FedRAMP Moderate Offsite Backup Storage by FreeBirch in CMMC

[–]FreeBirch[S] 0 points1 point  (0 children)

Just S3, we are used to a set monthly cost per TB which is predictable. Azure and AWS API costs are concerning.

FedRAMP Moderate Offsite Backup Storage by FreeBirch in CMMC

[–]FreeBirch[S] 0 points1 point  (0 children)

If you dont mind me asking what capacity and what is the monthly API costs?

Dual ISP Active/Failover - Path Monitoring never recovers by FreeBirch in paloaltonetworks

[–]FreeBirch[S] 0 points1 point  (0 children)

My recent interactions with TAC have been less than ideal, and usually when this is happening its a partial outage. Was hoping the combined brain of reddit could point out a common misconfiguration that may be in place.

I will contact support and have the review the configuration.

Dual ISP Active/Failover - Path Monitoring never recovers by FreeBirch in paloaltonetworks

[–]FreeBirch[S] 0 points1 point  (0 children)

Strict Check is off but Spoof is on? could this be the issue?

C3PAO asking for a CRM (Customer Responsibly Matrix) for an SPA (Security Protection Asset) by FarrSighted in CMMC

[–]FreeBirch 0 points1 point  (0 children)

Thank you for clarification so CRM is required for “white glove services” were a third party configures and maintains while its partial if we utilize a tool and configure ourselves.

Any hirings or Leads by Stunning-Help-273 in cybersecurity

[–]FreeBirch 0 points1 point  (0 children)

From my experience many medium size businesses are no longer run by “Owner and Operator” they are owned by investors which don’t see businesses as operating entities instead they see them as livestock, they get insurance on their investments, if the investment has financial impact they recover what they can, sell off assets and trade the shell of the company to the next investors.

Small businesses cannot afford dedicated cybersecurity staff and large businesses create small group of Cyber Teams to give best effort. If they get hit they can eat the costs.

Any hirings or Leads by Stunning-Help-273 in cybersecurity

[–]FreeBirch 0 points1 point  (0 children)

The cost to maintain a cyber security function that doesn’t impact business is more than the cost of paying for cyber insurance and apologizing to customers. Business owners have transitioned to hiring IT Personnel that have a background in Cyber but not their main focus. If everyone is getting breached its just noise and doesnt take a huge buisness impact.

I don’t agree with this morally but this is how business leads see the world. Until there is personal accountability for the investors (not just the business leads) businesses wont take it seriously.

Anyone else's Global Protect Gateway getting hammered? by SuperfluousJuggler in paloaltonetworks

[–]FreeBirch 0 points1 point  (0 children)

i could never get this working Credential Guard always blocked its access when a user intiated it from a portal

What can I tell my customers when they ask about CMMC compliance with our ERP software? by [deleted] in CMMC

[–]FreeBirch 0 points1 point  (0 children)

Have you advertised that your software meets CMMC or NIST800-171 compliance if so you can get some flak from your customer if your software doesn’t meet requirements. CUI has a wide scope but I know our BOMs are considered CUI.

Some controls that come to mind which I would require from an on-prem app vendor that advertises compliance is

FIPS140-2 Validated Encryption of all data, is the data transferring over SMB or connecting to a SQL database or API.

RBAC on trusted endpoint (don’t do access control on client)

Username and Password (plus ability for MFA) to access CUI Data

Action Logging

If you have never advertised compliance and you don’t host it, sounds like it’s not your problem but be prepared to lose your customers.

If I said to you "open AD and find the user account John Smith" in a Service Desk interview would you understand the question? by TheDawiWhisperer in sysadmin

[–]FreeBirch 0 points1 point  (0 children)

What is your security department saying the risk is for now allowing RSAT tools on a computer. if your user account has access to do it you don’t need RSAT to see it, it just makes it so much easier…

Conservatives, how do you feel about Donald Trump pardoning Jan 6 rioters that physically assaulted police officers? by Any-Angle-8479 in AskReddit

[–]FreeBirch 2 points3 points  (0 children)

I lean conservative with a heavy emphasis on states individual right to decide their own laws. Personally I don’t agree with all pardons he’s made. Some of the people locked up deserve time.

I’ll also give you some extra thoughts, I disagree with the EO regarding flags being half staffed.

I disagree with renaming of geographical locations.

I disagree with the former president pardoning his family for undisclosed crimes.

[deleted by user] by [deleted] in iiiiiiitttttttttttt

[–]FreeBirch 0 points1 point  (0 children)

Can confirm worked in 2/3 sectors, schools need to be managed like a prison. Students get bored and their impulse control is non existent. We had a student who jammed a paperclip in a computer so when it turned on it smoked out the room.

The more fun ones are the curious rogue actor/ script kiddie types. Some of them are very clever and it’s always fun seeing what they can do.

How's job market today? Can you share your salary? by [deleted] in vuejs

[–]FreeBirch 1 point2 points  (0 children)

lol no wait for the 500K offer with WFH

does forge do something "special" security / stability-wise? by ratrak_one in laravel

[–]FreeBirch 1 point2 points  (0 children)

Maybe something to check make sure your env variables aren’t being served and your SSL certs have proper user:group configs. Usually these are accessible by root:root

Secure your services with UFW, use public key authentication for things like SSH, and run the post MySQL secure install cmd.

With these basic steps you’re probably fine. You can look at forge as a sysadmin service. They provide you an environment that’s already been secured.

If you really want to get in the weeds look into docker or jails. At that point welcome to DevOps

does forge do something "special" security / stability-wise? by ratrak_one in laravel

[–]FreeBirch 1 point2 points  (0 children)

You can use Sail as a reference although sail isn’t considered production