• 0 Posts
  • 19 Comments
Joined 3 years ago
cake
Cake day: July 1st, 2023

help-circle


  • Exactly. Maybe one of your less close friends turns out to be a serial killer. Unbeknownst to you now you’ve made some jokes and had brunch with them. Now a team of cops is going through everything you’ve ever texted anyone because it’s unencrypted, correlating things to make you look horrible. Suddenly you’re getting your life ruined.

    There are cases of innocent people riding their bikes past an unknown crime scene getting arrested for murder because their phone was reporting their location to Google. Try explaining to your boss that you’re missing work today because you’re in jail for a murder charge. Privacy is important even when you think it’s not and perhaps especially when you think it’s not
















  • It certainly is. ISO 27001 is a framework, not very prescriptive at all. Basically an auditor will ask “how do you ensure data isn’t leaving your facility in the form of discarded hardware?” If you say “here’s a link to our media destruction policy. It says all drives are wiped according to NIST 800-88 cryptographic erasure. If that is not possible or not applicable, the drive is destroyed. Here’s our log of decomissioned equipment” chances are very good they’ll say “OK great let’s move on to the next one” with only minor followup questions.