New around here? Register your SA Forums Account here!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady

Thanks Ants posted:

If your work laptop is poo poo slow because of stuff your IT department did to it then just work slower
What gets me is the emails from corp infosec about me having "hacking tools" installed. Because I do. It's what they hired me for. It'd be nice if I could delete the Kali ISO to make them happy but Defender won't let me. Very sad, can't be helped.

Adbot
ADBOT LOVES YOU

Internet Explorer
Jun 1, 2005





Thanks Ants posted:

If your work laptop is poo poo slow because of stuff your IT department did to it then just work slower

Words to live by, but when it gets so bad that I can't navigate a Zoom/Teams meeting we have a problem. Mine can get to the point where I can't get to the unmute button or look up references to share. Good times.

Internet Explorer fucked around with this message at 22:08 on Mar 14, 2025

Tapedump
Aug 31, 2007
College Slice
I feel really low-rent with this question, so please point me to a better thread

CMMC... any good resouces out there other than dry gov docs? Just want to make sure I'm not missing out on an easier way to approach and digest this.

(Just lowly Level 1)

Defenestrategy
Oct 24, 2010

Tapedump posted:

I feel really low-rent with this question, so please point me to a better thread

CMMC... any good resouces out there other than dry gov docs? Just want to make sure I'm not missing out on an easier way to approach and digest this.

(Just lowly Level 1)

As someone who is currently going through CMMC Level 2, don't feel low rent CMMC is new and scary and a pain in the rear end for anyone who is in an underfunded security program. You're probably not gonna find any CMMC specific guidance because it really doesn't exist yet, the best you could do if you really want more is stuff referencing NIST 800-171 and 800-53, but honestly Level 1 from what I remember is like... fifteen controls and a self assessment so it's not so bad.

I believe there's a goon here who is an auditor of some flavor for it, I think.

edit: the best advice from my experience having just completed a mock assessment is over document everything. Everything must be documented, and those documents need documents even if it's self evident, create a giant stack of paper.

Defenestrategy fucked around with this message at 20:30 on Mar 14, 2025

Aunt Beth
Feb 24, 2006

Baby, you're ready!
Grimey Drawer

some kinda jackal posted:

can't execute malware if there's no free cycles

problem solved
McAfee employee spotted

MightyBigMinus
Jan 26, 2020

this is exactly the kind of super dumb aggro ignorance that bring us here today
does anyone actually pay for sysdig? and if you have been, do you think you're gonna renew?

every single sysdig customer i've talked to has either said "its awesome but we never use it" or "wiz's sensor is good enough so we're getting rid of it"

CloFan
Nov 6, 2004

Thread title is satire right? Imma bout to drop a lot of budget on Complete + Identity + SIEM

Riven
Apr 22, 2002

CloFan posted:

Thread title is satire right? Imma bout to drop a lot of budget on Complete + Identity + SIEM

Did you try to fly or go anywhere and buy anything last July?

madmatt112
Jul 11, 2016

Take them, they're warm.

CloFan posted:

Thread title is satire right? Imma bout to drop a lot of budget on Complete + Identity + SIEM

There are a lot of people who like the product and a lot of people who don’t like the product. :shrug:

Ojjeorago
Sep 21, 2008

I had a dream, too. It wasn't pleasant, though ... I dreamt I was a moron...
Gary’s Answer

CloFan posted:

Thread title is satire right? Imma bout to drop a lot of budget on Complete + Identity + SIEM

Coming this spring on Fox, Unfrozen Caveman CISO!

madmatt112
Jul 11, 2016

Take them, they're warm.

CloFan
Nov 6, 2004

I mean it's either that or S1 full stack

Either seem to be streets ahead of what we have now, and cheaper to boot!

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




Defenestrategy posted:

We're now doing sprints in my department. On the plus side this has turned into a net -2 meetings per month for me, on the negative side sprints don't make any sense to me having had it explained. In my half of the department I have my own internal projects, pen testing, lab stuff, whatever. I have to field "help desk" style questions and answers for various things like HIDS, NIDS, etc. and then on top of that I get emergency stuff like "An employee needs to be termed" or "an employee is mining crypto and we need to scrub their computer." poo poo.

What you need in this sort of situation to get your manager to define your allocation to Agile BS and Operational BS. Then you need them to back you up when ops stuff slips so you can meet agile targets and vice versa. The first part is hard, the second part will be harder.

If you can't get the management backing formally, start aggressively managing your time. Hand off tickets, push them back as much as SLAs will allow, make your calendar a wall of "gently caress off, I'm busy" events.

Adbot
ADBOT LOVES YOU

Hampton Flinch
Jan 1, 2006

CloFan posted:

Thread title is satire right? Imma bout to drop a lot of budget on Complete + Identity + SIEM

Crowdstrike incident caused several hours of outage where I work, so the company started a review to see if we should replace Falcon.

Someone made the call to do PoCs on the top competitors and see which ones wouldn't embarrass themselves in front of our red team, as a start. IDK what exactly happened after that, but we still have Falcon.

No doubt there's companies, with either better or worse risk environments than us, where Falcon wouldn't make sense. I imagine there are places that have CMDBs at bedrock, no-compromise app allowlisting, no direct sudo, etc, where they would see Falcon as too much additional risk.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply