Most of these compliance just seem like barber licenses. A way for existing entities entrench themselves.
Most of these compliance just seem like barber licenses. A way for existing entities entrench themselves.
The people running these programs rarely understand the security space well enough to even tell you what a lot of the hits even mean, which ramps up disdain and division between the groups. This is arguably more detrimental to security as the scanners give execs/management a false sense of security while the noise makes it incredibly difficult to run a holistic security strategy.
ETA: like I told my kids, if we don't police each other, the LLMs will never learn. ;)
IMO, nothing. It's not redeemable at all. Since you asked though, here is some thoughts:
Be more like FDA process where software is extensively reviewed, rollback procedures established, and you launch specific version with compliance. So basically two releases, maybe 4 a year.
Disallowing risk mitigation because IMO, that's result of most of problems. Oh yea, we are doing "Terrible Security thing but since fixing is too expensive, here is a bunch of lies about how we have mitigated it."
There is also option to make a government audit with criminal liability for falsifying/misleading auditors. This third-party system where auditors are getting paid results in problems. I've seen plenty of audits where bosses write up auditor requests is extremely specific ways that creatively leave out thing that should never be approved. I've also seen auditors be made aware of problem, then people backtrack, and auditors accept it because "They are also our customer and we need repeat business."
What happens when Vanta/Drata are compromised?
A mass-exploit of their customers?
Edit: Their software should really check and refuse to work if someone does that but obviously Vanta doesn't care. They can begin scanning and billing.
Thanks for the feedback. What we should probably do is take the credential, start scanning, and then nag them with a failing test about overly-permissive roles. Our own role is an easy check because we know what to expect, but there's other best practices here we can check for (and in some cases do, though not 100% comprehensively across all clouds.)