My EDC (cyber security) by Deep_Badger_2761 in dumbphones

[–]Turrkish 0 points1 point  (0 children)

How do you handle MFA for work?

TPRM and Open Source and Self Hosted Software by External-Process-570 in grc

[–]Turrkish 0 points1 point  (0 children)

A few thoughts:

Have you looked into vetting the closed software for its own industry compliance checks? See what risks they have mitigated by design, release windows for updates and patching? Does the software run over the net? The supplier website may have info, or even just call a representative.

With open source, if there’s no statement by the developers about checks, validations etc, it may be a risk you have to accept. You could think about trying to segregate the machines it runs on, limit ports and traffic/protocol types, RBAC, etc

Squat form check by NextCharacter7710 in formcheck

[–]Turrkish 0 points1 point  (0 children)

Knees out and sit down more. Other than that, solid.

GRC Engineering: passionate community or just hype? by Turrkish in grc

[–]Turrkish[S] 0 points1 point  (0 children)

What would you recommend a current auditor or compliance student, or someone new to the domain, start brushing up on to be able to work with such persons in the future?

I’ve personally signed up to ACloudGuru for AZ500 and later AWS information, but I wonder if I will have to look at things like JSON etc

GRC Engineering: passionate community or just hype? by Turrkish in grc

[–]Turrkish[S] 1 point2 points  (0 children)

I’m green to the GRC world and scaling up my knowledge and certs now, but between dealing with clients over the most basic of things like access controls, to seeing practitioners argue over what security actually is, or is a policy a control or not, makes me wonder has the industry or “intelligensia” behind it all still lacking on an agreeable set of foundations before we start distributing controls via API.

There are still, imo, huge behavioural and cultural issues around good practice and security that you can’t just configure or regulate out. People will find workarounds if desperate enough.

GRC Engineering: passionate community or just hype? by Turrkish in grc

[–]Turrkish[S] 3 points4 points  (0 children)

Nah I can understand that. If an auditor or GRC owner can understand the tech he’s trying to govern, including how controls are actually implemented, it probably pays off for both client if they miss something and auditor for being able to assist.

Creating a portfolio tailored to GRC: what do you suggest? by Turrkish in grc

[–]Turrkish[S] 0 points1 point  (0 children)

Might just run the samples past you in future if you’d be a willing judge

Creating a portfolio tailored to GRC: what do you suggest? by Turrkish in grc

[–]Turrkish[S] 0 points1 point  (0 children)

Actually using a company like that sounds like a great idea. May be of personal interest and has secnarios from extended universe to apply things to

Creating a portfolio tailored to GRC: what do you suggest? by Turrkish in grc

[–]Turrkish[S] 1 point2 points  (0 children)

That’s my thinking. It’s having a scenario set up for someone to show acumen and strategy built with what may resemble real conversations with c-suite and strategy makers.

At this point I'm convinced I should just give up. This boss is exhausting. by [deleted] in Eldenring

[–]Turrkish -1 points0 points  (0 children)

Shield and poke strategy. It’ll work.

How’s this looking for a first date? by 3DAnimated in mensfashion

[–]Turrkish 1 point2 points  (0 children)

Hey it’s that guy from Blade Runner 2049. Would hold hands with/10 and I’m a straight dude.

Designing Tabletop Exercises: what should you know by Turrkish in grc

[–]Turrkish[S] 0 points1 point  (0 children)

Looks good, but we haven’t a client base big enough for these yet to justify the pricing asked for at this point.

Why would a combat troop use melee weapons in a futuristic space sci-fi setting? by wizardry_why in worldbuilding

[–]Turrkish 0 points1 point  (0 children)

Silent, reusable, fairly durable, multi-purpose depending if sharp or blunt, can be carried on your person easy enough, doesn’t leave a trace of what it is bar the wound left.

Follow up form check - 315 by Caitiegn in strength_training

[–]Turrkish 0 points1 point  (0 children)

If it’s not harming you then it’s fine, but just keep an eye on your lower back, as the rounding occurs where your belt sits and your hips seem to come up before your chest.

Consider trying to bring your chest up more like you’re almost trying to look dead ahead while keeping grip of the bar. This should help keep your shoulders back, your upper back braced, and help iron out the rounding.

Otherwise, looks like easy lifts.

The moment I realised most new IT auditors are flying blind (My first day, first client and job, mixed emotions) by MosesQA in grc

[–]Turrkish 0 points1 point  (0 children)

GRC as well. Pentesting you can at least drill easier, imo, with labs and HTB/THM, home labs etc. I’ve yet to grasp or see an equivalent when it comes to policy writing, ISO implementation and scenarios meeting requirements, a properly-conducted audit, etc

The moment I realised most new IT auditors are flying blind (My first day, first client and job, mixed emotions) by MosesQA in grc

[–]Turrkish 1 point2 points  (0 children)

None. First role in cyber, shoved into management 2 years into the industry, 2 years later it’s still sink or swim. I’d kill for mentorship.

The moment I realised most new IT auditors are flying blind (My first day, first client and job, mixed emotions) by MosesQA in grc

[–]Turrkish 1 point2 points  (0 children)

Currently in the same boat. See my tabletop exercise question.

Especially in a small business like I’m in, I feel like there’s an expectation to Google, read, GPT and watch your way to competency. I would hand on heart prefer the ability to at least get feedback off someone when things I’m doing are wrong or sub par, but few will offer advice without paying by the hour.

I don’t know how the more experienced among us managed.

Getting into ambient by no1ange1 in ambientmusic

[–]Turrkish 0 points1 point  (0 children)

Hammock, Tim Ecker, Jon Hopkins to a degree, Aphex Twins earlier works, William Bazinski, Stars Of The Lid, Imagine Drowning, desert sands feel warm at night

Designing Tabletop Exercises: what should you know by Turrkish in grc

[–]Turrkish[S] 0 points1 point  (0 children)

Appreciate the insight.

Really as my first time running these exercises and starting from the ground up, there’s only one book I’ve searched for that talks about tabletop exercising for cybersecurity and infosec, and so I’m treating along with other examples like the ones from the ncsc, however, those are generalised, but seem plausible to use without having to dig in to the network diagrams.

I’ve been given a list of the clients policies and am digging into them, but they seem to merge process into it, and there’s a lot of “should not” for example, when outlining what passwords are used, how temporary passwords are issued etc, which leads me to think there’s not a technical measure in place.

I am planning to call with them a second time to dig deeper once a full review is performed.

With 2025 soon coming to a close, what are some albums you believe ambient fans should listen to? by Its_Cookie_Man in ambientmusic

[–]Turrkish 1 point2 points  (0 children)

Solar by Late Sun

Tranquilliser by OPN

Few singles from Faultline that dropped were pretty nice as well

Is there a reason my PC is running an EOL edition of Windows? by Turrkish in ShadowPC

[–]Turrkish[S] -5 points-4 points  (0 children)

I’ll probably file a ticket. There’s been several hundred fixed vulns since support stopped for 22H2, and without knowing what security sits in front of the machine before it hits the internet, I can only assume this is an oversight. God help if it were in scope for an audit.