Husband, Father, IT Pro, service.

I ask a lot of questions to try to understand how people think.

  • 8 Posts
  • 33 Comments
Joined 5 months ago
cake
Cake day: February 11th, 2024

help-circle




















  • I hear what you’re saying, you’re not wrong.

    I would argue that the technical implementations, the ones that are about a quantified or Boolean evaluation, that’s not the case.

    Sure, STIGs can be open to interpretation like any benchmark or compliance standard and are open to the reviewers personal discretion or trends in the industry.

    I wouldn’t suggest that stigs are more relevant than CIS, since it’s mostly only used by federal government, but it is something to be aware of and a skill set that’s in demand.

    I wouldn’t say cis, or stigs, aren’t a security practice by themselves. Security practices come from implementing good policies and evaluation, and I would suggest that the new cybersecurity framework 2.0 would help inform good security practices.

    Have you never found ambiguous standards anywhere else?







  • RedFox@infosec.pubtoSelfhosted@lemmy.worldTrueNAS vs Debian
    link
    fedilink
    English
    arrow-up
    8
    ·
    edit-2
    4 months ago

    TrueNAS is a propose built solution.

    You’ll need to use it the way it’s designed, which is extremely capable, but reading the manual is mandatory or you’ll do it wrong and then it will suck. I know this.

    There’s TN Core, and Scale. Ones based on FreeBSD, one’s Linux. You can compare for your needs.

    TN can be an enterprise solution if that tells you the capability.

    Edit, it’s meant to be a storage solution. Scale adds containers. It’s not great IMO as a general purpose server OS .