222 karma · joined May 28, 2010
This would require well staffed regulatory bodies. At least for GDPR, I don’t think we have that.
This required me to write a lot more than before, although I've always enjoyed writing.
In the beginning, I wrote beginning -> end, with just a high outline in my mind. Now, I write bullets first and then expand into paragraphs. This has helped me write a lot quicker and I think the articles have become easier to read (which matters a lot online, where everyone reads diagonally).
Worst that happened to me was a very smelly drunk..
That is the main reason I’m thinking about an electronic replacement.
Also used Hatchbox in another project (startup w customers), it definitely was worth the money.
For fun and giggles: this is what happened when I wanted to quickly build a side project after not coding for a while (using jumpstart to go faster) https://twitter.com/ddccffvv/status/1430967157404340228
I wonder how well the experimentation approach will work in this case though, as:
1. Effects might be subtle and outside of the expected impact area.
2. Timescale might be really important (effects over a time much longer than we anticipate. Or even a timescale that makes it impossible to run many experiments in reasonable time)
Seems like a high risk play, only to use as a last resort to me.
I look forward to a summary report on incidents somewhere in the future ;)
* Do you know if there are any follow up meetings planned? Did they discuss some kind of process?
* what were the main concerns discussed?
* interesting to find out about the coalition (I was briefly involved in a similar insurance setup in my home country). Is your ‘baseline’ derived from some standard? Can I find it online?
Can’t wait until the nights stabilise in a couple of months and I get my mind and my good mood back (those are the main symptoms for me).
Teaching your salespersons to help their contacts/champions with convincing their internal security to lower classification will be great ROI for you :)
The article does a great job of cutting through all the noise.
Highlighting here because it is relevant: certification is about sales.
I’d only do it once you either:
1) you spend much more time filling out questionnaires than the time/investment needed to get certified (note, they’ll still ask you to fill out questionnaires though)
2) you want to go after companies that actually care about this (banking, government). Even then, these will have shortcuts through procurement that will lower requirements (ie: innovation projects, small ticket items)
But as a techie, the magic to me no longer lies in the product building, but in the ‘finding the first 10-100’ customers part.
Have there been any posts on that lately?
It doesn't surprise me in the least that you didn't get any feedback. The default option for these companies is to make you accept their specific blend of security requirements... Of course, you then have to support that forever...
I've had good luck setting up a meeting with both the due diligence person and the actual buyer/champion present. It's often easier to explain your stance in person and the buyer is going to stop the due diligence person when he's getting into the weeds.
To me this is a non-issue, because customers almost always ask for types of security checks, not for specific tooling (ie: asking for source code analysis vs asking for veracode). As a rule, compliance/government folks will be concerned about the types of security measures you have in place and not about the specific implementation. Commercial source code analysis tools have varying support depending on language (as others have mentioned: some languages are harder than others). A very valid alternative is to use a linter with security checks (and potential custom rules). The advantage will be that checking will go much faster so you can do it more often (every PR instead of nightly for example). Many security conscious companies have something like this in place.
In general when you're answering security due diligence, it's your job to convince the customer you're going to keep their data safe. They will ask about certain things you don't have and it's your job to explain how you're still solving the underlying problem. Typical example: customers asking for antivirus on all systems and you using (immutable) docker containers.
By the way, the interesting thing here is not the answers to the questions, but how you organise your company to quickly and effectively (as in: no follow up meetings or worse: action plans) answer them. My pet peeve here is "customer guided security": You start from what you think you need (baseline) and you add the security measures that take the longest to explain why you don't have them. That way, you're skating through most of the due diligences and sales velocity goes up, which will make your bosses very happy.
In these cases, having notes will prevent scope creep and will be necessary to have customers accept the work. Customers will forget what was discussed and what was agreed to. They will want to add that "one last thing" just when you're expecting to close the project.
Even in different roles (or internally), I think many would benefit from writing down meeting notes because it anchors the discussion and creates shared understanding. Voice only will cause many to forget specifics or move the goal.
I don't think OP is in favor of writing a book for every meeting. Having notes / documentation will make you more effective. It will also lower the frequency of you and the other party having different expectations. It's a good habit to have for these reasons and the many others outlined in this thread.
To quote Edison: "Genius is one percent inspiration, ninety-nine percent perspiration". The article explains Mathilde's approach. I'm impressed with her rigorousness and consistency. It's a great way to build trust both internally and externally.
Building something (anything) from scratch to _really_ complete is an exercise in persistence. Being in the same boat right now, I admire her for what she's doing and how she's doing it.
Also: there’s a guidance document for authorities here: https://ec.europa.eu/newsroom/just/document.cfm?doc_id=47889
EU law does not work with exact codified procedures, which I understand is more common in US. So indeed, you will find guidance but not exact procedure (though it seems to be clear enough to me)
EDIT: article 83 instead of 82
Although I’d also like the list of subprocessors, that’s often needed and can’t find it on that site (at first glance)
Background: I would like to start or buy a recycling business because I want to be part of the solution instead of the problem (and if it can make a profit, I'm not independently wealthy). Yes, I know we need to reduce and reuse first, but we're now also sitting in a mountain of plastic and given inertia, it's not going to go away anytime soon.
I did read this one already [1], which I recommend to get a basic understanding of the various forms of recycling and the profitability.
[1] https://www.amazon.co.uk/gp/product/1569906769/ref=ppx_yo_dt...
Question: is there a reason we would choose a solver like this instead of encoding the effects in prolog and let it generate plans for us? Why would one approach be better than the other?
The EU (you might be surprised to learn) also recognises the freedom of speech (in fact it's a universal human right, see [2] article 19). However, this does not mean GDPR is not valid law, just as I have a hard time understanding how the first amendment would prohibit privacy laws to exist.
[1] https://en.wikipedia.org/wiki/United_States_free_speech_exce...
[2] http://www.un.org/en/universal-declaration-human-rights/
You can forever keep the chip on your shoulder here: https://teamsecondchance.threadless.com/
* Profit (if any) will go to a charity we can decide upon in the thread below. I nominate doctors without borders because they always do good work.
* Help with design is appreciated. I'm just a clueless engineer...
* Should you spend time designing a better version, the thought might occur to you that you are not spending that time on your startup and that might be a reason why you're team 2nd chance... ;-)
For example: it's amazing how much discussion there is around using paper cups vs a ceramic cup. Or when plastic actually might be the best packaging material (keeping food fresh for longer and being lighter to transport).
Can anyone here point to non-biased, well researched articles on this topic? I would imagine academia is a good place, but I don't know where to start.