Fen Labalme

358 posts

Fen Labalme

Fen Labalme

@openprivacy

FLOSS DevSecOps | Compliance as Code | Ongoing Authorization | CISSP CISO @CivicActions

Pittsburgh, PA Katılım Aralık 2008
198 Takip Edilen222 Takipçiler
Fen Labalme
Fen Labalme@openprivacy·
@sboots Two of the goals of compliance automation are to convert the documentation into a machine readable (and verifiable) format, and to shift-left its management into the software development life cycle (as we have with quality assurance).
English
1
0
1
0
Fen Labalme retweetledi
Elaine Labalme
Elaine Labalme@NewGirlInTown·
Elaine Labalme tweet media
ZXX
0
1
0
0
Fen Labalme
Fen Labalme@openprivacy·
Great line spoken at #2021cyburgh session on the Evolution of Enterprise and Personal Networks: "It's hard to secure the future while being regulated by the past." But I forgot to write down who said it for attribution when I use it. Can anyone help? @pghtech
English
0
0
1
0
Fen Labalme
Fen Labalme@openprivacy·
@konklone Traditional waterfall compliance is antithetical to security. Cultural changes like agile devsecops, ATO verification automation, live scanning and even acceptance of rolling releases will help. And zero trust is key.
English
0
0
0
0
Eric Mill
Eric Mill@konklone·
11/ Agencies will say they "assume breach", but follow-through on zero trust / least privilege remains rare. For example: monitoring "sensors" should be constrained to have read-only access, through permissions enforced by independent components. But rarely happens.
English
4
1
32
0
Eric Mill
Eric Mill@konklone·
1/ Unless the USG dramatically changes its approach to reviewing software, just doing more "vetting" of vendors will be 100% useless in catching issues like SolarWinds. Currently, it's all designed to raise the "floor" and avoid table-stakes stuff.
English
7
68
225
0
Fen Labalme
Fen Labalme@openprivacy·
The Georgetown Univerity Law Center has created state-by-state guides explaining the laws barring unauthorized private militia groups and what to do if groups of armed individuals are near a polling place or voter registration drive. law.georgetown.edu/icap/our-work/…
English
0
2
1
0
Fen Labalme retweetledi
Leif Utne
Leif Utne@leifutne·
"My most fervent wish is that I will not be replaced until a new president is installed." -Ruth Bader Ginsburg's dying wish, dictated to her granddaughter Only 46 more days till we elect POTUS #46. I'm beyond sad. npr.org/2020/09/18/100…
English
0
1
0
0
Fen Labalme retweetledi
EFF
EFF@EFF·
Everyone deserves to have affordable, high-speed Internet. The Accessible, Affordable Internet for All Act will make this a reality for people in the U.S. Tell your representatives and senators to vote yes. act.eff.org/action/tell-co…
English
4
38
86
0
Fen Labalme retweetledi
CivicActions
CivicActions@civicactions·
“Our projects may be hard, but we know they’re worth doing.” @USDS report shows how user-focused government is improving lives. We're honored to be part of this work and committed to seeking out hard projects that help the most people! @dscoalition 👇 usds.gov/resources/USDS…
CivicActions tweet media
English
0
1
5
0
Fen Labalme
Fen Labalme@openprivacy·
Come here @CivicActions (Karen and I) present "Transparent Code, Secure data" at #LibrePlanet2020 this morning at 10:40am EDT. Learn how to sell free software to the US Government, our bosses, and ourselves. Watch online at u.fsf.org/live
English
0
1
3
0
Fen Labalme
Fen Labalme@openprivacy·
I'm co-presenting "Transparent code, secure data" at #LibrePlanet2020, the FSF's conference on free software and ethical technology, March 14-15 in Boston, and I hope you'll come check it out! See the schedule at u.fsf.org/304
English
0
0
2
0