Anders Eknert · @anderseknert
598 followers · 991 posts · Server hachyderm.io

My talk from Amsterdam a few weeks ago is now up on YouTube! The — a compliance certification scheme for service providers in the cloud — is on its way, and will have a big impact on how organizations work with , and . A holistic framework like the EUCS provides controls applicable to the whole stack. How would we codify and enforce such rules?

@enisa_eu

youtube.com/watch?v=XoWf4QcSbD

#kubecon #eucs #security #compliance #automation #policy #opa #PolicyAsCode #Rego #OSCAL

Last updated 2 years ago

Anders Eknert · @anderseknert
492 followers · 787 posts · Server hachyderm.io

I really do like the idea of — a standardized, machine readable format (JSON/YAML/XML) to describe:

1. Compliance / security / privacy requirements
2. The components / methods used to achieve said compliance
3. The methods used to assess and report compliance

However, the people at et al. advocating this desperately need to learn a thing or two about communication. It's like they spent so much time on machine readability that even their talks are optimized for machines.

#OSCAL #nist

Last updated 2 years ago

Antony "no h" Saba · @awsaba
93 followers · 195 posts · Server hachyderm.io

Trying to get a handle on and I'm having the same problem I always have with : the use cases, even if phrased as user stories are so high level to be meaningless, and every presentation seems to dive into minutae that in no way relates to any kind of day-to-day activity.

It's mind boggling.

There's also the "java/xml? if it was 15 years ago and still at a more enterprisey org, then sure let's goooo", but not really relevant at any recent orgs anymore...

#OSCAL #stix #infosec #grc

Last updated 2 years ago

Ross K · @rossk
180 followers · 79 posts · Server hachyderm.io

I had an epiphany this week.

Previously, I was attracted to:
- the (still embryonic) interoperability story, a lingua franca for tools in the /assessment space is obviously cool and useful
- the possibilities of security-documentation-as-code (though I'm somewhat bearish on the idea of that getting traction in my org).

Now, I finally grok the component model, and I think it's going to be transformative.

#OSCAL #grc

Last updated 2 years ago

Ross K · @rossk
123 followers · 43 posts · Server hachyderm.io

I'd love to hear from anyone out there who has integrated into their security program in any meaningful way pages.nist.gov/OSCAL/

For me the assessment (plans, and results) side of things is the most interesting part at the moment.

#nist #OSCAL

Last updated 2 years ago