Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×

Comment Re:Sigh... heavy sigh... (Score 1) 44

No no it's okay, the CSO said there's no breach :)

"The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers."
https://www.okta.com/blog/2022...

The hacker had a few things to say
https://img.guildedcdn.com/Con...
https://img.guildedcdn.com/Con...
I think the best one was:

Security Standards. Okta's ISMP includes adherance to and regular testing of the key controls, systems and procedures of its ISMP to validate that they are properly implemented and effective in addressing the threats and risks identified. Such testing includes:

a) Internal risk assessments;
b) ISO 27001, 27002, 27017 and 27018 certifications;
c) NIST guidance; and
d) SOC2 Type II (or successor standard) audits annually performed by accredited third-party auditors ("Audit Report").

I don't think storing AWS keys within Slack would comply to any of these standards?

Slashdot Top Deals

The world is no nursery. - Sigmund Freud

Working...