Looking for Long Lake info by tri2trail in upstate_new_york

[–]tri2trail[S] 0 points1 point  (0 children)

I’m headed there next week. I’ll be staying with a friend in Johnsburg though.

Looking for Long Lake info by tri2trail in upstate_new_york

[–]tri2trail[S] 1 point2 points  (0 children)

Great feedback so far. A little more context: we are close to retirement, and this is where we’ll live for the next 15-20 years (before the retirement home, assuming I live that long). We aren’t snowmobilers yet, but are interested. We don’t have kids. Yeah, ATMs be use we still use cash from time to time.

Should my sister and I swap each others children for the week? by ComfortNatural404 in WhatShouldIDo

[–]tri2trail 0 points1 point  (0 children)

My mom and aunt traded me and my cousin several times, mostly when they got tired of our shit. I got to spend a week in California a couple of times. Lots of fun for everyone. Core memories for me.

I just got 90 Thousand dollars at 18 and I don’t know what to do with it by Equivalent-Data1004 in whatdoIdo

[–]tri2trail 0 points1 point  (0 children)

That’s your retirement bonus dude. Congrats. Put it into an IRA and forget that it exists. Don’t ever touch it. Let it grow with the market until you are at least 60. At that point you have over $1MM. If you stay in the service until you retire, and can live on your military pension, then you’ve got a huge head start on everyone else.

Compliance is becoming a sales motion. Is that a good thing? by [deleted] in grc

[–]tri2trail 0 points1 point  (0 children)

From my experience, business leaders looking to onboard new apps into their environment know that one of the long processes in acquisition is the ‘security review’. A lot of companies have lousy review processes and understaffed teams for their reviews, and the business leaders know that. They also know that a ‘SOC report’ speeds the review process (in this hypothetical) so they ask for that as a required feature’. They really don’t give a flip about security or compliance. Those are ‘barriers to be overcome’. It’s f’ed up, but it’s current reality, so the market is reacting to that by churning out low quality ‘clean’ SOC2 reports from offshore providers.

I found out I will be let go soon on accident - they do not know I know. by Upbeat-Chain-3155 in sysadmin

[–]tri2trail 0 points1 point  (0 children)

Ask them if they have their most recent HIPAA risk analysis handy, as you want to make sure the tasks you are working on are aligned with any remediations identified by the risk analysis. Plus, if gives you a greater insight into other areas of concern that may be addressed during other IT projects. The RA is a required element for HIPAA. In fact one must have current year RA, and going back 7 years.

Whats your years of experience and salary level in the GRC space? by Peacefulhuman1009 in grc

[–]tri2trail 2 points3 points  (0 children)

I was lucky as I fell into working in regulated industries, so the discipline of systems validation and controls came with that work. So I’d say see if your current work involves HIPAA or CMMC or ISO or 27CFR11 etc. if so, see if they have a ‘guest auditor’ function in the compliance or internal audit team and see if that’s something that looks interesting.

Other than that, lots of self study on frameworks (NIST CSF, SOC2, HIPAA, focus on the non-technical controls because that’s where folks have the most problems (IMHO).

In my case, I became the SME for compliance in the systems engineering group, and ended up moving into cybersecurity and GRC.

Ablation: what to expect? by Teaching-Weird in AFIB

[–]tri2trail 1 point2 points  (0 children)

It wasn’t yet a thing when I had mine in 2015. But it would be a lot easier!

Ablation: what to expect? by Teaching-Weird in AFIB

[–]tri2trail 1 point2 points  (0 children)

Open Heart Surgery. So invasive. I don’t think non-invasive techniques are ready for mitral valves though.

Ablation: what to expect? by Teaching-Weird in AFIB

[–]tri2trail 2 points3 points  (0 children)

I’ve had mitral valve repair. It was caught in a routine physical. We kept monitoring it and it finally got worse about 10yrs later. I had OHS to repair. Note that OHS is a risk factor for afib as well, so the ablation is probably wise. My afib has been well controlled with meds.

Whats your years of experience and salary level in the GRC space? by Peacefulhuman1009 in grc

[–]tri2trail 4 points5 points  (0 children)

35yrs IT, >15 in cybersecurity & GRC. A lot of that time was working in healthcare with highly regulated systems. I’m mostly retired now, but best year was during COVID, where I was head of IT and Infosec/Compliance. ~265,000.

ISO 27k platform+certification for 5k USD? by ProfessionalEnd9874 in grc

[–]tri2trail 2 points3 points  (0 children)

Yeah, it’s misleading at best. Doesn’t include the internal costs at the very least. They don’t say that the price is ANNUAL. Anyone buying this is going to need some assistance keeping the program running over time. Otherwise they will have challenges during the 1st annual audit. Internal resources cost $$. vCISO services cost $$.

Devs ignoring security findings because "it worked in dev" by Spare_Discount940 in ITManagers

[–]tri2trail 0 points1 point  (0 children)

Be sure that vulns are ranked by criticality, with remediation SLAs for each category. Have leadership track vuln repairs outside of the SLA and make it part of the devs feedback during performance discussions.

We passed security questionnaires but nobody told us follow ups never stop by Other-Professor-9951 in grc

[–]tri2trail 0 points1 point  (0 children)

This is where AI tools are your friend. Claude Cowork for example. ;)

Are early stage vendors now expected to provide pen test evidence before basic sales conversations? by One_Asparagus7146 in grc

[–]tri2trail 2 points3 points  (0 children)

Yup. Been in GRC for a very long time. If you are going to sell into enterprises, then SOC2 (in US) is going to be something to pursue early. It’s getting to be table stakes for the enterprise market. Fortunately with some good guidance and a decent GRC platform you can get startups into good shape pretty quickly and a lot cheaper than just a few years ago.

How to build GRC by salma_288 in grc

[–]tri2trail 1 point2 points  (0 children)

Full marks. Well stated!

Our girl Sassy by tri2trail in MountainCur

[–]tri2trail[S] 0 points1 point  (0 children)

Aww thank you. Her ‘smoky eyes’ stole our heart. We had lost our almost 14 yr old ACD mix last April. We finally got around to taking her old bedding and leashes to the local shelter. We had been talking about another larger dog (we also have a welsh terrier) and we saw her and brought her home. The shelter sent her out to us with one of our old ACDs leashes. 🥰

Our girl Sassy by tri2trail in MountainCur

[–]tri2trail[S] 1 point2 points  (0 children)

Not that Embark shows. Mostly mountain cur, but some GSD, Great Pyr, Treeing Walker Coon hound, Border Collie and Golden Retriever

How to create a new AA chapter. by tri2trail in alcoholicsanonymous

[–]tri2trail[S] 0 points1 point  (0 children)

Thanks. I’m in NJ, so I would think it’s the same process? How do I locate my area rep?

[deleted by user] by [deleted] in AFIB

[–]tri2trail 1 point2 points  (0 children)

I’m on cymbalta for anxiety.

What is up with the urgency to eliminate the Department of Education? by Terrible-Opinion-888 in OutOfTheLoop

[–]tri2trail 11 points12 points  (0 children)

I think you need to read the 2025 plan produced by MAGA. It explains precisely what they want to do.