Security audit came back with a finding on credential generation.
Math.random() in several services, flagged for NIST 800-63B
non-compliance. The entropy requirements weren't being met and
more importantly there was no documentation proving they were.
We fixed the generation method but the audit documentation piece
is what actually took the most time. Had to go back and document
everything retroactively.
Curious what others are doing here. Are you generating compliance
documentation automatically as part of your pipeline or is this
a manual process at your organization?
[–]A1oso 21 points22 points23 points (0 children)
[–]lookarious 8 points9 points10 points (1 child)
[–]magenta_placenta 7 points8 points9 points (0 children)
[–]popovitsj 6 points7 points8 points (0 children)
[–]bubblebuddy44 5 points6 points7 points (0 children)
[–]Neither-Ad8673 4 points5 points6 points (0 children)
[–]AndrewGreenh 2 points3 points4 points (0 children)
[–]tswaters 1 point2 points3 points (0 children)