Announcement for my new side project!
-------------------------------------------------------
https://t.co/Ni5hnCfgpe - Release #1: Security incident response program pack 1.0
Introduction
I've worked in the security industry for over 20 years and, during this time, have built and shaped many security programs. At every company I join, I find myself recreating or developing security programs from scratch. My peers have been in a similar position, and the more people I speak with at smaller companies, the more obvious it becomes that there isn't a single location where people can download ready-to-go security programs entirely for free. There's a lot of content online, but it can be difficult to find and challenging to find something simple to start with. I created SecTemplates as a side project to provide baseline programs for smaller security teams without direct expertise in building such programs.
Security incident response release pack 1.0
I'm pleased to announce our first release, the Incident Response Program Pack. The goal of this release is to provide you with everything you need to establish a functioning security incident response program at your company.
In this pack, we cover
Definitions: This document introduces sample terminology and roles during an incident, the various stakeholders who may need to be involved in supporting an incident, and sample incident severity rankings.
Preparation Checklist: This checklist provides every step required to research, pilot, test, and roll out a functioning incident response program.
Runbook: This runbook outlines the process a security team can use to ensure the right steps are followed during an incident, in a consistent manner.
Process workflow: We provide a diagram outlining the steps to follow during an incident.
Document Templates: Usable templates for tracking an incident and performing postmortems after one has concluded.
Metrics: Starting metrics to measure an incident response program.
Announcement:
https://t.co/7cWV1EaJR8
Download on GitHub:
https://t.co/BGpGMjCa82
About SecTemplates
To provide simplified, free, and usable open-source templates to enable engineering and smaller security teams to bootstrap security capabilities in their organizations.
Upcoming releases - Penetration testing release pack 1.0
Our penetration testing release pack will contain everything you need to scope your first pentest, work with a vendor, execute, and get the types of reports you need from an external tester.
Another security researcher, who said they lost patience with Microsoft's vulnerability disclosure process, publicly disclosed a bug without coordinating with the company https://t.co/k7yz0Kj4DC
JUST IN: Scientists say AI has decoded communication patterns in mice, dolphins, apes, birds, whales, & cuttlefish — could eventually lead to humans communicating directly with animals.
I think Anthropic is at about the peak of it's market cap, at least for awhile. Companies will not be able to sustain these costs and will look towards locally hosted models or small language models once they become available to reduce costs.