Curious what replaces it long-term.
Cybersecurity
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
So they're admitting their stuff is crap and that they expect for it to stay that way.
More like, the business are whining that security is hard and expensive; so, they shouldn't be required to do it.
While I'm no fan of checkbox security, CMMC was kinda like the sign in front of rollercoasters. Except instead of a minimum height, CMMC was saying, "your network must be at least this secure to hold CUI".
Seriously, I dealt with this stuff for years as a contractor for the US FedGov. It's not rocket science. It's not even hard. But, it does require that you document your shit and do a bit better than accepting the defaults. It won't make your network secure. But if you are struggling to meet the basic controls, I guarantee that your security is bad.
CMMC is more about how well your processes work. Low level = more chaotic, stuff basically works but people have to scurry around and improvise when it breaks. Mid level = it can break but procedures for fixing it are documented and regular. High level = can't break. No attempt at certifying to any level at all = never mind, just wing everything.
I wonder how much turning everything into piles of AI crap is involved with this.
Having worked with compliance across multiple industries, CMMC was created for very good reasons, but was poorly implemented, also like it was being deliberately sabotaged (spoiler: it was).
Our supply chain security is a joke in America and the big players have wanted it to stay that way this whole time. I do not think meaningful security standards can be adopted in a system with this level of blatant corruption.
I've also had to do compliance for California Dept. Of Cannabis Control regulations. I've been telling people for years: If you want to do security theater, follow the NIST SP 800-171. If you want to do real security, follow CA Cannabis Control standards. I'm not joking.
The biggest issues I've had with CMMC is that it seems to have been designed without any consideration for software development.