Michigan just passed a law requiring anyone who performs digital forensic investigations to either hold a private investigator license or possess a recognized professional certification such as the CISSP. The stated rationale is consumer protection - ensuring that people who handle sensitive digital evidence in legal proceedings meet some baseline standard of competence. The practical effect is going to be more complicated than that.

The Michigan Situation

The law, which takes effect next year, applies broadly to anyone performing computer forensic examinations for litigation, criminal investigations, or other legal proceedings within the state. If you do not have a PI license or an approved certification, you are breaking the law by examining a hard drive for evidence - even if you have been doing this work competently for twenty years.

The inclusion of the CISSP as an acceptable credential is what caught my attention. The CISSP is a broadly respected certification, but it is a generalist security certification. It covers ten domains ranging from access control to physical security to business continuity. Digital forensics is not one of those domains. You can hold a CISSP and have essentially zero knowledge of forensic imaging, chain of custody procedures, file system analysis, or any of the other specialized skills that forensic examination requires.

There are certifications that do focus specifically on digital forensics - the EnCE, the GCFE, the CCE. Michigan apparently decided that the CISSP was sufficient, which suggests that the people drafting this legislation were more interested in the credential's name recognition than in its relevance to the actual work being regulated.

Certification Versus Competence

This brings us to the perennial debate in the security industry: does holding a certification mean you are competent? The honest answer is that it means you were competent enough to pass a test on a particular day. Whether that translates to practical skill in the field depends entirely on the individual.

I hold a CISSP. I studied for it, I passed it, I maintain it through continuing education credits. I can tell you with confidence that the exam tested my ability to recall security concepts and apply them to multiple-choice scenarios. It did not test my ability to investigate a breach, analyze malware, configure a firewall, or perform any of the hands-on tasks that my actual job requires.

This is not a criticism of the CISSP specifically. Certification exams are inherently limited in what they can measure. They test knowledge, not skill. They verify that you know the theory, not that you can execute under pressure. The problem arises when organizations - or in this case, state legislatures - treat certification as a proxy for competence when it is really a proxy for minimum knowledge.

The Broader Certification Landscape

The security certification market has grown enormously over the past decade. CISSP, CISM, CISA, CEH, GIAC certifications, CompTIA Security+ - there is a credential for almost every subspecialty and career level. Employers increasingly require them as hiring filters. Government agencies mandate them for certain roles. And now Michigan is requiring them for an entire category of professional activity.

The effect on the profession is mixed. On the positive side, certifications provide a common baseline vocabulary and ensure that practitioners have at least been exposed to foundational concepts. They give hiring managers a screening tool when evaluating candidates. They encourage ongoing education through maintenance requirements.

On the negative side, they create a credentialism culture where the letters after your name carry disproportionate weight relative to your actual abilities. I have worked with CISSP holders who could not configure a basic firewall rule and with uncertified practitioners who could reverse-engineer malware in their sleep. The certification told me nothing about which person I wanted on my incident response team.

What Michigan Should Have Done

If the goal was to ensure competence in digital forensic investigations, Michigan should have required certifications that are actually relevant to digital forensics. Better yet, they could have established a competency board that evaluates practitioners based on a combination of education, experience, and demonstrated skill - similar to how other licensed professions operate.

Requiring a CISSP for forensic work is like requiring a medical degree for dentistry. It demonstrates that you have a broad base of knowledge in a related field, but it says nothing about your ability to do the specific job in question.

The security industry's relationship with certifications remains awkward. We need standards, we need baselines, and we need ways to evaluate competence at scale. But treating certifications as competence guarantees does a disservice to the profession and, in Michigan's case, to the public the law is supposed to protect.

Sam Spade did not need a CISSP to be a good detective. But apparently in Michigan, he would need one to look at a hard drive.

SA
SecForAll Editorial
Security Analysis & Commentary
SecForAll covers enterprise security trends, policy, and technology for security professionals and decision-makers. Our analysis draws on industry research, vendor briefings, and hands-on evaluation of security products and standards.