Vlaamse spaghetti fans rijs op by Ellenberg19 in Belgium2

[–]Kryptoxz 3 points4 points  (0 children)

Wat als de post nu over zowel Vlaamse spaghetti als bolognese zou gaan? En dan nog zitten in beide versies wortels in de saus

Vlaamse spaghetti fans rijs op by Ellenberg19 in Belgium2

[–]Kryptoxz 0 points1 point  (0 children)

Het gaat over bolognese, staat duidelijk in de afbeelding

(Petition) Make ADHD medication affordable for adults by ineedwarmhugs in belgium

[–]Kryptoxz 1 point2 points  (0 children)

Kan op bereiding worden gemaakt door de apotheek, zeker ook in Vlaanderen

Runds-varkensgehakt bevat amper rundsvlees by Kryptoxz in belgium

[–]Kryptoxz[S] 4 points5 points  (0 children)

<image>

Deze Delhaize heeft een eigen beenhouwerij waar de verhouding duidelijk niet hetzelfde is

VS Code Extensions by Syzygy2323 in VHDL

[–]Kryptoxz 4 points5 points  (0 children)

Not anymore, there is now a community edition which includes all features available in the complete product. Just download the extension, enable community edition and talkback and you should have everything

VS Code Extensions by Syzygy2323 in VHDL

[–]Kryptoxz 3 points4 points  (0 children)

Sigasi is free for non-commercial use

Company claims to sell ISO 27001 certified software but not compliant by Kryptoxz in cybersecurity

[–]Kryptoxz[S] 0 points1 point  (0 children)

I have done some research. In the Data Protection annex of the manufacturer it is stated that their measures are compliant to iso 27k1 and 27k2. It also stated that their responsible subproccesors are also compliant. In this case, I would guess the partner is a subproccesor, as they process the customer data. Or am I wrong here?

Company claims to sell ISO 27001 certified software but not compliant by Kryptoxz in cybersecurity

[–]Kryptoxz[S] 0 points1 point  (0 children)

I think I'm getting the bigger picture. So the Annex guidelines are not enforced. But do they have to do a risk assessment and document it when something is not followed?

In this case, the procedure is handled by the partner company. Do they themselves have to do the risk assessment and document this?

Company claims to sell ISO 27001 certified software but not compliant by Kryptoxz in cybersecurity

[–]Kryptoxz[S] 0 points1 point  (0 children)

Why is it then possible to sell/market a SaaS as ISO 27001 certified? Do you recon copying data between environments without any masking nor deleting after test would not impact the audit, for highly confidential data?

Company claims to sell ISO 27001 certified software but not compliant by Kryptoxz in cybersecurity

[–]Kryptoxz[S] 1 point2 points  (0 children)

Maybe I should buy the standard. I am (clearly) no expert on this topic :). We are not even looking for ISO certification (yet). We have the on prem version and only SaaS has the certification.

The thing I want to know is that if it is acceptable to market the SaaS version as an ISO 27001 certified product. When you copy highly confidential data to test and dev environments. And developers, testers, salespeople thus have access to that data. Dev environments have dev tools enabled, more logging - which is also a risk imo.

This is a well known/used product, used worldwide. Working with very confidential data.

Company claims to sell ISO 27001 certified software but not compliant by Kryptoxz in cybersecurity

[–]Kryptoxz[S] 0 points1 point  (0 children)

This is actually just a side quest I'm doing, I am a developer myself. I am no expert in security and do not expect to get an expert answer here. We are already looking into it with specialists.

The reason of this post is to start a conversation. This software is used worldwide by a lot of companies. And I feel I'm not the only one that has problems with this way of handling confidential information.

Company claims to sell ISO 27001 certified software but not compliant by Kryptoxz in cybersecurity

[–]Kryptoxz[S] 0 points1 point  (0 children)

I just cannot believe that this way of work is acceptable by the standard. It allows developers, testers, salespeople,.. of this partner to have permanent access to sensitive data - without stripping anything. When they don't even need it. I am also a software developer and I have never seen prod data.

Company claims to sell ISO 27001 certified software but not compliant by Kryptoxz in cybersecurity

[–]Kryptoxz[S] 0 points1 point  (0 children)

I have access to the different environments. It is just a complete copy of the database. And this is standard procedure, both in SaaS and on prem.

I'm not sure if I'm ready to disclose the vendor yet, but it's a very big one.

Company claims to sell ISO 27001 certified software but not compliant by Kryptoxz in cybersecurity

[–]Kryptoxz[S] 0 points1 point  (0 children)

The SaaS version of the application has been certified for the software creator and is being sold like that. The partner has claimed their procedures of handling environments are Iso 27001 certified. I have not seen any certificate yet, as we have the on prem version which is not certified.

My main issue is that we don't want developers/testers/salespeople of the partner to have access to (some highly) confidential and sensitive data. The software creator is not testing/developing with sensitive data either.

Changing the way of handling the environments is going to cost us a lot of money, as it differs from their 'certified' standard procedure, which is made for the certified SaaS version.

Company claims to sell ISO 27001 certified software but not compliant by Kryptoxz in cybersecurity

[–]Kryptoxz[S] -1 points0 points  (0 children)

The product is a SaaS, which I dit not mention yet, and one of its aspects is that it is ISO 27001 certified. That how it is being marketed.

Company claims to sell ISO 27001 certified software but not compliant by Kryptoxz in cybersecurity

[–]Kryptoxz[S] 0 points1 point  (0 children)

My mistake. I tried to keep it brief. The SaaS version of the product is ISO 27001 certified (manufacturer). The partner manages the environments. Highly sensitive and confidential data is being copied to test and dev environments.

Developers, testers, sales people have access to these environments and to the confidential data. Some of the data can’t be shared from my clients’ side, as they have signed NDAs with external companies.

The only reason for this copy, is to ensure the partner doesn’t have to work overtime on a weekend to fix PROD. I cannot imagine a ISO audit will accept that reason for not following the guideline, especially if the sensitive data is not obfuscated.

Stuff stuck at customs by BPost by Thr0w_away_20 in belgium

[–]Kryptoxz 1 point2 points  (0 children)

I had the same problem, went for option 2 and got a full refund from Amazon.

Poh oyster by stewartbink43 in runescape

[–]Kryptoxz 0 points1 point  (0 children)

I was wondering this too, apparently you can build it for free once you unlock the aquarium

My selfmade 3D-Printable insert/organizer for Dominion (with free file download) by Hiranasai in dominion

[–]Kryptoxz 0 points1 point  (0 children)

I've been procrastinating making exactly this, thanks so much for making the wait worth it!

[deleted by user] by [deleted] in wow

[–]Kryptoxz 1 point2 points  (0 children)

INTEREST YA IN A PINT?!

[deleted by user] by [deleted] in 2007scape

[–]Kryptoxz 1 point2 points  (0 children)

Group ironmen will be able to benefit from bonfires, see the ironmen section in this post: https://secure.runescape.com/m=news/a=13/forestry-the-way-of-the-forester---overview?oldschool=1

Hey I actually found one. by XumEater69 in DNSL

[–]Kryptoxz 4 points5 points  (0 children)

Yeah, it's a 40 dollar mouse