GIAC Certs

in GIAC
My boss says CCIE Security is overkill for our team and CEH isn't necessary so he wouldn't pay for these, but he would send me to SANS training. I checked out the site and see quite a few certs that look interesting, but I don't know where to begin. Do I have to begin at a specific cert like taking CCNA before other Cisco certs? Or can I just pick any one?
GISP, GSEC, GCIH, GCIA, and GPEN all look interesting. The GISP looks like the same material as CISSP so should I just skip that one since I'm taking CISSP soon? Can GSEC be skipped since I have CCNP Security? This is my third year in Security with experience with firewalls, VPN, proxies, MDM, physical security, email filters, etc.
GISP, GSEC, GCIH, GCIA, and GPEN all look interesting. The GISP looks like the same material as CISSP so should I just skip that one since I'm taking CISSP soon? Can GSEC be skipped since I have CCNP Security? This is my third year in Security with experience with firewalls, VPN, proxies, MDM, physical security, email filters, etc.
Alphabet soup from (ISC)2, ISACA, GIAC, EC-Council, Microsoft, ITIL, Cisco, Scrum, CompTIA, AWS
Comments
I'd recommend doing the free trial excerpt of the training material and seeing what you like. Of course, your role and responsibilities will also play into what choice would be best for you. If you are heavily network focused, you might want to look into the GCIA.
When I got into SANS I looked at the GSEC topics and found them too basic. Since I am a Windows guy I started with SEC505: Securing Windows. From there I moved to SEC504: Hacker Techniques, Exploits & Incident Handling. My next one is SEC501: Advanced Security Essentials - Enterprise Defender. I'm an addict now.
I always try to create awareness of the Work/Study Program. If funds are tight and the boss complains about the hefty $5k price tag you can facilitate one of the events and get the class, audio MP3s, onDemand, and one attempt at the cert for $900.
I would go with the 504 (GCIH) this will dabble deep enough into most of those areas that you will get an idea of the path you would like to take. It is also a good intermediate certification for people who have a couple years in InfoSec.
Overall, I thought it was great and it allowed me to go at my own pace (balancing work/life/school/training) and I was provided with everything needed to be successful. The thing I liked most about OnDemand is the ability to move back and forth between videos, i.e. if there was a concept I needed to hear be explained again, or write down a note or whatnot - I could do that, and pick up where I left off. They also have contact information for if you run into any difficulties while studying - i.e. you aren't clear on a topic or a command, how a tool works, etc. Last, from a cost perspective, it allowed me to maximize my training budget by not having to fly out / stay in a hotel.
If I feel comfortable with the material being presented based on the 'syllabus', I'd definitely do OnDemand again (aiming for the GCIH in 2015, likely OnDemand). If it was something where I felt that I would need more help / guidance with an instructor in the room, then I would go on-site to the classroom training.
But OnDemand allows you four months of access to the material to go through as your schedule (and discipline) permits with a VirtualMentor who typically responds within hours of a query (in my limited experienced of using them). You also don't have the travel costs to the event, obviously. There are also discount offerings posted that people forget to mention:
https://www.sans.org/ondemand/specials
I've never done vLive, so I can't speak to that. The best bang-for-the-buck if you want to attend an actual conference is the WorkStudy program.
Currently Working On: Python, OSCP Prep
Next Up: OSCP
Studying: Code Academy (Python), Bash Scripting, Virtual Hacking Lab Coursework
Cool!!! Good luck!
Transmosis | http://transmosis.com | LinkedIn | https://linkedin.com/in/t1mku
If evil be spoken of you and it be true, correct yourself, if it be a lie, laugh at it. - Epictetus
The only real failure in life is not to be true to the best one knows. - Buddha
If you are not willing to learn, no one can help you. If you are determined to learn, no one can stop you. - Unknown