Aussie CREST exams could open by November

Powered by SC Magazine
 

Exams hosted in Canberra, AusCERT hears.

The Council of Registered Security Testers (CREST) could begin certifying web application penetration testers in Australia and New Zealand for the first time by November.

SC Magazine broke news of the formation of the Australian and New Zealand chapters of CREST when it launched in March this year.

Originally formed in Britain, the certification requires testers and penetration testing organisations to pass a number of gruelling penetration exams, paying thousands for the privilege.

In return, CREST chapters on both sides of the Tasman promise to promote certified professionals to the country's largest and wealthiest corporations as the best in the business, able to seek out every nook and cranny that hackers might use to steal sensitive data and cause chaos.

The November timeline for availability of the Web Application Certification Examination track – one of a number available – was aspirational only and formal deadlines are yet to be set, CREST board members told a small gathering at AusCERT 2012.

Australian candidates initially need to attend a lab in Canberra to take the tests. Examinations can be taken later in each capital city via a secure link to Canberra.

Pen testing organisations are accredited initially through self-assessment, however both chapters considered having Australia firms audit New Zealand counterparts and vice versa.

Universities have also been invited to offer penetration testing training for the certifications. The chapters noted such training courses need to be supplemented with around six years' experience in penetration testing and would not be "crash courses and boot camps".

Many other aspects of CREST are also not yet set in stone. It was too early, for example, to consider including forensics within CREST (a forensics module exists in the UK model) nor have the groups established a pricing model.

However CREST in Australia and New Zealand would resemble the British model as much as possible under a collective objective to create a "global certification".

CREST Australia representatives at the AusCERT meeting included Richard Byfield from DataCom TSS and Wade Alcorn from NGS Secure, while New Zealand was represented by New Zealand Internet Task Force chair Paul McKitrick.

Copyright © SC Magazine, Australia


Aussie CREST exams could open by November
 
 
 
Top Stories
Meet FABACUS, Westpac's first computer
GE225 operators celebrate gold anniversary.
 
NSW Govt gets ready to throw out the floppy disks
[Opinion] Dominic Perrottet says its time for government to catch up.
 
iiNet facing new copyright battle with Hollywood
Fighting to protect customer details.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  26%
 
Sourcing and strategy
  12%
 
IT infrastructure (servers, storage, networking)
  22%
 
End user computing (desktops, mobiles, apps)
  15%
 
Software development
  25%
TOTAL VOTES: 346

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  58%
 
No
  42%
TOTAL VOTES: 144

Vote