Hiring the right person for the right job

I'm an IT manager looking to hire a full-time information security administrator. What certification(s) should I look for? Can you recommend any other tips on finding the right person?
For starters, let certifications be a guide not an absolute predictor of information security expertise. The CISSP is the most widely-recognized but various others are respectable as well including Security+ and the SANS GIAC certifications. Look for a vendor-neutral certification such as these if possible, but don't discount someone having a Microsoft, Linux, or especially Cisco-specific security certification. I still believe that hands-on experience is the best predictor of knowledge and success.
For more info on this topic, visit these SearchSecurity.com resources:
  • Ask the Expert: What role should certifications play in hiring someone?
  • Ask the Expert: Is a Master's degree or certifications better to have in the long run?
  • Ask the Expert: How can I prepare for the CISSP exam?

    This was first published in February 2005

  • Join the conversationComment

    Share
    Comments

      Results

      Contribute to the conversation

      All fields are required. Comments will appear at the bottom of the article.