An anonymous reader writes
"Cybersecurity is finally getting increased attention in Washington; however, one problematic idea that appears to have gained some traction is the development of a national certification program for cybersecurity professionals. While ostensibly targeted at the public sector and to protect critical infrastructure, it will have broad implications for the private sector. Such a proposal, while sounding helpful, will offer few benefits, introduce burdensome costs to the government and the private sector, and not address the root cause of most cybersecurity vulnerabilities. This memo lays out the reasons why using professional certification is not effective for getting good security.
Read the memo: http://itif.org/files/WM-2009-05-certification.pdf"Link to Original Source