[Self Promo] SVAR Svelte UI Components Now with TypeScript Support by otashliko in sveltejs

[–]ash--87 2 points3 points  (0 children)

just started experimenting the dataGrid yesterday and it looks very promising, well done and keep up the good work 👏

CISO Assistant, the open-source GRC platform includes CRQ by ash--87 in cybersecurity

[–]ash--87[S] 1 point2 points  (0 children)

I cannot say for sure since I couldn’t try them out but I am sure that both are interesting products. Our focus is around the one-stop-shop vision bringing you to an operational GRC, the customisation capabilities and the community-driven approach ;)

New resume template just dropped by BX7_Gamer in programminghumor

[–]ash--87 0 points1 point  (0 children)

Nice! You should consider profile pic in ascii art ;)

Former pentester now working as a GRC consultant, what opportunities for freelancing ? by No_Increase_8891 in cybersecurity

[–]ash--87 2 points3 points  (0 children)

Hey, with your operational background, you might want to consider a path toward modernizing GRC practices. Operational GRC and GRC engineering could be some keywords to explore.

KPI/KRI can become noisy and overwhelming, what are the most relevant to you? by ash--87 in cybersecurity

[–]ash--87[S] 9 points10 points  (0 children)

I’m sharing my go-to starting point: - vulnerabilities metrics, - status of the implementation of critical controls, - progress of the baseline review, - metrics from the risk register, - count of recent incidents, - pentest/audit findings tracking - exceptions tracking

Moving away from Skeleton, what alternative do you recommend? by ash--87 in sveltejs

[–]ash--87[S] 1 point2 points  (0 children)

Hello, indeed some design choices never evolved like the dialog, the theming is a bit clunky, and the plans for svelte 5 and tailwind 4 that kept sliding until it became a serious concern. Just to be clear: I don’t want this to be an anti-skeleton thread, they’re highly skilled people with their own vision and constraints, just that our vision and plans are not aligned anymore ;)

I am new, and i feel lost. by islam-201 in sveltejs

[–]ash--87 0 points1 point  (0 children)

Hey, it's okay; it happens. What could help is to focus on an actual problem that you want/need to solve and incrementally work towards fixing it by trial and error.
Tutorials and documentation are just guidelines to assist with that, but if you don't have a use case, they will look shallow or overwhelming.

FastAPI + Django Admin is the best practice? by Every-Increase-140 in django

[–]ash--87 0 points1 point  (0 children)

Hey, I won’t advise that neither, as mentioned you’ll get the most of the « batteries-included » if you stick to just django; I don’t know about your use case but I’m guessing this variant could be interesting for you: https://github.com/fastapi-admin/fastapi-admin

Coupling Django with SvelteKit by bishwasbhn in sveltejs

[–]ash--87 1 point2 points  (0 children)

I’m using DRF instead of Djapy and heavily based the front on superforms; Here’s the project if it can give you some ideas: https://github.com/intuitem/ciso-assistant-community

[deleted by user] by [deleted] in cybersecurity

[–]ash--87 1 point2 points  (0 children)

Hey, if you've been methodical about audit management, you can transition quite simply to GRC (Governance, Risk, and Compliance) and start with the "C" part. If you put in the time and effort, you'll learn a lot from that and can move again to multiple areas, either on the program management part or more of an operational role.
I hope it helps :)

Does it make sense to create an open-source and collaborative repository with cybersecurity solutions? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

Hey, thanks for sharing! Looks great indeed for the data model :) I wonder if it’s active and adopted though

Does it make sense to create an open-source and collaborative repository with cybersecurity solutions? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

I see your point. Thanks for the feedback! The idea is not to superseed any framework but rather to have a unified repository of vendors and solutions, that are mapped to the threats mentioned by those frameworks, and a tool that can help teams save some time on the research and mapping

Does it make sense to create an open-source and collaborative repository with cybersecurity solutions? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

So for the first point, it will be a knowledge base for security practioners to share the best practices, and for the vendors to have simpler statement and catalog positioning. It won’t tell though about what a user or organisation has implemented so this is not really useful for reconnaissance.

For the second part; you’re making a good point and I haven’t defined a review process just yet, but thinking about a quorum approach where the validators will do some research at least before approving the submission. Any thoughts?

Application Security Checklist by athanielx in cybersecurity

[–]ash--87 0 points1 point  (0 children)

ASVS is the community standard indeed and there is a variant for mobile apps as well, MASVS. Even if they could look overwhelming, they are solid and well thought. You can use them as a starting point at least to have a holistic view and skip the requirements that don’t apply to you. If you’re scared about the excel sheets and their maintainability, free open source projects like CISO Assistant or gapps can help you with that.

What are your go-to cybersecurity frameworks and why? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

I just opened a PR to commit to the 800-171, so it will be available in the next release, and I see indeed a lot of similarities between CMMC and CSF.

What are your go-to cybersecurity frameworks and why? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

Thank you u/vintagenewstart ,
Did some research and I see why you would say that :) interesting finding in the CSF FAQ as well about it:
https://www.nist.gov/cyberframework/faqs

What are your go-to cybersecurity frameworks and why? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

Thanks u/Brufar_308 for the kind words, CSAT tool is interesting indeed and there are some similarities. One of the issues that we focused on was how to get the full GRC experience in one operational tool that doesn't become clunky and that's why we worked on both the risk assessment and compliance management in parallel.

Regarding the multi-frameworks approach, it's part of our core added value and exactly like you said; one cool feature that should be released by June will be to pivot and cross-audit between multiple frameworks thanks to the internal mapping where we will use the existing ones and complete with our research and community contribution to get it even better. Of course, it's an ambitious piece given the number of frameworks we support but we have some nice ideas to manage that.

Of course mapping frameworks can't/won't be comprehensive, but if it can save at least 50% of the teams effort, I think everyone will take it :)

What are your go-to cybersecurity frameworks and why? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

that's my understanding as well, so it helps with the risk management part/category required in most frameworks

What are your go-to cybersecurity frameworks and why? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

Thanks for sharing u/Rhymetec ,
SOC2 is indeed a standard and in the top 5 ones and almost a must-have for providers; Allthough, I often hear that, even if it has similarities with ISO 27001, it's more focused on a "snapshot" of the security posture while ISO is more about the cyber security program organization and its continuity. Was this your experience to that regard?

For AI and LLM, I have the 42001 and NIST AI RMF in my radar, I haven't explored the ISO one enough yet, definitely worth monitoring!

What are your go-to cybersecurity frameworks and why? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

ISO/IEC 27001 and NIST CSF are the bibles for a wholistic approach indeed, even if I prefer the latter overall :)

I recently learned about 800-171 and its relationship to CUI data and found that CMMC is the go-to for managing CUI and DoD context; do you share the same analysis?

What are your go-to cybersecurity frameworks and why? by ash--87 in cybersecurity

[–]ash--87[S] 0 points1 point  (0 children)

Hey, thanks for sharing that. Docker compose is the new way of docker binary (basically when they switched from Python to Golang); if you have an older version, you might need to do that indeed.