April 19, 2022 By Brian Rhoades Cybersecurity Certifications, Industry News

Log4Shell broke at the end of 2021 and the security industry spent December and a good chunk of January in emergency response mode. If you somehow missed it, Log4Shell was a critical remote code execution vulnerability in Log4j, a Java logging library that is embedded in an almost uncountably large number of applications and infrastructure components. The vulnerability was trivial to exploit and the attack surface was massive because almost nobody had a complete inventory of where Log4j was running in their environment.

That last point is the one I want to dwell on, because it cuts directly to the skills and knowledge that certification programs are supposed to develop and that incidents like this test in real time.

Asset and software inventory management is foundational to any meaningful security posture. You cannot patch what you do not know you have. You cannot assess exposure to a vulnerability in a specific library if you do not have visibility into which applications in your environment use that library, in which versions, running on which systems. The organizations that responded to Log4Shell fastest and most completely were the ones with mature software bill of materials practices and application inventories. The ones that struggled most were the ones whose inventory was fragmented, incomplete, or simply nonexistent.

This is content that shows up in CISA exam domains around IT asset management and information systems operations. It shows up in the CompTIA Security+ and CySA+ around vulnerability management. It shows up in the CISSP in the asset security domain. These are not obscure corners of the curriculum. They are foundational concepts that Log4Shell demonstrated have direct operational consequences when they are not implemented well.

Patch management as a discipline also deserves mention. The challenge with Log4Shell was not just identifying where Log4j was running. It was the complexity of the patch response given how deeply embedded the library was in third-party and vendor-supplied software. Organizations had to coordinate with application vendors for patches to software they did not build themselves while also patching the components they did build. The patch management content in Security+ and related certifications, which sometimes feels abstract during study, became very concrete for security teams in December.

The CISA vulnerability research and coordination center at CISA’s known exploited vulnerabilities catalog is a resource worth bookmarking if you are in any kind of infrastructure or security role. It is updated regularly and reflects the actual vulnerability landscape that security practitioners are managing. Studying certification material alongside real-world resources like this gives you context that pure exam prep does not.

Log4Shell will not be the last incident of its kind. The software supply chain and the pervasive use of open source components throughout enterprise software stacks means that critical vulnerabilities in widely-used libraries are an ongoing risk category that is not going away. Building the skills to respond effectively to those incidents, and more importantly to establish the asset management practices that enable a faster and more complete response, is a meaningful investment in both your personal competence and your organization’s resilience.

Brian Rhoades

Brian Rhoades is a Senior VMware Instructor and IT veteran with more than 15 years of hands-on experience in virtualization, systems engineering, and cloud infrastructure. He has trained thousands of IT professionals to confidently work with VMware vSphere, vSAN, and NSX, and has authored multiple books and study guides for outlets across the industry. Brian has a habit of being somewhere new every few weeks, which if you've ever tried to pin down a good VMware instructor, explains a lot.