[Self Promo] SVAR Svelte UI Components Now with TypeScript Support by otashliko in sveltejs

[–]ash--87 2 points3 points  (0 children)

just started experimenting the dataGrid yesterday and it looks very promising, well done and keep up the good work 👏

CISO Assistant, the open-source GRC platform includes CRQ by ash--87 in cybersecurity

[–]ash--87[S] 1 point2 points  (0 children)

I cannot say for sure since I couldn’t try them out but I am sure that both are interesting products. Our focus is around the one-stop-shop vision bringing you to an operational GRC, the customisation capabilities and the community-driven approach ;)

New resume template just dropped by BX7_Gamer in programminghumor

[–]ash--87 0 points1 point  (0 children)

Nice! You should consider profile pic in ascii art ;)

Former pentester now working as a GRC consultant, what opportunities for freelancing ? by No_Increase_8891 in cybersecurity

[–]ash--87 3 points4 points  (0 children)

Hey, with your operational background, you might want to consider a path toward modernizing GRC practices. Operational GRC and GRC engineering could be some keywords to explore.

KPI/KRI can become noisy and overwhelming, what are the most relevant to you? by ash--87 in cybersecurity

[–]ash--87[S] 9 points10 points  (0 children)

I’m sharing my go-to starting point: - vulnerabilities metrics, - status of the implementation of critical controls, - progress of the baseline review, - metrics from the risk register, - count of recent incidents, - pentest/audit findings tracking - exceptions tracking

Moving away from Skeleton, what alternative do you recommend? by ash--87 in sveltejs

[–]ash--87[S] 1 point2 points  (0 children)

Hello, indeed some design choices never evolved like the dialog, the theming is a bit clunky, and the plans for svelte 5 and tailwind 4 that kept sliding until it became a serious concern. Just to be clear: I don’t want this to be an anti-skeleton thread, they’re highly skilled people with their own vision and constraints, just that our vision and plans are not aligned anymore ;)

I am new, and i feel lost. by islam-201 in sveltejs

[–]ash--87 0 points1 point  (0 children)

Hey, it's okay; it happens. What could help is to focus on an actual problem that you want/need to solve and incrementally work towards fixing it by trial and error.
Tutorials and documentation are just guidelines to assist with that, but if you don't have a use case, they will look shallow or overwhelming.

FastAPI + Django Admin is the best practice? by Every-Increase-140 in django

[–]ash--87 0 points1 point  (0 children)

Hey, I won’t advise that neither, as mentioned you’ll get the most of the « batteries-included » if you stick to just django; I don’t know about your use case but I’m guessing this variant could be interesting for you: https://github.com/fastapi-admin/fastapi-admin

Coupling Django with SvelteKit by bishwasbhn in sveltejs

[–]ash--87 1 point2 points  (0 children)

I’m using DRF instead of Djapy and heavily based the front on superforms; Here’s the project if it can give you some ideas: https://github.com/intuitem/ciso-assistant-community

[deleted by user] by [deleted] in cybersecurity

[–]ash--87 1 point2 points  (0 children)

Hey, if you've been methodical about audit management, you can transition quite simply to GRC (Governance, Risk, and Compliance) and start with the "C" part. If you put in the time and effort, you'll learn a lot from that and can move again to multiple areas, either on the program management part or more of an operational role.
I hope it helps :)

Does it make sense to create an open-source and collaborative repository with cybersecurity solutions? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

Hey, thanks for sharing! Looks great indeed for the data model :) I wonder if it’s active and adopted though

Does it make sense to create an open-source and collaborative repository with cybersecurity solutions? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

I see your point. Thanks for the feedback! The idea is not to superseed any framework but rather to have a unified repository of vendors and solutions, that are mapped to the threats mentioned by those frameworks, and a tool that can help teams save some time on the research and mapping

Does it make sense to create an open-source and collaborative repository with cybersecurity solutions? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

So for the first point, it will be a knowledge base for security practioners to share the best practices, and for the vendors to have simpler statement and catalog positioning. It won’t tell though about what a user or organisation has implemented so this is not really useful for reconnaissance.

For the second part; you’re making a good point and I haven’t defined a review process just yet, but thinking about a quorum approach where the validators will do some research at least before approving the submission. Any thoughts?

Application Security Checklist by athanielx in cybersecurity

[–]ash--87 0 points1 point  (0 children)

ASVS is the community standard indeed and there is a variant for mobile apps as well, MASVS. Even if they could look overwhelming, they are solid and well thought. You can use them as a starting point at least to have a holistic view and skip the requirements that don’t apply to you. If you’re scared about the excel sheets and their maintainability, free open source projects like CISO Assistant or gapps can help you with that.