Deer Brook Consulting
Speciality: Comprehensive Security Assessments
IT services and consulting company specializing in information security, privacy, and IT solutions; offers penetration testing, governance, risk assessment, and compliance services; based in Portland, Maine, with 27 employees and 65.4% YoY growth.
Origins of CISSP
The Certified Information Systems Security Professional (CISSP) certification was created by the International Information System Security Certification Consortium, known as (ISC)², in 1994. It was developed in response to the growing need for a standardized credential that could validate the knowledge and expertise of information security professionals. The certification was designed to establish a common body of knowledge for the cybersecurity field and provide organizations with a reliable way to identify qualified security practitioners during a time when information security was becoming increasingly critical to business operations.
Industry Value and Importance
The CISSP is widely recognized as one of the most prestigious and valued credentials in the cybersecurity industry. It demonstrates that holders possess comprehensive knowledge across eight security domains, including security architecture, risk management, and software security. Many government agencies, including the U.S. Department of Defense, and Fortune 500 companies either require or strongly prefer CISSP certification for senior security positions. The certification's rigorous requirements—including five years of professional experience and passing a challenging exam—combined with mandatory continuing education, ensure that CISSP holders maintain current, relevant expertise, making it a trusted benchmark for cybersecurity competence worldwide.
Origin of CompTIA Security+
CompTIA Security+ was created by the Computing Technology Industry Association (CompTIA), a non-profit trade association established in 1982. The Security+ certification was first launched in 2002 as a response to the growing need for standardized cybersecurity knowledge in the IT industry. CompTIA developed this vendor-neutral certification to establish a baseline of competency for IT security professionals, covering essential principles and best practices that apply across different technologies and platforms rather than focusing on specific products or vendors.
Industry Value and Importance
Security+ is widely recognized as one of the most valuable entry-to-intermediate level cybersecurity certifications in the industry. It meets the ISO 17024 standard and is approved by the U.S. Department of Defense (DoD) as one of the required certifications for information assurance positions, making it particularly valuable for government contractors and military personnel. Employers value Security+ because it validates that holders possess practical, hands-on skills in areas such as threat detection, risk management, cryptography, and network security. The certification's vendor-neutral approach means certified professionals can work with any technology platform, making them versatile assets to organizations of all sizes and across all sectors.
Certified Information Security Manager (CISM)
Origin
The Certified Information Security Manager (CISM) certification was created by ISACA (Information Systems Audit and Control Association) in 2003. ISACA developed CISM to address the growing need for a credential specifically focused on information security management rather than technical security skills alone. The certification was designed to recognize professionals who design, manage, and oversee an enterprise's information security program, filling a gap between technical security certifications and the business-focused leadership roles that were becoming increasingly critical in organizations.
Industry Value
CISM is highly valued in the cybersecurity industry because it validates expertise in information security governance, risk management, incident management, and program development from a management perspective. The certification is particularly respected for senior-level and managerial positions, as it demonstrates an individual's ability to align security strategies with business goals and manage security programs effectively. Many organizations, especially in regulated industries and government sectors, specifically seek CISM-certified professionals for leadership roles, and the credential is often associated with higher salaries and advancement opportunities in information security management careers.
CompTIA PenTest+ Certification
Origin
CompTIA PenTest+ was created by the Computing Technology Industry Association (CompTIA), a non-profit trade association established in 1982 that develops vendor-neutral IT certifications. The PenTest+ certification was launched in 2018 to address the growing need for standardized skills validation in offensive security and penetration testing. CompTIA developed this certification in response to the increasing demand for qualified penetration testers and the lack of intermediate-level certifications that bridge the gap between foundational security knowledge and advanced ethical hacking skills. The certification was designed with input from cybersecurity professionals and industry experts to ensure it reflected real-world penetration testing practices and methodologies.
Industry Value and Importance
PenTest+ is valued in the penetration testing and cybersecurity industry because it validates hands-on technical skills in planning, scoping, and conducting penetration tests, as well as analyzing results and producing actionable reports. Unlike purely theoretical certifications, PenTest+ emphasizes practical abilities including vulnerability assessment, exploitation techniques, and post-exploitation activities across various systems and networks. Many organizations and government agencies recognize PenTest+ as meeting compliance requirements, with the certification approved under the DoD 8570.01-M directive for certain information assurance roles. Penetration testing companies value team members with PenTest+ certification because it demonstrates a standardized baseline of competency, helps establish credibility with clients, and shows commitment to professional development in offensive security practices.
CompTIA A+ Certification: Origin
The CompTIA A+ certification was created by the Computing Technology Industry Association (CompTIA), a non-profit trade association, and was first launched in 1993. CompTIA developed this certification to establish a vendor-neutral standard for validating foundational IT skills across different hardware and software platforms. The certification emerged during a time when the IT industry was rapidly expanding and needed a reliable way to verify that technicians possessed the essential knowledge and competencies required for entry-level IT support roles.
Industry Value and Importance
The CompTIA A+ certification is widely recognized as the industry standard for establishing a career in IT support and is often considered a prerequisite for entry-level positions. Employers value this certification because it demonstrates that holders possess practical skills in areas such as hardware troubleshooting, operating systems, networking, security, and mobile devices. Many organizations, including government agencies and Fortune 500 companies, require or strongly prefer A+ certification for their IT support staff. The credential also serves as a stepping stone to more advanced certifications and helps professionals demonstrate their commitment to maintaining current technical knowledge in an ever-evolving field.
Origin of CISA
The Certified Information Systems Auditor (CISA) certification was created by ISACA (Information Systems Audit and Control Association) in 1978. ISACA, founded in 1969, developed CISA to establish a standard for professionals working in IT audit, control, and security. The certification emerged in response to the growing need for qualified individuals who could audit information systems and ensure their proper governance, as organizations increasingly relied on computer systems for critical business operations.
Industry Value and Importance
CISA is widely recognized as one of the premier certifications for IT audit and control professionals. It demonstrates an individual's expertise in assessing vulnerabilities, implementing controls, and ensuring compliance with industry standards and regulations. Employers value CISA holders because the certification requires significant professional experience and passing a comprehensive exam covering domains like information system auditing, governance, and risk management. Many organizations, particularly in financial services, healthcare, and government sectors, specifically seek or require CISA certification for audit and compliance roles, making it a valuable credential for career advancement in IT governance and security.
CompTIA Network+ Certification
Origin and Background
The CompTIA Network+ certification was created by the Computing Technology Industry Association (CompTIA), a non-profit trade association established in 1982. Network+ was launched in 1999 as a vendor-neutral certification designed to validate foundational networking skills across all platforms and technologies. CompTIA developed this certification in response to the IT industry's need for a standardized way to assess the competency of networking professionals, particularly as internet connectivity and network infrastructure became increasingly critical to business operations.
Industry Value and Importance
Network+ is widely valued in the IT industry because it demonstrates that holders possess essential networking knowledge required for troubleshooting, configuring, and managing wired and wireless networks. The certification is vendor-neutral, meaning it covers universal networking concepts rather than proprietary technologies, making it applicable across diverse IT environments. Many organizations, including the U.S. Department of Defense, recognize Network+ as meeting baseline requirements for networking positions. It serves as a stepping stone for IT professionals pursuing careers in network administration, help desk support, and systems administration, and is often considered a prerequisite for more advanced networking certifications.
Certified Ethical Hacker (CEH) Certification
Origin and Creation
The Certified Ethical Hacker (CEH) certification was created by the International Council of E-Commerce Consultants (EC-Council) in 2003. EC-Council, founded by Jay Bavisi, developed this certification in response to the growing need for standardized training in ethical hacking and penetration testing methodologies. The program was designed to legitimize the practice of "white hat" hacking by establishing a professional framework for security professionals who need to think like malicious hackers in order to better defend their organizations' systems and networks.
Industry Value and Importance
The CEH certification is widely recognized and valued in the cybersecurity industry because it validates a professional's knowledge of current hacking techniques, tools, and methodologies from an attacker's perspective. Many government agencies, including the U.S. Department of Defense, and numerous private sector organizations recognize CEH as meeting their information assurance training requirements. The certification demonstrates that holders understand how to identify vulnerabilities and weaknesses in systems, making them valuable assets for organizations seeking to strengthen their security posture through proactive testing and assessment.
- New England Aquarium