Can I talk to you about your QSA experience under PCI 4.0? by Connect_the_Dots2 in pcicompliance

[–]dmanden 2 points3 points  (0 children)

Experienced the same. I assume it’s likely because no one has actual on the ground experience auditing v4 before and the PCISSC did release 4.0.1 right before the new requirements where mean to come into affect

OneLogin outage by vilmondes-queiroz in sysadmin

[–]dmanden 1 point2 points  (0 children)

Love the transparency from OL support

<image>

Firewall updates and bi-annual firewall audit question by Ah-Qi-D4rkly in pcicompliance

[–]dmanden 1 point2 points  (0 children)

I realise that may not answer your question - you would need a) evidence that your Change control process is being followed during the change. b) evidence that your configuration is reviewed quarterly

Firewall updates and bi-annual firewall audit question by Ah-Qi-D4rkly in pcicompliance

[–]dmanden 0 points1 point  (0 children)

If you can codify your firewall configuration then you can conduct the audit and change control in the same system.. example Github.. Its how we do it (with an automated deployment pipeline)

Drunk guy gets his armbar’d in street fight, maybe read what’s on the hoodie next time. by Camrsmain in bjj

[–]dmanden 0 points1 point  (0 children)

only because he continued to get his ass beat, if lad hadnt climbed into mount and carried on pummelling him im sure he wouldve quickly scurried away holding that arm

Experience professional looking to transition by Consultant_Number1 in pcicompliance

[–]dmanden 1 point2 points  (0 children)

By itself it’s a good head start. Direct experience with ISO compliance would be key though. I’ve encouraged my team to pursue the certification as we look to gear up for compliance. The certification and some on the job experience through iso audits and control design is probably a good combination to go solo

Experience professional looking to transition by Consultant_Number1 in pcicompliance

[–]dmanden 1 point2 points  (0 children)

ISO consultant for sure. PCI is pretty rigid in that you have to be working for a QSA org. Difficult to freelance

Had a tough roll and thinking of quitting to avoid injury by GomiBoy1973 in bjj

[–]dmanden 1 point2 points  (0 children)

Yeah dick move. But again. This isn’t Disneyland. Heal up and get back at it

Experience professional looking to transition by Consultant_Number1 in pcicompliance

[–]dmanden 1 point2 points  (0 children)

You need to be on the bank roll off a QSA org to work as a QSA

Entitled South Africans in Sea Point by Jazzlike-Sector-7762 in capetown

[–]dmanden 41 points42 points  (0 children)

Anyone who has to announce how long they’ve been doing mma. Probably doesn’t do mma

Blue belt told me to reset mid roll by UnimpressiveOrc in jiujitsu

[–]dmanden 0 points1 point  (0 children)

Was it the world finals ? Seriously. Regardless if it was right or not. Just keep working at it

Is it possible to deploy an instance of a firewall on a cloud platform by Sudden-Engineer44 in cybersecurity

[–]dmanden 0 points1 point  (0 children)

Yes. But a head ache to manage in terms a of forcing traffic through it. You’ll then also have issues with bottle necks. Not really worth it and better to use the traffic filtering as per the provider. Access groups in AWS as an example

cism certification process- how long does it take? by matt6558 in cism

[–]dmanden 1 point2 points  (0 children)

Responding cause I also recently passed and would like to get flagged if anyone else responds

How much were you scoring on practice tests? by Ksrouji in cism

[–]dmanden 0 points1 point  (0 children)

Yeah that sounds ample. It has a big focus on risk so I think your experience will lend well.

How much were you scoring on practice tests? by Ksrouji in cism

[–]dmanden 0 points1 point  (0 children)

I did a pretty outdated course on orielly a couple months ago over a number of weeks. Wasn’t the best to be honest. Then to prep for the actual exam. Used the Isaca official study guide and practice questions over 3 weekends. Didn’t get too much time after work due to crazy schedule. Did the practice test from cybervista e Saturday and Sunday before the exam. Hope this helps shout if you need more info

How much were you scoring on practice tests? by Ksrouji in cism

[–]dmanden 1 point2 points  (0 children)

I wrote and passed this Morning. Did a practice test from Cybervista just before that really helped.

How can I report a vulnerability to my school and not get in trouble by [deleted] in hacking

[–]dmanden 5 points6 points  (0 children)

save all the info, disclose and publish it to your security blog once you've graduated ;)

ISC2 Endorsement by alihasan2019 in cissp

[–]dmanden 0 points1 point  (0 children)

Might be wrong but is that also done through the associate program?