|
|
|
|
|
by AmericanChopper
2246 days ago
|
|
Lower down the tread I mentioned vendor due diligence, specifically because I’ve done so many vendor security reviews. But there’s more to it than that. You might also need to be threat modelling it, legal will need to review the ToS and privacy policy. You probably need to figure out the impact on other services too. If you’re in a regulated organisation, there could be any number of other things you have to do, and on going compliance costs. If you work in a bank, and somebody wants to install Gentoo, you’d have to figure out how to run anti-virus on it, how to centralise patches for it, how to install endpoint DLP, make sure it has the correct web proxy configuration... the costs can easily stack up. |
|
It may be correct for them. But for you, as a candidate, it's a good indicator that you'd be happier in the kind of company where engineering has the power to get that done.
Between jamfcloud, osquery, munki, etc. there are plenty of companies and tools out there catering to IT departments that take this seriously.