Hello all,
I would like to get your feedback on the certification path I've chosen to take. My educational background is a bachelor degree in CS as well as a bachelor and master degree in law. All professional experience I've gained was in my own company. I started my company 17 years ago in High School building websites, that gradually moved (as my studies progressed) towards web application development and later consultancy. Currently, I work for different clients as an IT consultant, project manager, and interim IT manager. In those roles, I've gained some experience in InfoSec, specifically in Identity management and Security/Risk management (especially compliance to privacy regulations). Because I receive a lot of requests from (potential) customers to set up an ISMS and/or test their security, I decided to move more into those areas. My goal is to provide security consultancy, pen testing and setting up an ISMS for my customers. Therefore, after research on different forums and blogs, I decided to take the follow certs/courses:
- Sec+ (self-study)
- ISO 27001/27002 Lead Implementer (Live class)
- CEH (Live class)
- GPEN (Live class)
- OSCP (Live class)
For the pen testing courses I decided to brush up on:
- Linux skills (taking the Linux foundations courses)
- Network knowledge (N+ self-study)
- TCP/IP knowledge (Reading a few books)
- Coding skills (I know PHP and some ASP, taking online Python and Ruby courses)
Before I'm taking the CEH class I will read a CEH book.
I would like to have your comments on the following:
- Any advice on the certs I'm taking, are there any leaps I'm taking that are too big or are some certs overlapping too much?
- Do you recommend taking OSCP directly after GPEN or wait a while and gather more experience before taking it?
- Any advice on the pen testing prep? Do I need to cover some other areas as well or is there any overkill in what I'm doing now?
- I've already finished studying for Sec+ but contemplating whether or not to take the exam, any thoughts?
Thank you in advance for your time!