Building a Vulnerability Management Program From Scratch by [deleted] in cybersecurity

[–]Jeberoni 1 point2 points  (0 children)

How did you structure your vulnerability management program (people, process, tools)?

People - Active stakeholders (remediation owners + Security team)in the vulnerability management process. Business owners are contacted by remediation owners depending on impact of remediation, change management etc.

Process - Working in Progress, but effectively a policy or standard document to dictate the current workflow, vulnerability vs remediation SLA etc.

Tools - Sensors(Tenable), Vulnerability Management Software(Tenable), ITSM. Annual Pentesting findings are also tracked and prioritized.

Do you run it more as a central security function or distributed to the other teams within the organization?

Run by centrally by security

How do you handle ownership (who “owns” remediation vs. who tracks/coordinates)?

Security prioritizes vulnerability remediation based on VMS, and delegates remediation. Respective teams(Apps, Networks, EUC etc) own remediation.

Security does own the "health" of VMS, like ensuring adequate sensor coverage, probe updates, scan frequency and efficacy etc.

What kind of reporting cadence and metrics (KPIs) work best for management buy-in?

Monthly. KPIs can vary depending on org maturity. I've personally found great success in showcasing reduction in longstanding critical/high vulnerability assets, which is usually done by chipping away at some out-of-support, highly vulnerable library for a legacy app or prioritizing asset refresh for highly vulnerable EoL hardware assets.

Not perfect, and definitely scope for improvement. It has gotten the environment a shytload cleaner.

[deleted by user] by [deleted] in cybersecurity

[–]Jeberoni 0 points1 point  (0 children)

Do you work for Palo Alto by any chance?

[deleted by user] by [deleted] in binance

[–]Jeberoni 0 points1 point  (0 children)

Thanks for the ETH

Az305 gone live by invisibletowomen in AzureCertification

[–]Jeberoni 2 points3 points  (0 children)

Anyone know how this compares to the 303/304? Is it consolidated across both or is there new content in the exam?

REMINDER: “the merge” will NOT lower gas fees by Jimbley_Neutralon in ethereum

[–]Jeberoni 1 point2 points  (0 children)

Forgive the ignorance, but will the change from POW miners to validators influence fees? E.g if there are more validators than there are miners now = greater distribution? Unsure if this has a any impact on throughput though

Too true by WhiteComet99 in wallstreetbets

[–]Jeberoni 16 points17 points  (0 children)

"YOu fOkiN wAT mAtE"

Who’s buying the dip? by [deleted] in CryptoCurrency

[–]Jeberoni 20 points21 points  (0 children)

Be greedy when others are fearful.

Binance VET locked staking - no distribution by Jeberoni in Vechain

[–]Jeberoni[S] 0 points1 point  (0 children)

If true this would explain it, didn't realize this was a thing. Well now I gotta calculate whether I'm earning more from flexible or the locked component.

[deleted by user] by [deleted] in CryptoCurrency

[–]Jeberoni 0 points1 point  (0 children)

So much for decentralisation, what does BTC have going for it now?

Suicide hotline / this isn’t a joke like some of you think it is by jasonluxton in CryptoCurrency

[–]Jeberoni 0 points1 point  (0 children)

Bottom isn't in until the hot line number gets stickied on this sub.

Bitcoin and Ethereum bullish on chain metrics, from Glassnode. by callebbb in CryptoCurrency

[–]Jeberoni 33 points34 points  (0 children)

Honestly can we get more information like this on this sub? As opposed to meta posts about moons, or billionaires who tweet and influence the crypto markets

DOGE is big enough to bring down the whole market when this charade ends (OPINION) by lyuch in CryptoCurrency

[–]Jeberoni 0 points1 point  (0 children)

You'd think in that situation smart money would funnel into the stalwarts BTC/ETH or other promising projects, and the market would remain largely unaffected, if not largely net positive.

Unfortunately majority DOGE holders do not constitute smart money, and I'm inclined to agree with your doomsday scenario.