council, 2003[1984]) Lacey (2006) mentions the BCS in passing, principally as a peer along with a number of engineering associations, implying that they would be advisory and supportive to a new institute representing Information Security practitioners. That the IISP and BCS both run security certification schemes (and that the IISP's framework has apparently found favour with the government with regards to assessing education) however is arguably an example of Abbot-type splinter competition for control of a body of knowledge, albeit that the organisations greatly overlap and cooperate (Mansfield-Devine, 2013). Whilst an argument can be made that the domains of IT Security (which the BCS might fully own) and Information Security (the focus of the IISP) are separate, writers such as Abbott (1988) and Freidson (1970) show that professions such as law and medicine have extended their reaches to cover gaps far wider than this in search
of dominance over an area of practice.
Ultimately such bodies allow security professionals to participate in industry and collegiate events (Brocaglia, 2005) which is a vital step to establishing an identity. Institutions are not necessarily benign forces however, even if established with pure motives; those at the top can be very well rewarded which may skew the priorities and behaviour of the organisation if an effective democratising process is not present (Schultz, 2005).
Perhaps the most significant recent work on the Information Security profession was the study by the US National Research Council (NRC, 2013) and subsequent paper by its lead contributors (Burley et al., 2014), published after the data for this study was collected. The NRC was tasked with determining criteria for whether government should professionalise the US industry. This study, whilst extensive, took a relatively basic, trait-based model of profession (see also the online white papers on the subject by NICCS (2012a; 2012b)) and was based on public testimony from a large number of institutions, expert witnesses and professionals. The poorly-defined scope of Information Security practice and myriad potential roles and inter-relationships led the report to conclude that the occupation was not mature enough to be regulated as a profession. Whatever roles have been defined for the industry had apparently not taken root in the US context by 2013.
Whilst governments have been slow to introduce mandatory qualifications in private practice, they have taken steps to regularise entry into their own security ranks. The US 8570.01-M
"Information Assurance Workforce Improvement Program" mandates baseline technical and management skills of staff occupying Information Assurance roles in the US Department of Defense (US DoD, 2010). Personnel fulfilling these roles (which are defined in some detail) are required to acquire and maintain particular qualifications, which may only be waived in cases of
“severe operational or personnel constraints”, the certification level required being commensurate with the designated seniority or technical skill level of the role.
Similarly, as part of the UK Cyber Security Strategy, the UK Government intention is to increase the level of professionalism amongst national security workers (CESG 2012a, p.3;
DBIS 2014a). The stated aim appears to be one of ensuring a level of competence to a set standard of knowledge and awareness, as defined by the IISP. A hierarchy of competence status levels is defined and a series of body of knowledge streams identified. There is a directly implied link between professionalisation and competence to respond to increased threat (CESG 2012b, p.7). The hierarchy is cumulative for technical knowledge but not for other skills, such that it is possible to manage a team without being able to perform every job within it, however an “expert” must possess also relevant basic and intermediate technical skills (CESG 2012b,
pp.25–26). A brief code of conduct is included (CESG 2012b, p.31).