Will Gregorian

94 Followers
147 Following
123 Posts
I have no idea what I’m doing but I get it done.
Using the latest headlines is just plain wrong. Shame on you.

How do we maintain our Information Security policies and procedures?

Obsidian editor! We use the editor to maintain our policies and procedures in Markdown.

How do we version control our policies and procedures?

GitHub! We use the Obsidian community Git plugin to maintain version control and branch, and we use Pull Requests for approvals, democratizing our document management process.

Where do we publish our policies and procedures?

Confluence! We use the Obsidian community Confluence plugin to publish the main branch documents.

Why do we use Obsidian + Git + Confluence?

By maintaining our governance documentation as code, we can easily evidence the Git history to ensure maintenance and approvals, which helps us demonstrate program effectiveness.

Compliance doesn't have to be boring; it can borrow engineering methodologies for efficiency. Best of all, at a minimal cost.👍

@austinfromboston I found a picture of you from a long time ago.
When the SOC 2 auditor tells me they also do pen testing.
CEO vish? Let’s do it!
The new MacBook Pro looks great, and MagSafe.

_______ Software PVT, Ltd InfoSec team policy is dumb AF. Don’t do this.

Source: Reddit, not mine. Also, I have a home computer/mobile device that I can use as well; where is your policy now?