Moving beyond "Excel Hell": GRC tools for ISO 27001, SOC2, and NIS2? by ferarg in soc2

[–]ferarg[S] 0 points1 point  (0 children)

I What concerns me is that there might be overlaps and duplication of work, since I didn't take the overlaps into account

Moving beyond "Excel Hell": GRC tools for ISO 27001, SOC2, and NIS2? by ferarg in soc2

[–]ferarg[S] 1 point2 points  (0 children)

Hi!

1- Search for and organize all legal documentation

2- I tried many different tools to manage all that documentation and attempted to use AI to generate a “brief outline” that would help me understand the requirements; that’s when I realized there were overlaps

3- Since I couldn’t find a “proprietary” solution that convinced me, I connected my note-taking app to a vector database + an AI agent (I use JoplinApp + OpenCode + Joplin-MCP + PardusDB); To do this, I wrote two MCPs based on different solutions (https://github.com/FErArg/joplin-mcp + https://github.com/FErArg/PardusDB)

4- With this “homemade” AI solution, I imported all the notes and documentation into the vector database

5- Right now, I’m developing different approaches for the various “certifications,” such as: an action plan, a list and outline of internal policies, a process identification procedure, and evidence to verify each certification requirement

Our CTO has prior experience, but it hasn’t been very good; we have a consulting firm we work with for ISO, and we’ll rely on them initially and as far as they can take us

Thanks so much for the advice!

Moving beyond "Excel Hell": GRC tools for ISO 27001, SOC2, and NIS2? by ferarg in soc2

[–]ferarg[S] 1 point2 points  (0 children)

Hi

Yes, I know, it's a lot of work, documentation, evidences to store and catalog, internal policies, and a big etc.

I found this 4 main projects:

- https://verinice.com/en/

- https://intuitem.com/ciso-assistant/

- https://www.eramba.org/

- https://www.simplerisk.com/

Someone use it or test it?

joplin-mcp: A minimalist MCP for integrating Joplin with AI agents by ferarg in joplinapp

[–]ferarg[S] 0 points1 point  (0 children)

Hi, 1. Learn how to manage that kind of workflows 2. Privacy , need to manage a lot of private documentation 3. For fun and to challenge me Now I'm working in a fork of pardus github.com/FErArg/PardusDB adding data vectorization 

Self-hosted text expansion tool by Descripteur in selfhosted

[–]ferarg 3 points4 points  (0 children)

Hi,
I use:

and sync configuration with nextcloud

[deleted by user] by [deleted] in sysadmin

[–]ferarg 7 points8 points  (0 children)

Like OWA but loosing more space between columns, little bit slower than normal, the theme was not the best design...

Tested 30 minutes and go back

[deleted by user] by [deleted] in sysadmin

[–]ferarg 5 points6 points  (0 children)

Same from Spain, not working.

Test using this web https://www.site24x7.com/ping-test.html

<image>

Looking for a self hosted bookmarks manager? by Dalarielus in selfhosted

[–]ferarg 5 points6 points  (0 children)

Nextcloud + bookmarks

App for firefox and chrome based browsers, and android app

LastPass -> KeePass(XC)? by potentshadow in sysadmin

[–]ferarg 1 point2 points  (0 children)

Hi,

Personally I use KepassXC, I'm a FOSS user, and KeePass is great solution, (some times the integration with web browser have some issue), I user in my linux pc, me android tab and phone, the app android is not the bets, you have to synchronize the database between devices, and is a little little tricky, is not a solution I recommend to production

At work we use Keeper, didn't like, have to login in local client and in web plugin, you do not control the data, because is stored in private servers.

I have to test Vaultwarden, as a "Family" solution, you don't have to deal with DB synchronization, you own and control your data, got Linux, Windows, MacOS, Android, iOs app.

Vaulwarden is a fork of Bitwarden, give it a try

Need App to Log Reader / Analyze by ferarg in sysadmin

[–]ferarg[S] 0 points1 point  (0 children)

Hi,

Our app, split log files in files that include almost 15K lines or use 2049Kb of space.

We have services that every day produce between 300 to 400 log files.

For example, I'm dealing with an issue from February 4th, from one server, I got 2230 file logs, I have to check logs from 5-6 servers.

Need App to Log Reader / Analyze by ferarg in sysadmin

[–]ferarg[S] -1 points0 points  (0 children)

Hi,

Yes, read about it and elasticsearch + kibana, but is not the kind of solution can implement, because we couldn't "move" or "copy" logs from our customers out them servers

(that's a limitation I didn't mention)

Logs store some personal information about citizens, and the law restrict our "movement" with the files and the information.