tl;dr — Brit. Europhile. Gay. 63, no idea how that happened. Londoner for work rather than inclination. Professionally that would be IT hardware and data centres, but currently unemployed. Will consider all reasonable offers and most unreasonable ones. Interested in books, SF&F history, physics. Transit/transport. Architecture, especially housing. Dealing with climate change. Politically lefish and small-l liberal. Oddly traditionalist in many things.
Exclusive business resource poised to become world’s virtual headquarters for SMEs interested in doing business in China.
📺 https://peer.adalta.social/w/wERvtEKvbRvBn1rcwHWurY 🔗 🇩🇪🇺🇸🇫🇷 🔗 ℹ️
La convergence inattendue des logiciels de conformité et de l’innovation technique audiovisuelle crée un nouveau paradigme pour le financement de la R&D.
Exclusive business resource poised to become world’s virtual headquarters for SMEs interested in doing business in China.
I'm Phil, I do things, I know things. It's good to make friends. #emacs #foss #selfhosted #actuallyautistic #cptsd #cybersec #infosec #systemadministration Bots /not/ welcome. Bridges out of Fedi /not/ welcome. Corporations/ businesses /not/ welcome.
Man #Vanta is so bad…
Their Entra MFA enforcement check is horrible. It only checks if a conditional access policy exists, and if it has ‘MFA’ in the builtinControls. If it does, it’s a pass.
But it doesn’t check…
- if any users are excluded from the policy
- if any groups are excluded
- if the policy covers all users even after exclusions (e.g. if the exclusions are service accounts for any reason)
- if the geoblocking is functional
- if any of the excluded users are privileged
Vanta is a tool designed to mislead auditors, presenting as a third-party authority with their ‘trust center’ and all the flashy shiny dashboards.
Yet the core is rotten.
I haven’t been this insulted since I found out that #vanta has a barely functional risk API (was trying to sync our risk register from our internal repo… long story).
Just… I lack words.
#infosec #cybersec #grc #privacy #compliance #fintech #informationsecurity #audit #soc2
Empowering healthcare and MedTech with cutting-edge IT consulting and software development. #healthtech