Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Virigoth
Apr 28, 2009

Corona rules everything around me
C.R.E.A.M. get the virus
In the ICU y'all......




How is the AWS openjdk version? Have you tested it any?

Adbot
ADBOT LOVES YOU

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:
someone talk to me about SOC 2 compliance.

I've just been asked (and will officially be asked tomorrow) to take over for consultant preparing this SaaS shop for SOC 2 compliance. It's part of a business division and split into a new company/new domain. I'm designing their domain architecture, updating their logging/SIEM infrastructure, implmenting role based security, that sort of thing. But otherwise I don't know poo poo about SOC 2 other than general security best practices and some pretty useless free PDF checklists.

betterinsodapop
Apr 4, 2004

64:3
Recommendations for VPN? Currently using the Win10 built-in VPN. We use Meraki for our network poo poo.
Buddy of mine suggested PureVPN.

The Fool
Oct 16, 2003


What are you trying to do? You say you're using the built-in VPN client but talk about using a hosted VPN service instead? What's wrong with the built-in Meraki client VPN service?

Nuclearmonkee
Jun 10, 2009


The Fool posted:

What are you trying to do? You say you're using the built-in VPN client but talk about using a hosted VPN service instead? What's wrong with the built-in Meraki client VPN service?

Yeah built in OS client vpn connecting to a meraki MX seemed to work fine when I messed with it at my last job. If you just need basic remote access VPN functionality it works perfectly fine.

freeasinbeer
Mar 26, 2015

by Fluffdaddy

The Iron Rose posted:

someone talk to me about SOC 2 compliance.

I've just been asked (and will officially be asked tomorrow) to take over for consultant preparing this SaaS shop for SOC 2 compliance. It's part of a business division and split into a new company/new domain. I'm designing their domain architecture, updating their logging/SIEM infrastructure, implmenting role based security, that sort of thing. But otherwise I don't know poo poo about SOC 2 other than general security best practices and some pretty useless free PDF checklists.

Run.

Edit: I got through it as a sass shop and the only infra guy on staff and it’s a nightmare of bullshit that will eat up your time. Your company will also cheap out on auditors who don’t comprehend any sort of cloud stuff and anything that isn’t a 100 person team with dedicated folks for networking, security and compliance. Your company thinks it needs it for that big deal but has no idea what goes into it and if it’s a startup it’s a big waste of time at this point.

There are even stuff built in to it that look for things like fully staffed ccb’s, having executive sign off and separation of duties.


Edit2: our saving grace was infra as code through terraform and ansible. If your doing this on Windows may *diety of choice* help you.

freeasinbeer fucked around with this message at 03:30 on Feb 8, 2019

Coredump
Dec 1, 2002

Does onenote have the ability to where I can define some brackets or quotes and it will format the text inside a way I define? I want a way to highlight and change font on code as I make a document on a server I'm building.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


SE dumped a poo poo pile on us yesterday. Been here a while and has no idea how poo poo works so he just escalates ticket. He escalated too far this time and now I can’t find him in our company registry.

Woops maybe next time do your job.

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.

Docjowles posted:

There seems to be a widely held belief that the Oracle JDK is somehow massively superior to openjdk in terms of performance and stability. I've gotten a lot of pushback or at least skepticism about switching our apps from running under Oracle to "that rinky dink openjdk bullshit". We're a huge open source shop and don't pay for anything unless we have to, so that was particularly surprising.

I think that used to be the case, but for modern versions they are the same loving thing. The Oracle version just includes commercial support, and some value-add libraries and features that we don't use at all.

Embrace openjdk, and enjoy one less reason to have Oracle in your life.

There’s always the AWS version of OpenJDK:

https://aws.amazon.com/corretto/

Virigoth posted:

How is the AWS openjdk version? Have you tested it any?

I have not, but Corretto is being fully embraced here. I can’t speak to any customizations or deltas between AWS openjdk and other forks.

Agrikk fucked around with this message at 06:08 on Feb 8, 2019

orange sky
May 7, 2007

Wells Fargo's disaster recovery failed so their poo poo was down for hours lmao what a trash fire

Test your DR sites folks

bull3964
Nov 18, 2000

DO YOU HEAR THAT? THAT'S THE SOUND OF ME PATTING MYSELF ON THE BACK.


Oh, so that's why my plan to do my taxes tonight failed when I couldn't access my mortgage documents.

Methanar
Sep 26, 2013

by the sex ghost

bull3964 posted:

Oh, so that's why my plan to do my taxes tonight failed when I couldn't access my mortgage documents.

If your bank burns down your house is free

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k

Methanar posted:

If your bank burns down your house is free

Didnt you watch Mr. Robot? You also have to destroy the paper copies

Bullet Magnet
Sep 26, 2007
it's THAT GUY!

Sepist posted:

Didnt you watch Mr. Robot? You also have to destroy the paper copies

Didn't you watch Fight Club? You also have to destroy all the branches in New York City.

TerryLennox
Oct 12, 2009

There is nothing tougher than a tough Mexican, just as there is nothing gentler than a gentle Mexican, nothing more honest than an honest Mexican, and above all nothing sadder than a sad Mexican. -R. Chandler.

orange sky posted:

Wells Fargo's disaster recovery failed so their poo poo was down for hours lmao what a trash fire

Test your DR sites folks

WTF isn't that a SOX compliance violation?

AreWeDrunkYet
Jul 8, 2006

TerryLennox posted:

WTF isn't that a SOX compliance violation?

Is there a regulation Wells Fargo hasn't run afoul of in the last decade? At this point it wouldn't be surprising if they were caught burning laptop batteries in an open pit.

Docjowles
Apr 9, 2009

Agrikk posted:

There’s always the AWS version of OpenJDK:

https://aws.amazon.com/corretto/

Our devs want Java 11 which Amazon hasn't released yet, but I am aware and watching with interest :)

Zorak of Michigan
Jun 10, 2006


TerryLennox posted:

WTF isn't that a SOX compliance violation?

SOX says you have to have a DR plan. Only experience can tell you it doesn't work. I'd like to imagine it will make their audit more of a challenge next year, but let's face it, they'll tell the auditors some crap about improvements they've made and get waved through.

On the other hand, if their own figures tell them they lost a significant amount of money, that might actually create some real interest in fixing the problem.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Can anyone recommend a resource to dig into BGP? I know the barest basics, but I'm having to do more and more of it for routing in AWS. I'm muddling my way through with guides and google, but could really do with learning the fundamentals so I can troubleshoot better. I don't need to know how it works across the public internet right now, but it's the stuff like how every VPC has two tunnels built to my firewall and uses BGP to route traffic across both that I want to understand better.

e: preferably with labs. I'm open to the idea of paid material if needed.

rafikki fucked around with this message at 17:14 on Feb 8, 2019

Docjowles
Apr 9, 2009

I asked the same thing last year and got a great reply from our pal madsushi

madsushi posted:

There are three books that will teach you almost everything you need to know about BGP. They're all still great. If they mention something like "this is a new thing that's rolling out", it's been out forever and assumed standard. :)

Book #1 - Halabi / Cisco


Book #2 - Stewart / Juniper

BGP4: Inter-Domain Routing in the Internet

Book #3 - Norton

Internet Peering Playbook (most of this content is available for free at drpeering.net as well....)


Halabi and Stewart will teach you about the protocols. Norton will teach you about how the internet ACTUALLY works. It's got a lot of the juicy details about peering, PNI, transit, etc that tell you about the actual business side and how agreements are made behind the scenes. If you've never run BGP between companies before, it'll be helpful.

I read the first two books and now know enough BGP poo poo to do AWS Direct Connect / VPN stuff. Can confirm they're both excellent despite their age. I would start with the Stewart book and advance to the Halabi one if you find it didn't go deep enough for you.

tortilla_chip
Jun 13, 2007

k-partite
You want this book: https://www.amazon.com/Internet-Routing-Architectures-Networking-Technology-ebook/dp/B0015V9DQ0

GNS3/EVE/VIRL/your sim of choice will be enough to lab.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Halabi and stewart it is, thanks!

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
I've spent the better part of the week uncovering the deep intricacies of a platforms qos functionality for a deep dive presentation on changing the functionality to better align with our global qos policy.

Platform is being decommissioned in 2 months. Why the gently caress do we even bother?

Also this platform was completely abandoned by cisco so there are no SMEs on their end to help me work through this. I ended up educating our AS guy on how this poo poo works.

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


orange sky posted:

Wells Fargo's disaster recovery failed so their poo poo was down for hours lmao what a trash fire

Test your DR sites folks

Last year around Thanksgiving and Christmas I had the worst time with Wells Fargo. Couldn't check my account, couldn't use an ATM because I had my withdrawal limit even when I hadn't used an ATM in months. On top of that one of their recruiters tried to pull me in for a "Cloud Engineer" position. It had nothing to do with Cloud at all and was just basic AD, Storage and Virtualization.

bull3964
Nov 18, 2000

DO YOU HEAR THAT? THAT'S THE SOUND OF ME PATTING MYSELF ON THE BACK.


Methanar posted:

If your bank burns down your house is free

If only.

I now wish it was still offline since after I got access again I finished my taxes and found the lovely "tax cuts" are making me owe money for the first time in 22 years.

bull3964 fucked around with this message at 20:56 on Feb 8, 2019

orange sky
May 7, 2007

Don't worry your money was well spent in share buybacks and yachts with IMAX

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.

Docjowles posted:

Our devs want Java 11 which Amazon hasn't released yet, but I am aware and watching with interest :)

Without an NDS in place I can say it's coming soon(tm).

Zorak of Michigan
Jun 10, 2006


Fellow work-from-home types: anyone have a recommendation for a stereo Bluetooth headset? I'm trying to find something comfortable enough to wear all day, with enough battery life to wear all day, a mic that doesn't pick up too much background noise, and with a hard mute button, so I don't have to unlock my phone before I interrupt someone and tell them that we're definitely not doing what they want. Oh, and I have a big fat head, so I'm looking for something without too much clamping force, too. Currently I'm looking at the Jabra Evolve 75 or Plantronics Voyager 8200, and leaning toward the Plantronics.

George H.W. Cunt
Oct 6, 2010





We use the Jabba and it is excellent. I usually get a solid 14 hours per charge

Thanks Ants
May 21, 2004

#essereFerrari


Zorak of Michigan posted:

Fellow work-from-home types: anyone have a recommendation for a stereo Bluetooth headset? I'm trying to find something comfortable enough to wear all day, with enough battery life to wear all day, a mic that doesn't pick up too much background noise, and with a hard mute button, so I don't have to unlock my phone before I interrupt someone and tell them that we're definitely not doing what they want. Oh, and I have a big fat head, so I'm looking for something without too much clamping force, too. Currently I'm looking at the Jabra Evolve 75 or Plantronics Voyager 8200, and leaning toward the Plantronics.

Any reason it needs to be a headset? USB speakerphones are really good now and do the whole noise rejection thing. Treat yourself to a Polycom VoxBox.

tortilla_chip
Jun 13, 2007

k-partite
Bose QC35

lampey
Mar 27, 2012

The Iron Rose posted:

someone talk to me about SOC 2 compliance.

I've just been asked (and will officially be asked tomorrow) to take over for consultant preparing this SaaS shop for SOC 2 compliance. It's part of a business division and split into a new company/new domain. I'm designing their domain architecture, updating their logging/SIEM infrastructure, implmenting role based security, that sort of thing. But otherwise I don't know poo poo about SOC 2 other than general security best practices and some pretty useless free PDF checklists.

We had SOC 2 audits the last couple years and are going to SSAE16 going forward. It doesn't sound like you are in charge of making policy, or implementing policy if you have no previous experience with SOC 2. So mostly you will just be providing reports to management, information the auditor asks for, and potentially arguing with them if what they are asking for is impractical. Whether the company has a policy, and whether or not they are following policy will depend on what the company was doing last year. Whether this will be relatively easy, or tedious and miserable will depend on the infrastructure and the product, and what the auditor is asking for. Is this the first time you are being audited, or just a followup from previous years?

Zorak of Michigan
Jun 10, 2006


Thanks Ants posted:

Any reason it needs to be a headset? USB speakerphones are really good now and do the whole noise rejection thing. Treat yourself to a Polycom VoxBox.

One of the things I like about dropping my current landline headset and going cell+BT is that I could get up and move around freely, even go downstairs and make myself a sandwich.

Thanks for the recommendations, George and tortilla_chip.

bull3964
Nov 18, 2000

DO YOU HEAR THAT? THAT'S THE SOUND OF ME PATTING MYSELF ON THE BACK.


The Iron Rose posted:

someone talk to me about SOC 2 compliance.

I've just been asked (and will officially be asked tomorrow) to take over for consultant preparing this SaaS shop for SOC 2 compliance. It's part of a business division and split into a new company/new domain. I'm designing their domain architecture, updating their logging/SIEM infrastructure, implmenting role based security, that sort of thing. But otherwise I don't know poo poo about SOC 2 other than general security best practices and some pretty useless free PDF checklists.

Find out if it's Type I or Type II as that makes a huge difference.

Type I is "Here are our policies and procedures to cover the controls, do you see any gaps."

Type II is "Ok, here's our proof that we are following all the policies and procedures to ensure we are in compliance with our control language."

SOC 2 also has different pillars, so the scope of the audit may be different depending on what pillars your org is going after for compliance.

The auditors will find something, that's their job, as long as you come to with decent mitigation, they are generally happy.

orange sky
May 7, 2007

This is gonna be really crazy

https://twitter.com/NBCNews/status/1094246798313644033?s=19

guppy
Sep 21, 2004

sting like a byob

Friend of mine told me yesterday that WF has no record of his mortgage.

wargames
Mar 16, 2008

official yospos cat censor

guppy posted:

Friend of mine told me yesterday that WF has no record of his mortgage.

congrats on your friend for paying off his house so quickly, also screw WF so hard.

Neddy Seagoon
Oct 12, 2012

"Hi Everybody!"

guppy posted:

Friend of mine told me yesterday that WF has no record of his mortgage.

Just out of curiosity as I'm not up on the US housing market, does that means he owns the house without debt, or that technically nobody owns the house right now?

Vulture Culture
Jul 14, 2003

I was never enjoying it. I only eat it for the nutrients.

Neddy Seagoon posted:

Just out of curiosity as I'm not up on the US housing market, does that means he owns the house without debt, or that technically nobody owns the house right now?
It means the bank still has a lien on the house but has no record of any money being paid towards the lien

Adbot
ADBOT LOVES YOU

orange sky
May 7, 2007

Vulture Culture posted:

It means the bank still has a lien on the house but has no record of any money being paid towards the lien

Well of course it had to be the worst of all options

Also I imagine that IT department right now telling the board that there's no backups nor a way to get that data back (you just know there isn't)

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply