stefano,
@stefano@bsd.cafe avatar

A capable colleague passed on a request from their client. They want to know if the VM disks are encrypted at rest, if the keys are rotated periodically, and if there's a key retention procedure in place. Ironically, the client's VPS runs on Ubuntu 18.04, which has been out of updates for a year, and despite numerous notifications to upgrade, they believe it can wait. 😄

ParadeGrotesque,
@ParadeGrotesque@mastodon.sdf.org avatar

@stefano

Somebody got a letter from their client, asking what their security level was...

"Oh yeah, remember that old server we store everything on?"

stefano,
@stefano@bsd.cafe avatar

@ParadeGrotesque I think so...

ParadeGrotesque,
@ParadeGrotesque@mastodon.sdf.org avatar

@stefano

I guarantee it.

Some big client of theirs wants to be iso 9001 certified, which requires their suppliers to provide security guarantees.

Lawyers write boilerplate letters, send letters to all suppliers. And they contact their IT guys and ask the questions that were in the letter. About that Ubuntu 18.04 servers.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Cybersecurity
  • DreamBathrooms
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • ngwrru68w68
  • tacticalgear
  • JUstTest
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • provamag3
  • lostlight
  • All magazines