Apples vs Oranges
Hi all,
Would like to seek advice on cyber forensics courses in sg and which are the more preferred providers.
Currently doing IT system admin in a law firm and recently there are some cases which require cyber forensics skills such as cloning of hdd and phone data for expert witness purposes in court. Think having such skills will help add value to myself.
Thanks for any input!
I read the follow-up threads to the original poster's post with great interest, especially those that promoted one certification or provider over another (to me it's like saying Android vs iOS

) .
Here's my take :
When you compare any IT-security certification course with another, you need to make a fair comparison because no 2 courses cover exactly the same content.
For example, a general hacking-only-focused course (e.g. CEH) is strictly about attack only and does not cover other areas such as forensics, investigation, etc.
Even between different "attack-only-focused" courses, the width of the topics vs the length of the days matters since you can only cover so much within X number of days.
For example, comparing EC-Council CEH with SANS ICS410 with Thinksecure's OSWA would be an inconsistent comparison.
CEH covers many different general areas of hacking within whatever number of days while ICS410 focuses only on ICS/SCADA within whatever number of days and OSWA focuses only on WiFi/Bluetooth/RFID within whatever number of days.
All have different content and address different audiences so how can a truly objective comparison as to the superiority of one's content over the other be made?
A course covering everything hacking under the sun in 5 days is simply not going to go as deep as a course focusing on limited areas in the same 5 days because you can only fit so much into 5 days.
Similary, a course designed to focus on one area is not going to touch on other areas at all that another course that covers multiple areas not as deeply in the same time frame.
Thus, any conclusion that anyone tries to offer that a particular "brand-name" course or provider is better than another is completely subjective because, while it may be true for the person offering the conclusion, it may not be applicable for another person who may have a different set of job-related needs.
For example, stating to someone looking for a wireless hacking or web hacking course that the forensics course you attended is better and that they should go for it instead is "wen pu dui ti".
Similarly, anyone claiming that a course is bad because they found it bad for themself does not mean that it is automatically bad for everyone.
You must find out from the person making the negative statement what was their original goal or job requirement in selecting the course, why the course did not fulfil that stated goal or job requirement and to provide concrete examples of WHY it failed to meet the stated goal or job requirement instead of subjective interpretations (i.e. you need to try to find the real reason and motivation WHY they claim the course they went for is bad).
For example, i can say that ABC123XYZ Seafood Restaurant serves bad food.
But then you ask me what i like and i say i like beef and i hate seafood.
You would then know why i said the restaurant was bad - not because it is actually bad but because i hate seafood, yet i went to a seafood restaurant (i.e. it is like i am asking to be disappointed with the food). So now you know what my motivation is to slam the restaurant.
Also, a person cannot make a conclusion as to the superiority of a course by doing a comparison between 2 courses of differing content, e.g. comparing an attack-focused course that is designed to cover as many topics as possible (e.g. CEH) versus a specialized course that focuses on only ICS/SCADA (e.g. ICS410).
Whoever you look at, be it EC-Council, SANS, Thinksecure and all other certification provider websites and course leaflets, you need to compare like to like.
For example, comparing something like FOR508 which covers forensics to OSWA which covers wireless is comparing apples to oranges. Some people will prefer apples and other people will prefer oranges.
A fairer comparison yardstick between certifications in general without taking into account their actual content would be : for whatever is the given content covered, does the certification examination use performance-based testing as a measurement for passing the exam? (i.e. do you have to do some practical action to derive the answer to the question)
If you look at literature from various universities and research tanks, you will find that performance-based testing is superior to non-performance-based testing such as MCQ tests which predominate even formal high-school/secondary/tertiary education systems.
Here is one such study from the University of Texas :
https://digital.library.txstate.edu/bitstream/handle/10877/3454/fulltext.pdf?sequence=1 . The conclusions and summary are inside Chapter 6 page 73 onwards. Note that essay-writing can be considered same as MCQ if candidates are told in advance the required structure to be used on the essay and the essay formula is taught as a brain-dumpable exercise.
The reason why some certifications are slammed by many people on the internet is IMO likely the result of the cost considerations of how exams are offered by providers. Performance-based testing requires some sort of exam infrastructure to be setup. And that costs more money per person to administer.
This means the provider must either pass the cost on the customer or takes a smaller profit or (more commonly) does not implement performance-based testing at all.
Having said that, the price of a course is not a completely accurate indicator of its quality.
Factors such as whether the trainers have to be flown in from overseas or not, whether there is a performance-testing exam environment, training venue, whether the training provider has a large marketing staff payroll to cover, etc, all factor into the final price you pay.
The size of your marketing payroll and how expensive your office rent is certainly does not factor into the quality of the content. In fact, lower pricing might even indicate that the provider may be more efficient operationally and passing the savings onward to the customer. I for one wouldn't mind that as a customer.
And since we don't usually have visibility into the backend ops and payroll of a provider, that is why performance-based testing is the key difference maker.
After all, you don't want to someone say to your face that a certification that you obtained solely by passing a non-performance-based-test on the back of your then-8-years of experience puts you on the same level as a 0-years experience person who only crammed for the exam via brain dumps and passed it.
This actually happened to me a long time ago in another country and i can assure you it was not a pleasant feeling to have a certification i attained just on the basis of my industry experience being downgraded just because someone could attain the same certification just by brain-dumping. That is why since that incident i became a big believer in performance-based testing because that is the only real way to make sure that my certification does not get downgraded over time.
Performance-based testing would ensure that if a person manages to get certified, he/she has earned it based on performance and not simple memorization.
So if i can get whatever is the best market price for a performance-based certification examination, that to me is always the key thing in my selection criteria.
On a related side note, as i have observed a large number of IT-related certifications proliferate over the last decade, one should always remember that the original basis of certification is to identify which individuals can do the job or not by making them pass a test which is designed to separate the wheat from the chaff.
If the pass rate of a certification exam is abnormally high or where people automatically expect to pass the exam just on the basis of exam-cramming, then the certification exam might not be stringent enough in its testing criteria and/or format.
A certification should by definition be stringent for the content that a person is being tested on such that only those who can put what they learn in a course together with all the prior work experience they have into actual real-world practice can pass.
Just compare the Cisco CCIE with its CCNA and you get the idea why there are way more CCNAs than CCIEs and why the CCIEs get paid way more.
Back to the original poster :
Since your question is specifcally about forensics-based course content, you probably want to ignore the courses in all those posts that have non-forensics content and only zoom in to do research on the courses which have forensics content and make your selection from there. Looking at the non-forensics-courses is again "wen pu dui ti".

Visit the course websites and download the brochures to find out the details yourself. Then call up the providers and ask to speak to someone technical and fire away. Under no circumstance talk to a marketing person about the course content and what are the takeaways !!
Just make sure that whatever you select has a performance-based test to safeguard the certification's value.
Hope you find what you are looking for!