顯示具有 證照相關 標籤的文章。 顯示所有文章
顯示具有 證照相關 標籤的文章。 顯示所有文章

ISO17025 - 實驗室認證



ISO17025標準是由國際標準化組織ISO/CASCO(國際標準化組織/合格評定委員會)制定的實驗室管理標準,該標準的前身是ISO/IEC導則 25:1990《校準和檢測實驗室能力的要求》。國際上對實驗室認可進行管理的組織是「國際實驗室認可合作組織(ILAC)」。

ISO17025標準主要包括:定義、組織和管理、質量體系、審核和評審、人員、設施和環境、設備和標準物質、量值溯源和校準、校準和檢測方法、樣品管理、 記錄、證書和報告、校準或檢測的分包、外部協助和供給、投訴等內容。該標準中核心內容為設備和標準物質、量值溯源和校準、校準和檢測方法、樣品管理,這些 內容重點是評價實驗室校準或檢測能力是否達到預期要求。

CCE(Certified Computer Examiner) - 電腦鑑識調查專家

受惠於網路無遠弗界的便利性,企業e化也愈來愈受到重視與普及。根據統計,企業內的資料有85%是以電子化的方式進行存放,這其中,新產生的資料更有高達93%是電子化的,而且約有75%的資料從來未曾以紙張的形式印出來過。

這意謂著一件事實,隨著人們與企業愈來愈依賴電腦科技,當所有的資料都存放在電腦中時,資訊安全的重要性與日俱增,尤其是因資料外洩而帶來的企業損失更為可觀。

日前,McAfee引述普渡大學所進行一項由資訊保險暨安全教育研究中心的研究員檢驗CIO問卷結果指出,去年全球因為資料外洩就造成了高達1兆美元的企 業損失。這項分析是由來自美、英、德、日、中、印、巴西及杜拜等等國家的800位CIO的受訪結果,在受訪的企業中,去年總計有高達46億美元的IP價值 損失,並花費約6億美元來補救相關的資料外洩問題。

需要特別提出的是,有39%受訪者認為,在現有經濟景氣下重要資料也比過去更容易外洩,換言之,企業需要上緊發條來面對日新月異的網路犯罪手段。然而,因 內部人員疏忽或惡意而導致的意外事件,也不容忽視,前不久香港消防處才發生了內部文件外洩事件,部分消防員的個人資料和考核報告,都可以在網上下載。 

雖然消防處已經針對此一事件明定了作業流程,往後內部人員若要將限閱或機密文件帶離辦公室處理,就必須向上級申請及做出相應的保密措施,卻也只能亡羊補牢,顯示出內部資料外洩的重要性。
 
電腦鑑識新興市場  
資料外洩、金融舞弊事件層出不窮,防範資安犯罪當然不能再墨守成規,企業事先建置資安防護的相關解決方案來進行預防,事後找出問題的癥結點,將原兇繩之以法,才能收到嚇阻不法行為的功效。 

不過,就蒐證的技巧而言,隨著資訊的發展也有了不同於傳統以實體證據例如指紋或彈道為主的鑑識手法-數位鑑識。這是利用科學驗證的方式來加以蒐集、分析、 調查數位證據,並且提供數據還原,例如在各種儲存媒體與網路傳輸下被刪除或移走的資料將其還原,進而提供給法院採信的一種工具。 

而電腦鑑識則被定義為以周延的方法及程序保存、保存、萃取、記載及解讀電腦媒體證據與分析其成因的科學。數位鑑識技術的發展已經十多年,在國外的運用已經 相當成熟,甚至也有相關的法規支持,例如美國和歐洲分別施行Sarbannes-Oxley和Basel II法案後,以數位鑑識作為風險管理的公司便愈來愈多。而在新加坡、香港等地電腦鑑識的需求也蓬勃發展,不過台灣仍屬於啟蒙階段。 

晨宇資訊總經理黃蕙菁指出,在台灣遇到網路犯罪問題,最好的途徑是報請刑事警察局偵九隊或是各縣市電腦犯罪專責組偵查,然而許多企業在遇到問題時,都通常 都不願意主動報案,原因之一是不想讓事件曝光,一旦讓警方涉入不但會變成人人關注的大新聞,無形中對企業形象造成毀損,而且司法程序也可能拖上好長一段時間。 

「但是,這對資安防範是沒有助益的。企業若是考量到名譽問題,不妨可以仿效國外,多數的企業傾向自行設立鑑識團隊來追蹤或抓出商業間諜、大型的犯罪組織、 詐欺與散發垃圾郵件的歹徒,或是找尋風險管理公司尋求協助,儘管這會為企業成本帶來負擔,但比起名譽損失或鉅額的賠償金,這些投資仍然較為划算。」 

CCE專業認證  
黃蕙菁表示,這就是晨宇資訊為什麼想要引進電腦鑑識調查專家(Certified Computer Examiner,CCE)的主要原因,企業需要更全面性的防範資安,設立獨立運作的鑑識團隊。



而對IT人員而言,電腦鑑識調查也是另一項轉職的出路,因為鑑識調查需要對IT具有一定程度的瞭解,而且還需要有調查與分析的能力,以及需有足夠的法律知識、專業與權威性,這通常需要有足夠的經驗才能做得到,IT人員至少就具備了第一項基本條件。 

CCE認證是由國際電腦鑑識調查協會(The International Society of Forensic Computer Examiners,ISFCE)所主導的專業認證,目前已有超過千位以上的電腦鑑識調查專家取得CCE認證,而且ISECE已在2008年4月成為美國 刑事鑑識實驗室主管協會(ASCLD/LAB)之數位鑑識實驗室的合作夥伴。 

在台灣,經濟部標準檢驗局所督導之財團法人全國認證基金會早在民國94年,便與美國刑事鑑識實驗室主管協會簽署合作協議備忘錄,希望藉由相互合作發展與共 同評鑑的方式,加強國內鑑識科學實驗室技術發展的專業性與國際性,延伸評鑑後的認證效益,使得彼此雙方實驗室於未來如經共同評鑑後可以獲得相互的認可。換 言之,美國刑事鑑識實驗室主管協會已經受到了國內標檢局的認可,是相當具有公信力的獨立單位。 

這門課程的內容從道德規範、鑑識人員基本常識到法律的隱私問題以及如何讓取得或保存的資料過程具有法律上的效益,並且能夠精準的針對問題來進行事後的分析 都含括在內。CCE在人員資格需求上相當特別,除了要具有基本的資訊安全概念及系統管理、網路管理等基本能力之外,還要求要身家清白,沒有刑事犯罪紀錄, 並且能夠遵守道德規範。 

「這就好像是警察或法官的角色永遠都必須保持立場中立、不偏頗的道理是一樣的,不然就會遭人質疑公正性。」黃蕙菁說。

二階段考試  
取得電腦鑑識調查專家需要通過幾項關卡,首先須上滿五天的課程,在最後一天的課程結束後,立即會舉行一場線上的測試,總共是75題複選題,答題時間是45 分鐘,需要答對80%才算及格。通過了之後,國際電腦鑑識調查協會有實作測驗,受試者需在90天內完成全部測驗。換言之,從課程開始至取得認證約莫至少需 要4個月的時間。

黃蕙菁指出,CCE的課程內容需要用到幾項工具,例如SMART、Simple Carver、Passware Kit以及Forensic Tool Kit(Demo version),市價約2,500美金,而這些工具晨宇已經事先取得授權,完全無須額外再支付費用。目前一般學員的費用是120,000元,在政府單位 或警調單位服務的人員則有折扣優惠為98,000元。 

根據瞭解,目前在國外具有電腦鑑識調查專家資格的人員,年薪約在400萬左右,台灣行情雖然還不及國外,但在經濟不景氣以及工作職缺釋出減少下,或許也是另一項投資自己或是轉職的方向。 

但黃蕙菁也提醒企業,若是想直接讓IT人員負責電腦鑑識採證,藉以節省人事成本是行不通的作法,雖然所有的鑑識數據都能在電腦中被找到,但是沒有照著一定的條件、流程或作法採集來的資料,甚至不具有採信上的效益,而這樣的採證也就失去了意義。 

專業不能取代  
「在國外的報導中,企業最常犯的錯誤之一就是讓沒有經過專業鑑識的內部IT人員直接委派進行數位鑑識調查。有個案例可以清楚的說明這種作法並不妥當。假設 某企業懷擬某台電腦上的資料存有證據,而且對於現在面臨的案件相當重要,因此這家企業的法務人員要求IT人員去列印、下載或儲存這些資料在可攜式媒體上, 而且IT人員也照著要求執行了,看起來這些過程都很妥當,而且資料也被收集回來了,成本也保持在最低的限度,但是卻是很糟糕的決策。」 

黃蕙菁引述專家觀點指出問題的徵結,首先這些檔案內容只是資料而不是證據,除非IT人員有經過電腦鑑識的認證,並且接受過證據保存程序、採集的訓練,否則他們並不懂得圍起「封鎖線」,保留現場的完整性。 

而且就算正確的證據採集技術被使用,但是在採集的當下很有可能就改變了資料的樣貌,例如在列印或存檔時,Meta data無可避免地會被改變,但Meta data在鑑識上卻是很重要的線索,換言之,證據是受到破壞了。最後,重新打開電腦也會改變電腦內的快取記憶體或暫存檔,這又會進一步破壞或損掉電腦上留 存的證據。 

雖然,一個優秀的電腦鑑識人員是能夠讓被損壞的證據再還原回來的,但這要花上數位的時間與成本,這比起由專業人員來做為首次的資料保存的成本要高出許多, 而且也不是每一項證據都能保證可以還原,最重要的一點是,讓IT人員來採集證據而不請鑑識人員來處理,其實是違反專業倫理,理想的作法是尋找經過認證的外 部人員來進行電腦採集。 

結語  
做好資安防護工作是現今所有企業都須積極面對的問題,國際電腦鑑識調查協會以第三方獨立機構的立場,設計出電腦鑑識調查專家課程,目的就是教導有心朝向此 領域發展的人員,如何善用工具,找出具有法律效益的證據,協助企業有效防範。這類的證照在台灣才剛推出不久,有心朝向此領域的IT人員不妨也可以多加參酌研究。


轉自 網管人

電腦鑑識相關證書


CCCI -- Certified Computer Crime Investigator (Basic)
The CCCI is one of two computer forensic certifications aimed at law enforcement and private IT professionals seeking to specialize in the investigative side of the field. Basic requirements include two years of experience (or a college degree, plus one year of experience), 18 months of investigative experience, 40 hours of computer crimes training and documented experience from at least 10 investigated cases.
Source: High Tech Crime Network certifications

CCCI -- Certified Computer Crime Investigator (Advanced)
The CCCI is one of two computer forensic certifications aimed at law enforcement and private IT professionals seeking to specialize in the investigative side of the field. Advanced requirements include bump experience to three years (or a college degree, plus two years of experience), four years of investigations, 80 hours of training and involvement as a lead investigator in 20 cases, with involvement in over 60 cases overall.
Source: High Tech Crime Network certifications

CCFT -- Certified Computer Forensic Technician (Basic)
The CCFT is one of two computer forensic certifications aimed at law enforcement and private IT professionals seeking to specialize in the investigative side of the field. Basic requirements include three years of experience (or a college degree, plus one year of experience), 18 months of forensics experience, 40 hours of computer forensics training and documented experience from at least 10 investigated cases.
Source: High Tech Crime Network certifications

CCFT -- Certified Computer Forensic Technician (Advanced)
The CCFT is one of two computer forensic certifications aimed at law enforcement and private IT professionals seeking to specialize in the investigative side of the field. Advanced requirements include three years of experience (or a college degree, plus two years of experience), four years of investigations, 80 hours of training and involvement as a lead investigator in 20 cases with involvement in over 60 cases overall.
Source: High Tech Crime Network certifications

CIFI -- Computer Information Forensics Investigator
The CIFI identifies senior management personnel, law enforcement officer, IT professionals, lawyers and others, who capable of finding and detecting weaknesses and vulnerabilities in computer systems and networks by using specific tools and related knowledge. It is also provide related personnel in searching the source of criminal documents and digital materials to effectively collect, handle, process and preserve computer forensics evidence. To obtain CIFI certification, a candidate needs to successfully complete one exam.
Source: International ICT Council

CEECS -- Certified Electronic Evidence Collection Specialist Certification
The CEECS identifies individuals who successfully complete the CEECS certification course. No prerequisites are required to attend the course, which covers the basics of evidence collection in addition to highly technical terminology, theories and techniques.
Source: International Association of Computer Investigative Specialists

CFCE -- Certified Forensic Computer Examiner
The International Association of Computer Investigative Specialists (IACIS) offers this credential to law enforcement and private industry personnel alike. Candidates must have broad knowledge, training or experience in computer forensics, including forensic procedures and standards, as well as ethical, legal and privacy issues. Certification includes both hands-on performance-based testing as well as a written exam.
Source: International Association of Computer Investigative Specialists

CERI-CFE -- Computer Forensic Examination
The CERI-CFE seeks to identify law enforcement officials with basic computer crime investigation experience and training. Requirements include two years of computer investigation/debugging, one year of Microsoft platform analysis, six months of non-Microsoft platform analysis, 40 hours of approved training, a written exam and successful completion of hands-on exercises.
Source: Cyber Enforcement Resources Inc.

CERI-ACFE -- Advanced Computer Forensic Examination
The CERI-ACFE seeks to identify law enforcement officials with advanced computer crime investigation experience and training. Requirements include two years of computer investigation/debugging, four years of Microsoft platform analysis, two years of non-Microsoft platform analysis, 80 hours of approved training, a written exam and successful completion of hands-on exercises.
Source: Cyber Enforcement Resources Inc.

CCE -- Certified Computer Examiner
The CCE, offered by the Southeast Cybercrime Institute at Kennesaw State University in partnership with Key Computer Service, seeks to identify individuals with no criminal record who have appropriate computer forensics training or experience, including evidence gathering, handling and storage. In addition, candidates must pass an online examination and successfully perform a hands-on examination on three test media.
Source: Key Computer Service

CSFA -- CyberSecurity Forensic Analyst
The CSFA aims to identify individuals who are interested in information technology security issues, especially at the hardware level. Prerequisites include at least one certification in computer and software support, networking or security (such as CompTIA's A+, Microsoft's MCSA or MCSE, or Cisco's CCNA), successful completion of an introductory and an advanced computer forensics course offered through the CyberSecurity Institute and no criminal record.
Source: CyberSecurity Institute

GCFA -- GIAC Certified Forensics Analyst
This cert program seeks to identify individuals who can demonstrate knowledge of and the ability to manage and protect important information systems and networks. The SANS organization is well known for its timely, focused, and useful security information and certification program. A shining star on this landscape, the GIAC program aims at serious, full-time security professionals responsible for designing, implementing and maintaining a state-of-the-art security infrastructure that may include incident handling and emergency response team management.
Source: Global Information Assurance Certification

CHFI -- Computer Hacking Forensic Investigator
The CHFI is geared toward personnel in law enforcement, defense, military, information technology, law, banking and insurance, among others. To obtain CHFI certification, a candidate needs to successfully complete one exam.
Source: EC-Council

PCI -- Professional Certified Investigator
This is a high-level certification from the American Society for Industrial Security (ASIS is also home to the CPP and PSP certifications) for those who specialize in investigating potential cybercrimes. Thus, in addition to technical skills, this certification concentrates on testing individuals' knowledge of legal and evidentiary matters required to present investigations in a court of law, including case management, evidence collection and case presentation. This cert requires five years of investigation experience, with at least two years in case management (a bachelor's degree or higher counts for up to two years of such experience) and a clean legal record for candidates.
Source: ASIS International

CCSA -- Certification in Control Self-Assessment
The CCSA demonstrates knowledge of internal control self-assessment procedures, primarily aimed at financial and records controls. This cert is of primary interest to those professionals who must evaluate IT infrastructures for possible threats to financial integrity, legal requirements for confidentiality and regulatory requirements for privacy.
Source: Institute of Internal Auditors

CIA -- Certified Internal Auditor
The CIA cert demonstrates knowledge of professional financial auditing practices. The cert is of primary interest to financial professionals responsible for auditing IT practices and procedures, as well as standard accounting practices and procedures to insure the integrity and correctness of financial records, transaction logs and other records relevant to commercial activities.
Source: Institute of Internal Auditors

CFE -- Certified Fraud Examiner
The CFE demonstrates ability to detect financial fraud and other white-collar crimes. This cert is of primary interest to full-time security professionals in law, law enforcement or those who work in organization with legal mandates to audit for possible fraudulent or illegal transactions and activities (such as banking, securities trading or classified operations).
Source: Association of Certified Fraud Examiners

CISA -- Certified Information Systems Auditor
The CISA demonstrates knowledge of IS auditing for control and security purposes. This cert is of primary interest to IT security professionals responsible for auditing IT systems, practices and procedures to make sure organizational security policies meet governmental and regulatory requirements, conform to best security practices and principles, and meet or exceed requirements stated in an organization's security policy.
Source: Information Systems Audit and Control Association

EnCE -- EnCase Certified Examiner
The EnCase® Certified Examiner (EnCE®) program certifies both public and private sector professionals in the use of Guidance Software's EnCase computer forensic software. EnCE® certification acknowledges that professionals have mastered computer investigation methodology as well as the use of EnCase during complex computer examinations. Recognized by both the law enforcement and corporate communities as a symbol of in-depth computer forensics knowledge, EnCE® certification illustrates that an investigator is a skilled computer examiner.
Source: guidancesoftware

ACE -- AccessData Certified Examiner
AccessData certifications are obtained by completing a multiple choice exam which consists of Knowledge Based and Practical Based elements. Although there are no prerequisites, certification candidates will benefit from taking AccessData courses specifically designed to give you a firm foundation in the technology of your choice.
Source: AccessData




CHFI 相關資料


CHFI 介紹

CHFI 重點整理

CHFI 題型

CHFI 投影片



參考引用來源:http://chfi.dyndns.org/

CEH(Certificated Ethical Hacker) - 道德駭客

「美國國防部採用EC-Council國際認證系列CEH課程為防駭訓練指標」





CEH(Certificated Ethical Hacker)道德駭客是一個中立型資安技術認證,延自美國聯邦調查局(FBI)訓練人才的課程。參加CEH訓練課程的臺灣學員,目前以SOC(資安監控中心)、政府部門和銀行這3個產業最多。通過CEH認證,意味著對於應用程式的安全、稽核、網路管理具有整合性的了解與認知。



「要參加CEH訓練課程和考試,都必須先簽署保密協定(NDA)。」這主要是避免參加CEH訓練課程的學員,非法使用所學的入侵手法。簽署保密協定是對學員的 一種提醒,若學員有不法舉動,必需自負責任。
CEH的考試方式,主要是150題單、複選題,考試時間4小時,滿分100分,70分以上 才合格。CEH的考試會有許多情境題,例如詢問一些MIS平常在工作上會遇到的資安問題,也會問發生原因和解決方式。


CEH的認證永久有效,若要從舊版考試升級到最新版,如果通過CEH 5.0之前版本,只要上網自修新版課程即可,不必參加訓練課程即可參加考試。或者是第二種升級方式,對於曾取得CEH認證,可以透過參加各種資安會議、累積足夠的CEC,便可以自動升級到最新版的CEH認證。



CISSP與CEH認證比較
CISSPCEH
重視資安理論框架 偏重駭客攻防實務技巧課程
很少改版每一 個作業系統改版、新攻擊手法增加,就會推出新版訓練
臺灣考過人數不到300人 臺灣考過人數不到300人
資料來源:iThome整理,2008年3月



CHFI (Computer Hacking Forensic Investigator) 電腦駭客鑑識偵查員

CHFI (Computer Hacking Forensic Investigator)為電腦駭客鑑識偵查員的認證,簡單的說就是「數位鑑識」會用到的技術證照….

何謂「電腦鑑識」

在 牛津辭典中 Computer Forensics (電腦鑑識)的定義為 "the application of forensic science technique to computer-base material.",主要的過程在於應用嚴謹的程序及科技的方法去處理數位資訊設備相關鑑識工作,當公司或個人遇到資訊相關緊急事故時,如何還原事情發生的真相,即為電腦鑑識領域的範疇。


根據加州柏克萊大學的研究,目前公司中有超過93%的資訊產出是以數位格式分散貯存在各個系統中,同時相同的研究也指出在 所有的資訊犯罪、侵權案例中,有超過85%的案例均會留下數位遺趾 (Foot print)。因此如何以科技的方法,在具有證據力的前題下將所有的數位資訊證據正確搜集及分析,則為電腦鑑識主要工作項目。


在鑑識領域 中的一句名言 "有一分證據,說一分話",因此電腦鑑識必需根據現有系統中所保留的任何資訊來研究分析,找出跟事件有關聯的資訊證據而無法無中生有,因此電腦鑑識工作者往往需要花費大量的時間去將資訊整理及分析,而所運用的科技方法主要在於達成一個目標,"只要證據存在就可以找得出來"。


電腦駭客鑑識偵查員的認證是由EC -Council所推出,在臺灣總代理是翊利得資訊,包括翊利得資訊、資策會都有開CHFI的課程。因為 CHFI是EC-Council道德駭客認證(CEH)的進階認證,為了滿足資安技術人員的進階需求,從3年前剛推出的1年1班,到最近的1年3~4班。 顯見越來越多政府或企業重視數位採證的技術。


CHFI是1個5天的課程,認證課程面向較廣,首先是了解何謂鑑識,從基本設備、鑑識實驗 室的環境規畫等;再者,就得先了解檔案與系統格式,才知道怎麼把已經被刪除或消失的證據找出來。接下來,鑑識人員就得知道如何按部就班做鑑識,並了解進行鑑識時,所有會發生的困難與挑戰。而怎麼寫鑑識報告,甚至進一步成為法庭上的專家證人,也都會在CHFI的篇章中詳細介紹到。


EC-council 介紹:
EC- Council(國際電子商務顧問局)全稱為International Council of E-Commerce Consultants,是一家以會員制為基礎的專業機構,總行設于紐約,主要來自哈彿大學、紐約市立大學、加利福尼亞大學、澳洲昆士蘭中央大學等大學教授,講師以及從事電子商務的企業界人士組成;還有來自Microsoft、IBM、SONY、Cisco等國際著名機構的代表。EC-Council的目 的是支持和加強在設計、建立、管理、推廣電子商務事業上發展的個人及機構的機能,向電子商務人士提供專業認證,向會員提供電子商務教育,技術等優惠技術。 EC-Council在企業界建立了國際通訊網路,成為電子商務專業人士的全球代言人。


EC-Council認證目前全世界取得證照人數超過五千人,許多是公司派訓人員參加,顯示各公司對於此認證的重視程度。國內所有中大型的企業都需要這樣的證照,可以防護企業網路安全,目前台灣才剛引進此種認證,目前國內有少數人員取得此種認證,未來此證照將有迫切需求。

certcities.com 證照排行榜



#10: Linux Professional Institute Certification, Level 2 (LPIC 2)
Vendor: Linux Professional Institute
Reader Interest Score (out of 20): 10
Buzz Score (out of 10): 5
Total: 15

#9: Systems Security Certified Practitioner (SSCP)
Vendor: (ISC)2
Reader Interest Score (out of 20): 13
Buzz Score (out of 10): 4
Total: 17

#8: MCSE: Security
Vendor: Microsoft
Reader Interest Score (out of 20): 12
Buzz Score (out of 10): 6
Total: 18

#7 Cisco Certified Network Professional
Vendor: Cisco
Reader Interest Score (out of 20): 12
Buzz Score (out of 10): 7
Total: 19

#6: Cisco Certified Internetwork Expert
Vendor: Cisco
Reader Interest Score (out of 20): 11
Buzz Score (out of 10): 9
Total: 20

#4 (TIE): Cisco Certified Security Professional (CCSP), Project Management Professional (PMP)
Vendors: Cisco, Project Management Institute
Reader Interest Score (out of 20): 13, 14
Buzz Score (out of 10): 8, 7
Total: 21

#3: Microsoft Certified Architect
Vendor: Microsoft
Reader Interest Score (out of 20): 15
Buzz Score (out of 10): 7
Total: 22

#2: Microsoft Certified Technical Specialist: SQL & .NET
Vendor: Microsoft
Reader Interest Score (out of 20): 18
Buzz Score (out of 10): 5
Total: 23

#1: Red Hat Certified Engineer
Vendor: Red Hat
Reader Interest Score (out of 20): 17
Buzz Score (out of 10): 8
Total: 25

恭喜RHCE,怎麼沒有2007、2008的排行??

Top 15 薪情證照排行榜



1. PMI Project Management Professional (PMP)

With an average annual salary of $101,695, the PMP certification from the Project Management Institute (PMI) organization tops the list of highest paying certifications for the current year.

2. PMI Certified Associate in Project Management (CAPM)

Next highest on the list of highest paying certifications is PMI's Certified Associate in Project Management (CAPM). The average annual salary for CAPM holders that were surveyed is $101,103.

3. ITIL v2 - Foundations

With an annual average salary of $95,415 the ITIL v2 Foundations certification came up third on the list of highest paying certifications. ITIL stands for the IT Infrastructure Library. The ITIL certification is designed to show expertise in ITIL service support and service delivery.

4. Certified Information Systems Security Professional (CISSP)

Coming in at a close 4th on the list of highest paying certifications is the Certified Information Systems Security Professional or CISSP certification from (ISC)2. The average annual reported salary was $94,018.

5. Cisco CCIE Routing and Switching

At $93,500 per year average annual salary, the Cisco CCIE Routing and Switching certification came in 5th on the list of highest paying certifications in the technology industry.

6. Cisco CCVP - Certified Voice Professional

Number six on the list of the highest paying certifications is the Cisco CCVP or Cisco Certified Voice Professional. The average annual salary of CCVP respondents was $88,824.

7. ITIL v3 - ITIL Master

The ITIL v3 certification - the ITIL Master - came in 7th on the list of the highest paying technical certifications. The average annual salary for ITIL Master certification holders was $86,600.

8. MCSD - Microsoft Certified Solution Developer

The MCSD or Microsoft Certified Solution Developer certification pays an average of $84,522. This puts the MCSD certification at number 8 on the list of highest paying certifications in technology.

9. Cisco CCNP - Cisco Certified Network Professional

Cisco Certified Network professional or CCNP certification is number 9 on the list of highest paying technical certifications. The average annual salary reported by CCNP holders is $84,161.

10. Red Hat Certified Engineer

The Red Hat Certified Engineer (RGCE) came in at number 10 on the list of highest paying certifications. The average annual salary reported by Red Hat Certified Engineers is $83,692.

11. MCITP - Microsoft Certified IT Professional (Enterpeise)

The MCIPT certification (Enterprise), or Microsoft Certified IT Professional - Enterprise Support comes in at number 11 on the list of highest paying technical certifications. (The MCITP Database is number 14, see below). The average MCITP Enterprise salary reported was $82,941.

12. Cisco CCSP - Cisco Certified Security Professional

Coming in at number 12 on the list of the highest paying technical certifications is the Cisco CCSP or Cisco Certified Security Professional. The average annual salary reported by CCSP holders is $80,000.

13. MCAD - Microsoft Certified Applications Developer

With an average annual salary of $79,444, the MCAD certification, or Microsoft Certified Application Developer certification, is number 13 on the list of highest paying certifications in technology.

14. MCITP - Microsoft Certified IT Professional (Database)

The MCIPT certification (Database), or Microsoft Certified IT Professional - Database comes in at number 14 on the list of highest paying technical certifications. (The MCITP Enterprise Support is number 11, above). The average MCITP Database salary reported was $77,000.

15. MCDBA - Microsoft Certified Database Administrator

The Microsoft Certified Database Administrator, or MCDBA, comes in at number 15 on the list of highest paying technical certifications. The average annual salary reported by MCDBA respondents is $76,960.