September 8, 2020 By Brian Rhoades Cybersecurity Certifications

Somebody asked me at a virtual training event last month whether the Security+ was still worth pursuing given how much the cybersecurity certification market has expanded. There are more options now than there were five years ago. Vendor-specific security credentials, specialized certifications for cloud security, pen testing, digital forensics. Is the Security+ still relevant or has it been lapped?

It is still relevant. Here is why the argument is actually straightforward.

The Security+ occupies a specific and important position in the certification ecosystem. It is vendor-neutral, which means it is not tied to a platform you may or may not be working with at any given employer. It is DoD-approved under the 8570.01-M directive, which matters enormously for anyone pursuing government or defense contractor roles. And it covers a broad enough set of foundational security concepts that it genuinely makes you a more capable IT professional regardless of your eventual specialty.

The DoD 8570 connection is worth dwelling on for a moment because I think it gets undersold in general career discussions. A significant portion of the cybersecurity jobs in the United States are in or adjacent to the federal government and defense contracting ecosystem. The DoD mandates that personnel performing information assurance functions hold specific baseline certifications mapped to their job roles. The Security+ satisfies the baseline requirement for several of those role categories. If there is any chance you will work in that world, the Security+ is not optional. You can review the DoD 8570 framework directly at the DOD Cyber Exchange site.

For people entering cybersecurity from a general IT background, the Security+ also serves as a forcing function to fill knowledge gaps that practitioners often develop by working in narrow specialties for a long time. Cryptography concepts, PKI, identity and access management, risk management frameworks, incident response processes. These are things that experienced IT professionals sometimes have deep practical experience in one area and significant gaps in others. Working through the Security+ content systematically tends to surface those gaps in a way that informal on-the-job learning does not.

The current version of the exam, SY0-601, was released this year and covers the threat landscape and technology environment of 2020 including cloud security, mobile security, and the kinds of social engineering attacks that dominate real-world incident reports right now. It is a well-designed exam and the CompTIA Security+ certification page has the full objectives available as a free download.

The Security+ is not the credential that will make you a senior security engineer. That is not what it is for. It is the credential that establishes a common foundation of security knowledge that employers can build on when they hire entry and mid-level practitioners. For that purpose, in 2020, it is still the best option in its category.

Brian Rhoades

Brian Rhoades is a Senior VMware Instructor and IT veteran with more than 15 years of hands-on experience in virtualization, systems engineering, and cloud infrastructure. He has trained thousands of IT professionals to confidently work with VMware vSphere, vSAN, and NSX, and has authored multiple books and study guides for outlets across the industry. Brian has a habit of being somewhere new every few weeks, which if you've ever tried to pin down a good VMware instructor, explains a lot.