• 0 Posts
  • 12 Comments
Joined 1 year ago
cake
Cake day: July 1st, 2023

help-circle


  • It certainly is. ISO 27001 is a framework, not very prescriptive at all. Basically an auditor will ask “how do you ensure data isn’t leaving your facility in the form of discarded hardware?” If you say “here’s a link to our media destruction policy. It says all drives are wiped according to NIST 800-88 cryptographic erasure. If that is not possible or not applicable, the drive is destroyed. Here’s our log of decomissioned equipment” chances are very good they’ll say “OK great let’s move on to the next one” with only minor followup questions.






  • As someone who also has 15+ years of experience in the field and is currently infosec management, it’s not that bad. Certainly not something I’d say “you’re in for a world of hurt” about like somebody just bought a bad timeshare.

    Especially if you’re not hosting production email for a company and you’re not leaving the server as an open relay, it isn’t very painful at all.

    You could also be less condescending, but as you said: your call. :)





  • Personal preference: Jellyfin instead of plex

    Some that I run that you don’t seem to have anything for:

    • Lancache (if you have several gaming PCs on the network or host any kind of lan party)
    • surveillance camera software e.g. shinobi
    • I see grafana, but other monitoring services like icinga, librenms, etc
    • Mayan EDMS - I’ve found this really helpful as anything I get in the mail, I scan in, and this makes it all searchable and retrievable.
    • There’s a whole hole you could dig if you start getting into home automation (I use home assistant)