BSides London 2021 BSides London 2021

Saturday, November 13, 2021

Audit and compliance headaches - can data you already have provide the answer?

<Not Recorded>
For security teams and security managers, there are more and more tools, in more and more places than ever before. At the same time, we have increased interest from management, investors and auditors about the security posture, operations and risk.
 For real teams on the ground, answering the questions that stem from this, and providing the data is increasingly time consuming, often manual and quite frankly, frustrating. I didn't sign up as a security analyst to be pasting data from McAfee AV! This talk describes some common challenges, how the author has approached them in the past, what works/doesn't work, and explores some really useful data sources that you probably have, but probably haven't exploited yet.
 The good news, is that oftentimes, there is good hard data available which demonstrates the value of all your hard work; it just needs to be brought out.