@renice well said. my favorite sort of Ponzi scheme: one with a purpose.

#SOC2

Last updated 1 year ago

Today it's my turn to present at the company all-hands meeting: on the importance of the certification.

I hope the first slide captures my feelings appropriately.

#SOC2

Last updated 1 year ago

Today is my turn to present at the company all-hands.

#SOC2

Last updated 1 year ago

chillu · @chillu
30 followers · 55 posts · Server mastodon.nz

"in all material respects" must be my least favourite security buzzword bingo phrase

#SOC2

Last updated 2 years ago

Julian Klinck · @mino
18 followers · 12 posts · Server sfba.social

Of the last recent years I was usually the go to guy for anything product compliance related. and mainly. The standardization and related work towards a safer internet for everyone is important. Googles effort of bringing forward a standard for vulnerability scanning is noteworthy: github.com/google/osv-scanner

#SOC2 #iso27001 #opensource

Last updated 2 years ago

Our latest drop: github.com/chainguard-dev/acls

As part of , we've been using this to run monthly reviews of our ACLs across SaaS platforms: , , , etc.

acls-in-yaml dumps from each platform into a consistent and neutral format, which makes it easy to visualize change over time.

We use this by committing the result into a repo and getting the PR reviewed by the admins for each system.

PS: ACL change alerts are also awesome!

#github #yaml #ACLs #Vercel #slack #gcp #audit #compliance #SOC2 #opensource

Last updated 2 years ago

I'm open-sourcing a new tool today: kolide-google-matcher

It's fringe, as it's designed for IT admins that use both and , but for that handful of users, it can unearth violations: github.com/chainguard-dev/koli

#compliance #SOC2 #googleworkspace #Kolide

Last updated 2 years ago