[Owasp-cert] Lee Kushner talk at OWASP 2008 USA

Bil Corry bil at corry.biz
Mon Oct 20 16:45:46 EDT 2008


He does bring up an interesting paradox - the more that people have the certification, the less relevant and valuable it is.  So the conflict for us is, how do we encourage many people to become certified, fulfilling OWASP's mission of "make application security visible" while tempering it with a certification that is challenging to obtain?  I suppose the different qualifying levels of the certification do achieve this to some degree.

- Bil


McGovern, James F (HTSC, IT) wrote on 10/20/2008 3:36 PM: 
> You mean I can't grandfather myself :-( 
> 
> Seriously, I plan on being one of the first candidates to take our exam
> in the spirit of eating one's own food. The challenge is that if I fail,
> it will appear more credible than if I pass. Have to think about this
> reality. 
> 
> -----Original Message-----
> From: owasp-cert-bounces at lists.owasp.org
> [mailto:owasp-cert-bounces at lists.owasp.org] On Behalf Of Bil Corry
> Sent: Monday, October 20, 2008 4:29 PM
> To: owasp-cert at lists.owasp.org
> Subject: [Owasp-cert] Lee Kushner talk at OWASP 2008 USA
> 
> I was watching Lee Kushner's talk from OWASP 2008 USA (NYC) and he gives
> some advice for the OWASP certification.  He starts talking about
> certification at 8:00, and specifically mentions OWASP certification at
> 8:53:
> 
> 	
> http://video.google.com/videoplay?docid=5330096815878108179&hl=en
> 
> For those who don't want to watch a minute of video, he basically
> advises OWASP certification to set the bar very high and make everyone
> take the exam to get the certification (i.e. don't hand out certs to
> deserving individuals).




More information about the Owasp-cert mailing list