mathie25 | 4 years ago | on: Ask HN: Is the ISO 27001 certification worth it?
mathie25's comments
mathie25 | 4 years ago | on: Ask HN: Is the ISO 27001 certification worth it?
Thus, a lot of times, to sign customers, you need to be secured, as an IT/Security department can easily shut down any SaaS project if it is not secure enough. Having a certification like ISO 27001 or a report like SOC2 can really be helpful, and is sometimes a necessity. So ask yourself "does our company needs a SOC2/ISO 27001 to sign customers? Is it a blocker for our business?". You never want to achieve compliance "just because", you need a business reason to do it.
We started building our security program (ISMS) based on ISO 27001 (which is a really good basis in my opinion), but decided to get a SOC2 report instead. We started with a SOC2 type I report, then a type II. I personally find that a SOC2 is much more flexible than an ISO 27001 certification.
We mainly deal with big European customers, and SOC2 and ISO 27001 are seen as equal; never had a problem there. Most customers don't even read the report to be honest; it's a check in a box.
Having a SOC2 report or ISO 27001 certification shows that you care about security, and it sets the tone from the start.
mathie25 | 5 years ago | on: Joe Rogan Is the New Mainstream Media
mathie25 | 5 years ago | on: Ask HN: “Git” for Microsoft Office?
mathie25 | 6 years ago | on: Ask HN: How do you share passwords simply and securely?
Is it possible to use our own hosted Firefox send? Thanks!
mathie25 | 6 years ago | on: Ask HN: How do you share passwords simply and securely?
We mainly used it on Slack. We made a slash command (/secret) to easily share passwords on Slack.
So the only thing you need to do is write /secret YourPassword.
After that, you need to be authenticated via Google SSO as we added a proxy. Yes, we know, the password goes through Slack.
mathie25 | 6 years ago | on: Collection of awesome projects, blog posts, books, and talks on quantifying risk
Additional interesting ressources: - Implementing Enterprise Risk Management by James Lam https://www.amazon.ca/Implementing-Enterprise-Risk-Managemen... - Protivi Guide to Enterprise Risk Management https://www.protiviti.com/sites/default/files/protivitierm_f...
mathie25 | 6 years ago | on: Don’t Put Your Work Email on Your Personal Phone
mathie25 | 7 years ago | on: Design checklist for perfect charts
mathie25 | 7 years ago | on: Design checklist for perfect charts
mathie25 | 7 years ago | on: Microservices, Containers and Kubernetes in Ten Minutes
mathie25 | 7 years ago | on: Launch HN: Scribe 2.0 (YC W17) – Configurable, Actionable Alerts on Slack
mathie25 | 7 years ago | on: How Alexa knows “peanut butter” is one shopping-list item, not two
mathie25 | 7 years ago | on: Ask HN: Best practices for onboarding new employees?
Before the onboarding: - we make sure all access has been give to every SaaS/software/etc needed for the employee to be able to work day one. We have defined a list of access needed for each job (engineering, finance, customer success, etc). - we make sure that we have all necessary hardware (e.g macbook, screens, keyboard etc.) and that all necessary software/update are already there.
Onboarding day: - First meeting is about presenting our company, what we do, our values, the market in which we work, etc. - Second meeting is finalizing the computer setup (e.g. password) - Third meeting is about security (my job). I'm presenting security, talking about our policies and etc. It's a pretty lightweight discussion. - Fourth meeting is the HR meeting (e.g. sign the NDA, talk about insurance, etc.) - Final meeting is a presentation of our application.
All along the day, we make it clear that they can ask any questions, anytime.
After the onboarding: 1 week after the onboarding day, we sent a survey about the onboarding day (what did you like, what could be improved, etc.). Only the Head of HR see this (for confidentiality).
mathie25 | 8 years ago | on: Facebook announces Clear History feature
If you conduct business with an individual, most of time, your legal basis will be the Legitimate interests of both parties, you should only rely on consent for non-necessary part/service (like subscribing to a newsletter, or sharing information for improving the service).
For a good summary of that, I would recommand this ICO document: https://ico.org.uk/media/about-the-ico/consultations/2013551...
mathie25 | 8 years ago | on: Ask HN: How to securely send documents
It's also open source
mathie25 | 8 years ago | on: Facebook CEO says no plans to extend all of GDPR globally
mathie25 | 8 years ago | on: Into the Breach’s interface was a nightmare to make and the key to its greatness
mathie25 | 8 years ago | on: Ask HN: How will you manage your digital assets when you die?
So it would mean that companies would not be obliged to comply with GDPR.
mathie25 | 8 years ago | on: How GDPR Will Change The Way You Develop
Quote from GDPR, page 5, recital 23 (http://www.privacy-regulation.eu/en/recital-23-GDPR.htm). I'm no lawyer, but that's the way I'm understanding it.