• Carighan Maconar@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    9 months ago

    Yeah my ex makes a lot of money basically sitting down with companies and over years (because it’s such an arduous process to get managers to understand the importantance of) make them slowly, ever so slowly, do proper access or even identity management.

    • Laser@feddit.de
      link
      fedilink
      arrow-up
      0
      ·
      9 months ago

      For all the criticism it gets, this is something that Common Criteria at EAL 3 and higher covers, and if your company can’t ensure secure development of a product, the product doesn’t get certified. At least my scheme is always very strict with life cycle aspects, and if you’re not getting a certificate for a market it’s required in, that’s money lost, and a huge motivator for management to implement changes.