SANS Institute: Difference between revisions
imported>Entranced98 m Reverted edit by Toby Foxer (talk) to last version by Discospinster |
imported>Cmr08 put punctuation before the <ref> tags per WP:REFPUNCT |
||
| Line 37: | Line 37: | ||
==Programs== | ==Programs== | ||
SANS sponsors several community resources including the Internet Storm Center, an internet monitoring system operated by volunteer security practitioners that provides analysis of emerging threats and has been recognized for identifying novel attack patterns.<ref>{{Cite web |last=Pauli |first=D |date=November 16, 2016 |title=DDoS back-off timer tickles SANS ISC's 'unbearable lightness of scanning' |url=https://www.theregister.com/2016/11/16/ddos_backoff_timer_tickles_sans_iscs_unbearable_lightness_of_scanning/ |website=The Register}}</ref> The SANS Reading Room maintains an extensive archive of information security research documents that serves as a key resource for security professionals. SANS also co-founded the Center for Internet Security and provides cybersecurity news through various digital publications. | |||
SANS offers news and analysis through Twitter feeds and e-mail newsletters. Additionally, there is a weekly news and vulnerability digest available to subscribers.<ref>{{cite book|last1=Messier|first1=Ric|title=GSEC: GIAC Security Essentials Certification|date=2014|publisher=McGraw-Hill Education|location=New York|isbn=978-0-07-181962-6|page=7}}</ref> | SANS offers news and analysis through Twitter feeds and e-mail newsletters. Additionally, there is a weekly news and vulnerability digest available to subscribers.<ref>{{cite book|last1=Messier|first1=Ric|title=GSEC: GIAC Security Essentials Certification|date=2014|publisher=McGraw-Hill Education|location=New York|isbn=978-0-07-181962-6|page=7}}</ref> | ||
| Line 44: | Line 44: | ||
When originally organized in 1989,<ref>{{cite web|url=http://www.sans.org/about/sans.php|title=SANS Institute: About|work=sans.org|access-date=2008-12-16|archive-date=2013-04-12|archive-url=https://web.archive.org/web/20130412014412/http://www.sans.org/about/sans.php|url-status=dead}}</ref> SANS training events functioned like traditional technical conferences showcasing technical presentations. By the mid-1990s, SANS offered [[Convention (meeting)|event]]s which combined training with [[trade fair|tradeshow]]s. Beginning in 2006, SANS offered asynchronous online training (SANS OnDemand) and a virtual, synchronous classroom format (SANS vLive). Free webcasts and email newsletters (@Risk, Newsbites, Ouch!) have been developed in conjunction with security vendors. The actual content behind SANS training courses and training events remains "vendor-agnostic". Vendors cannot pay to offer their own official SANS course, although they can teach a SANS "hosted" event via sponsorship. | When originally organized in 1989,<ref>{{cite web|url=http://www.sans.org/about/sans.php|title=SANS Institute: About|work=sans.org|access-date=2008-12-16|archive-date=2013-04-12|archive-url=https://web.archive.org/web/20130412014412/http://www.sans.org/about/sans.php|url-status=dead}}</ref> SANS training events functioned like traditional technical conferences showcasing technical presentations. By the mid-1990s, SANS offered [[Convention (meeting)|event]]s which combined training with [[trade fair|tradeshow]]s. Beginning in 2006, SANS offered asynchronous online training (SANS OnDemand) and a virtual, synchronous classroom format (SANS vLive). Free webcasts and email newsletters (@Risk, Newsbites, Ouch!) have been developed in conjunction with security vendors. The actual content behind SANS training courses and training events remains "vendor-agnostic". Vendors cannot pay to offer their own official SANS course, although they can teach a SANS "hosted" event via sponsorship. | ||
In 1999, | SANS training has evolved from traditional technical conferences to include asynchronous online training and virtual classrooms. The organization maintains a vendor-agnostic approach to content development. In 1999, SANS formed the Global Information Assurance Certification (GIAC) program, which provides certifications that are consistently ranked among the most valuable in the cybersecurity industry.<ref>{{Cite web |last=Grimes |first=R.A. |date=January 10, 2023 |title=The top cybersecurity certifications for 2023 |url=https://www.csoonline.com/article/568999/the-top-cybersecurity-certifications-for-2023.html |website=CSO Online}}</ref> The institute also developed NetWars, a cyberattack simulation platform used by U.S. military organizations including the Air Force and Army. | ||
It has developed and operates ''NetWars'', a suite of interactive learning tools for simulating scenarios such as cyberattacks. NetWars is in use by the US Air Force<ref>{{Cite news|title = Stepped Up Cyberthreats Prompt Air Force To Rethink Training, Acquisitions|url = http://www.afcea.org/content/?q=stepped-cyberthreats-prompt-air-force-rethink-training-acquisitions|newspaper = Afcea International|access-date = 2015-11-17}}</ref> and the US Army.<ref>{{Cite web|title = Strengthening the nation's defense against hackers|url = http://www.cbsnews.com/news/strengthening-the-nations-defense-against-hackers/2/|website = www.cbsnews.com| date=26 April 2015 |access-date = 2015-11-17}}</ref><ref>{{Cite news|title = CyberCity allows government hackers to train for attacks|url = https://www.washingtonpost.com/investigations/cybercity-allows-government-hackers-to-train-for-attacks/2012/11/26/588f4dae-1244-11e2-be82-c3411b7680a9_story.html|newspaper = The Washington Post|date = 2012-11-26|access-date = 2015-11-17|issn = 0190-8286|language = en-US|first = Robert Jr|last = O'Harrow}}</ref> | It has developed and operates ''NetWars'', a suite of interactive learning tools for simulating scenarios such as cyberattacks. NetWars is in use by the US Air Force<ref>{{Cite news|title = Stepped Up Cyberthreats Prompt Air Force To Rethink Training, Acquisitions|url = http://www.afcea.org/content/?q=stepped-cyberthreats-prompt-air-force-rethink-training-acquisitions|newspaper = Afcea International|access-date = 2015-11-17}}</ref> and the US Army.<ref>{{Cite web|title = Strengthening the nation's defense against hackers|url = http://www.cbsnews.com/news/strengthening-the-nations-defense-against-hackers/2/|website = www.cbsnews.com| date=26 April 2015 |access-date = 2015-11-17}}</ref><ref>{{Cite news|title = CyberCity allows government hackers to train for attacks|url = https://www.washingtonpost.com/investigations/cybercity-allows-government-hackers-to-train-for-attacks/2012/11/26/588f4dae-1244-11e2-be82-c3411b7680a9_story.html|newspaper = The Washington Post|date = 2012-11-26|access-date = 2015-11-17|issn = 0190-8286|language = en-US|first = Robert Jr|last = O'Harrow}}</ref> | ||
| Line 58: | Line 58: | ||
SANS continues to offer free security content via the SANS Technology Institute Leadership Lab<ref>{{cite web|url=http://www.sans.edu/resources/securitylab|title=STI Information Security Laboratory|work=sans.edu|access-date=2007-07-14|archive-date=2010-12-20|archive-url=https://web.archive.org/web/20101220153435/http://www.sans.edu/resources/securitylab/|url-status=dead}}</ref> and IT/Security related leadership information.<ref>{{cite web|url=http://www.sans.edu/resources/leadershiplab|title=STI Information Security Leadership Laboratory|work=sans.edu|access-date=2007-05-10|archive-date=2010-12-16|archive-url=https://web.archive.org/web/20101216205851/http://www.sans.edu/resources/leadershiplab/|url-status=dead}}</ref> | SANS continues to offer free security content via the SANS Technology Institute Leadership Lab<ref>{{cite web|url=http://www.sans.edu/resources/securitylab|title=STI Information Security Laboratory|work=sans.edu|access-date=2007-07-14|archive-date=2010-12-20|archive-url=https://web.archive.org/web/20101220153435/http://www.sans.edu/resources/securitylab/|url-status=dead}}</ref> and IT/Security related leadership information.<ref>{{cite web|url=http://www.sans.edu/resources/leadershiplab|title=STI Information Security Leadership Laboratory|work=sans.edu|access-date=2007-05-10|archive-date=2010-12-16|archive-url=https://web.archive.org/web/20101216205851/http://www.sans.edu/resources/leadershiplab/|url-status=dead}}</ref> | ||
== Courses | == Courses and certifications == | ||
SANS offers more than 85 | SANS offers more than 85 cybersecurity courses covering topics such as penetration testing, incident response, cloud security, and digital forensics. The curriculum includes both technical training and security leadership education. GIAC certifications validate skills in specific security domains and are widely recognized for their rigor<ref>{{Cite web |last=Verton |first=D |date=February 16, 2004 |title=The 10 most difficult IT certifications |url=https://www.computerworld.com/article/2565349/the-10-most-difficult-it-certifications.html |website=Computerworld}}</ref> and relevance to current security challenges. | ||
== Global impact and recognition == | |||
SANS maintains significant influence on international cybersecurity practices. The institute's curriculum aligns with the U.S. National Institute of Standards and Technology (NIST) NICE Cybersecurity Workforce Framework,<ref>{{Cite web |last=Petersen |first=R |date=2020 |title=Workforce Framework for Cybersecurity (NICE Framework) |url=https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-181r1.pdf |website=National Institute of Standards and Technology}}</ref> and its training content addresses the core cybersecurity threats and priorities identified in official European Union cybersecurity frameworks.<ref>{{Cite web |last=Ifigeneia |first=Lella |date=October 2023 |title=ENISA THREAT LANDSCAPE 2023 |url=https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023 |website=European Union Agency for Cybersecurity}}</ref> The organization has been cited as a key solution to addressing the global cybersecurity skills gap,<ref>{{Cite web |last=Finkle |first=J |date=March 19, 2012 |title=U.S. government, companies scramble to find cybersecurity pros |url=https://www.reuters.com/article/usa-cybersecurity-jobs/update-1-u-s-government-companies-scramble-to-find-cybersecurity-pros-idUSL2E8EJ9FQ20120319 |website=Reuters}}</ref> with its training programs helping to alleviate workforce shortages worldwide. | |||
==Awards | == Criticism and controversy == | ||
The SANS Institute has faced criticism regarding the high cost of its training programs and certifications, with public debates about their return on investment for individual professionals.<ref>{{Cite web |last=Mello |first=J.P. |date=May 5, 2021 |title=Is that pricey cybersecurity certification worth it? |url=https://www.forbes.com/sites/forbestechcouncil/2021/05/05/is-that-pricey-cybersecurity-certification-worth-it/ |website=Forbes}}</ref> The ethical nature of some course content has also been questioned. For instance, courses covering "active defense" and "hack back" techniques have been noted to sit in a legal and ethical grey area.<ref>{{Cite web |last=Leyden |first=J |date=October 12, 2017 |title=SANS teaches infosec pros to hack back (and get away with it) |url=https://www.theregister.com/2017/10/12/sans_hack_back_course/ |website=The Register}}</ref> In a notable incident that challenged the institute's security posture, SANS confirmed a 2020 data breach that compromised the personal information of thousands of users.<ref>{{Cite web |last=Gatlan |first=S |date=December 3, 2020 |title=SANS confirms data breach after hacker steals info for 28,000 users |url=https://www.bleepingcomputer.com/news/security/sans-confirms-data-breach-after-hacker-steals-info-for-28-000-users/ |website=Bleeping Computer}}</ref> | |||
==Awards programs== | |||
SANS acknowledges the contributions made by exceptional information security professionals, through its annual awards programs.<ref>{{Cite web |title=Cybersecurity Awards {{!}} SANS Institute |url=https://www.sans.org/about/awards/ |access-date=2024-02-08 |website=www.sans.org}}</ref> | SANS acknowledges the contributions made by exceptional information security professionals, through its annual awards programs.<ref>{{Cite web |title=Cybersecurity Awards {{!}} SANS Institute |url=https://www.sans.org/about/awards/ |access-date=2024-02-08 |website=www.sans.org}}</ref> | ||
*Difference Makers Awards (DMA) celebrates individuals or teams whose efforts and contributions have resulted in significant advancements in cybersecurity defense capabilities and who are contributing back to the information security community in ways that deserve recognition.<ref>{{Cite press release |last=Institute |first=SANS |title=SANS Announces the 2021 Winners of the Difference Makers Awards |url=https://www.prnewswire.com/news-releases/sans-announces-the-2021-winners-of-the-difference-makers-awards-301441165.html |access-date=2024-02-11 |website=www.prnewswire.com |language=en}}</ref><ref>{{Cite web |date=2020-10-01 |title=Nominations Now Open for the SANS 2020 Difference Makers Awards |url=https://apnews.com/article/technology-computer-and-data-security-computing-and-information-technology-fca61e84994fb8a3850bca45600fcdc8 |access-date=2024-02-11 |website=AP News |language=en-US}}</ref> | *Difference Makers Awards (DMA) celebrates individuals or teams whose efforts and contributions have resulted in significant advancements in cybersecurity defense capabilities and who are contributing back to the information security community in ways that deserve recognition.<ref>{{Cite press release |last=Institute |first=SANS |title=SANS Announces the 2021 Winners of the Difference Makers Awards |url=https://www.prnewswire.com/news-releases/sans-announces-the-2021-winners-of-the-difference-makers-awards-301441165.html |access-date=2024-02-11 |website=www.prnewswire.com |language=en}}</ref><ref>{{Cite web |date=2020-10-01 |title=Nominations Now Open for the SANS 2020 Difference Makers Awards |url=https://apnews.com/article/technology-computer-and-data-security-computing-and-information-technology-fca61e84994fb8a3850bca45600fcdc8 |access-date=2024-02-11 |website=AP News |language=en-US}}</ref> | ||
Latest revision as of 09:43, 4 November 2025
Template:Short description Template:Multiple issues Script error: No such module "For". Script error: No such module "Infobox".Template:Template otherScript error: No such module "Check for unknown parameters".Template:Main other The SANS Institute (officially the Escal Institute of Advanced Technologies) is a private U.S. for-profit company[1] founded in 1989 that specializes in information security, cybersecurity training, and selling certificates. Topics available for training include cyber and network defenses, penetration testing, incident response, digital forensics, and auditing.[2] The information security courses are developed through a consensus process involving administrators, security managers, and information security professionals. The courses cover security fundamentals and technical aspects of information security. The institute has been recognized for its training programs[3] and certification programs.[4] Per 2021, SANS is the world’s largest cybersecurity research and training organization.[5] SANS is an acronym for SysAdmin, Audit, Network, and Security.[6]
Programs
SANS sponsors several community resources including the Internet Storm Center, an internet monitoring system operated by volunteer security practitioners that provides analysis of emerging threats and has been recognized for identifying novel attack patterns.[7] The SANS Reading Room maintains an extensive archive of information security research documents that serves as a key resource for security professionals. SANS also co-founded the Center for Internet Security and provides cybersecurity news through various digital publications.
SANS offers news and analysis through Twitter feeds and e-mail newsletters. Additionally, there is a weekly news and vulnerability digest available to subscribers.[8]
Training
When originally organized in 1989,[9] SANS training events functioned like traditional technical conferences showcasing technical presentations. By the mid-1990s, SANS offered events which combined training with tradeshows. Beginning in 2006, SANS offered asynchronous online training (SANS OnDemand) and a virtual, synchronous classroom format (SANS vLive). Free webcasts and email newsletters (@Risk, Newsbites, Ouch!) have been developed in conjunction with security vendors. The actual content behind SANS training courses and training events remains "vendor-agnostic". Vendors cannot pay to offer their own official SANS course, although they can teach a SANS "hosted" event via sponsorship.
SANS training has evolved from traditional technical conferences to include asynchronous online training and virtual classrooms. The organization maintains a vendor-agnostic approach to content development. In 1999, SANS formed the Global Information Assurance Certification (GIAC) program, which provides certifications that are consistently ranked among the most valuable in the cybersecurity industry.[10] The institute also developed NetWars, a cyberattack simulation platform used by U.S. military organizations including the Air Force and Army.
It has developed and operates NetWars, a suite of interactive learning tools for simulating scenarios such as cyberattacks. NetWars is in use by the US Air Force[11] and the US Army.[12][13]
Faculty
The majority of SANS faculty are not SANS employees, but industry professionals and experts in the field of information security.[14][15] The faculty is organized into six different levels: Mentors, Community, Certified Instructors, Principal Instructors, Senior Instructors, and Fellows.[16]
SANS Technology Institute
Template:As of, SANS established the SANS Technology Institute, an accredited college based on SANS training and GIAC certifications. On November 21, 2013, SANS Technology Institute was granted regional accreditation by the Middle States Commission on Higher Education.[17]
SANS Technology Institute focuses exclusively on cybersecurity, offering a Master of Science degree program in Information Security Engineering (MSISE), five post-baccalaureate certificate programs (Penetration Testing & Ethical Hacking, Incident Response, Industrial Control Systems, Cyber Defense Operations, and Cybersecurity Engineering (Core), and an upper-division undergraduate certificate program (Applied Cybersecurity). SANS later launched a bachelor's degree program in Applied Cybersecurity as well.[18]
SANS continues to offer free security content via the SANS Technology Institute Leadership Lab[19] and IT/Security related leadership information.[20]
Courses and certifications
SANS offers more than 85 cybersecurity courses covering topics such as penetration testing, incident response, cloud security, and digital forensics. The curriculum includes both technical training and security leadership education. GIAC certifications validate skills in specific security domains and are widely recognized for their rigor[21] and relevance to current security challenges.
Global impact and recognition
SANS maintains significant influence on international cybersecurity practices. The institute's curriculum aligns with the U.S. National Institute of Standards and Technology (NIST) NICE Cybersecurity Workforce Framework,[22] and its training content addresses the core cybersecurity threats and priorities identified in official European Union cybersecurity frameworks.[23] The organization has been cited as a key solution to addressing the global cybersecurity skills gap,[24] with its training programs helping to alleviate workforce shortages worldwide.
Criticism and controversy
The SANS Institute has faced criticism regarding the high cost of its training programs and certifications, with public debates about their return on investment for individual professionals.[25] The ethical nature of some course content has also been questioned. For instance, courses covering "active defense" and "hack back" techniques have been noted to sit in a legal and ethical grey area.[26] In a notable incident that challenged the institute's security posture, SANS confirmed a 2020 data breach that compromised the personal information of thousands of users.[27]
Awards programs
SANS acknowledges the contributions made by exceptional information security professionals, through its annual awards programs.[28]
- Difference Makers Awards (DMA) celebrates individuals or teams whose efforts and contributions have resulted in significant advancements in cybersecurity defense capabilities and who are contributing back to the information security community in ways that deserve recognition.[29][30]
- Michael J. Assante ICS Security Lifetime Achievement Award acknowledges individuals who have made exceptional contributions to the security of Industrial Control Systems (ICS) on a global scale. Recipients are celebrated for their efforts to bridge the gap between IT and operational technology (OT), significantly enhancing awareness and implementations of cyber-secure ICS.[31][32]
See also
References
External links
- Template:Official website
- SANS Technology Institute
- SANS Institute trade name information from Maryland Department of Assessments and Taxation
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".
- ↑ Script error: No such module "citation/CS1".