|
|
|
|
|
by hnbear
1250 days ago
|
|
I’ve found it immensely frustrating in numerous roles when discussing security, audit and compliance requests that the requesters can seldom actually explain their reasoning. I want a clear statement of risk and why their proposed compensating control actually mitigates it. Far too often the answers are just “it’s securerer” or “it’s the way we do it”, and actually proposing something that genuinely mitigates the underlying issue is ignored. All that said, I’ll end up referencing this in the future as somewhat useful steps in a number of situations. Some have simpler approaches - eg for password security can just reference NIST guidelines which currently clearly state not to rotate and just require length above complexity. And they’re backup to with tested evidence and a clear rationale. |
|