While giving Crowdstrike the autonomy to push updates without prior MSFT permission (as is being reported now), not sure why MSFT didn't reserve the right to check each time in massive details as to how Crowdstrike first did extensive pre-launch testing in a controlled environment before releasing the new update into production. The more you allow a vendor to integrate, the more rigorous and thorough your oversight needs to be. Autonomy and Rigour are two separate things, not to be conflated. The buck still stops at MSFT. (To cite a parallel, a car manufacturer has to take full responsibility for a component supplied by a component supplier. They cannot pass the buck.). #thirdpartyrisk #vendorriskmanagement #MSFT.
Manish Maheshwari’s Post
More Relevant Posts
-
Automation is important when complying with 72 work roles, three different competency levels, knowledge, skills, tasks, and a DODD 8140.03 framework designed to evolve! Stay compliant. Stay vigilant. Stay automatic. #cyberskills #DIB #cyber #cybercompliance #DODCyber
Stay current with DoDM 8140.03 using CyberSTAR. It automatically updates with new regulatory elements, ensuring compliance across all levels. Learn how it works: https://hubs.la/Q02y10dz0 #DoD #CyberCompliance #TechInnovation
To view or add a comment, sign in
-
#BSOD CrowdStrike : Even before awaiting for the official advisory, our quick analysis and fast execution were pivotal. By changing the CrowdStrike agent auto-update policy to ver. N-2, we managed to reduce damage by up to 80%, resulting in reduced stress and faster recovery. #INDmoney #DemocratizingFinance #InfoSecGovernance #EffectiveCrisisManagement Dhruv Pathak Ashish Kashyap
To view or add a comment, sign in
-
We are now in a skills-based hiring, employment, and compliance model when it comes to cyber security. WillCo Tech simplifies your compliance challenges, automatically managing updates with the continuing changes in the DOD Directive 8140.03 framework. #8140 #cybercompliance #cyberworkroles #cyberskills
Stay current with DoDM 8140.03 using CyberSTAR. It automatically updates with new regulatory elements, ensuring compliance across all levels. Learn how it works: https://hubs.la/Q02y10dz0 #DoD #CyberCompliance #TechInnovation
CyberSTAR supports the Cyber Workforce Qualifications Program
To view or add a comment, sign in
-
#MFA prevents 99% of successful #CyberAttacks, but only if it's configured correctly. Are you aware of the blindspots in your MFA? Extend MFA across all users, including service accounts - learn how in the on demand webinar now 👇👇 https://loom.ly/cblTQGU
To view or add a comment, sign in
-
Properly set up Multi-Factor Authentication can block nearly all cyber threats - Is yours MFA solution fully optimised? Don't let your service accounts become vulnerabilities. Join our latest webinar to learn how to protect them effectively and extend MFA coverage. https://loom.ly/cblTQGU
#MFA prevents 99% of successful #CyberAttacks, but only if it's configured correctly. Are you aware of the blindspots in your MFA? Extend MFA across all users, including service accounts - learn how in the on demand webinar now 👇👇 https://loom.ly/cblTQGU
To view or add a comment, sign in
-
We developed the OVERSIGHT™ tool for IXRS®3 to prevent discrepancies from revealing themselves when it's too late. Learn how OVERSIGHT™ can help you stay ahead of the game: https://okt.to/xm8Kir #clinicaltrials #IRT
To view or add a comment, sign in
-
Two certifications you can trust in. #exo
We’re excited to announce that Exo Works™ has achieved both HITRUST and SOC 2 Type II certifications. These certifications validate our commitment to protecting our customers’ sensitive information. Check out our certifications and more: https://hubs.la/Q02pZ_pd0 #ExoWorks #POCUS #Workflow #HITRUST #SOC2
To view or add a comment, sign in
-
Stay current with DoDM 8140.03 using CyberSTAR. It automatically updates with new regulatory elements, ensuring compliance across all levels. Learn how it works: https://hubs.la/Q02y10dz0 #DoD #CyberCompliance #TechInnovation
CyberSTAR supports the Cyber Workforce Qualifications Program
To view or add a comment, sign in
-
In 2020 my team had a foresight to introduce a custom CrowdStrike release process to prevent this exact outcome. We met with CrowdStrike support team and asked to have our release process as a standard out of the box option, but clearly that did not happen. Our release process looks like this: DEV=N INT=DEV > INT and stable/unchanged for 7 days PROD=INT > PROD and stable/unchanged for 7 days This introduces a 2 week test buffer for stability checks and prevents this very silliness.
Major IT Outage Hits Banks, Airlines, Businesses Worldwide
wsj.com
To view or add a comment, sign in
-
The key differences between EDR and XDR simplified. Sec: letsdefend
To view or add a comment, sign in