Questions tagged [compliance]
14 questions
2
votes
2 answers
How do I prove that all available windows security updates are installed on a Windows 10 workstation?
If I have a Windows 10 workstation, I can use something like wmic qfe list or Get-Hotfix to show all the installed updates on that system. How can I prove, that the list of updates installed, are really all that is a available to be installed? I'm…

Ben Sooter
- 141
- 6
2
votes
1 answer
Getting massive web traffic from Microsoft Exchange Online Protection IP range after sending out email campaigns, how can I mitigate it?
After the marketing team starts an email campaign, our web server gets pummeled with strange requests from Microsoft's EOP IP range. Looking back through the logs, this has always happened, albeit the number of emails we were sending were a lot…

Taylor Howellsmith
- 23
- 3
1
vote
1 answer
IPS for web application in Kubernetes
We have an application hosted in Azure under Kubernetes. In a security compliance document shared with us, there are multiple points mentioning about implementation of an IPS (Intrusion Prevention System). I understand the features and security…

Anonymous Platypus
- 121
- 5
1
vote
2 answers
Alternative of AWS SSM for configuration compliance in GCP
we want to implement compliance monitoring in our cloud environment. For AWS, we are using AWS SSM to do it. But there is no alternative product in GCP, the only thing that will have the same functionality is cloud security command center and its…

Ilham Sulaksono
- 593
- 1
- 10
- 19
1
vote
2 answers
Design a compliance content search in O365 to ONLY return a specific person and a specific domain
I am attempting to do a content search through Exchange on O365 to return mail between user@domain.com and anyone at outsidedomain.com
I thought that this should work in the KQL:
(ParticipantDomains:outsidedomain.com) AND ((Sender:user@domain.com)…

dragonspeed
- 165
- 2
- 9
1
vote
0 answers
Is it possible to do screen recording on AWS workspaces?
I've been used to using tools like observit and cyberark psm for screen recording. Moving to a more distributed cloud-based toolset and want to keep the same level of compilance, is there a way to do screen recording of AWS workspace instances. …

Peter Turner
- 2,178
- 9
- 33
- 45
1
vote
0 answers
Server 2012R2 Foundation with 2019 Standard
We have done a FSMO migration from a Server 2012R2 Foundation to Server 2019 Standard.
After uninstalling the ADDS from the foundation server we started having a licensing issue with this popup:
"The server did not finish checking the license…

amit19595
- 11
- 1
1
vote
1 answer
SOC2 Compliance and Hardware
Topic is SOC2 compliance relating to server hardware.
Simply put, we have a mixed bag of servers that, while perfectly suited to their job, are End of Life and End of Support with the manufacturer.
As an example, one of the servers is a Dell…

Jay
- 11
- 1
0
votes
0 answers
Repeated GCP Compliance Notifications
I have been on GCP for roughly 3 months now. In that 3 months I have received 6 notices from GCP saying that one of my compute engines is creating a denial of service attack. They provide the IP address of the CE, and the time the attack triggered…

G. Malsack
- 1
- 1
0
votes
0 answers
Automate email traffic reporting Office365 Security and Compliance
I am a Security Engineer at my organization and I'm looking for ways to automate the reporting process for suspicious emails.
We are using Terranova Security Awareness for Phish email reporting, and I receive these reported emails in my mailbox.…

Jacob K
- 101
- 1
0
votes
1 answer
Unable to open PHP script files, even though I own them and have permissions
I'm using RHEL 8, and I have run into a crazy problem. My user account is unable to open PHP files.
If I have a file, owned by my user, and readable by my user, and I add

Nick2253
- 141
- 2
- 7
0
votes
1 answer
How long should accounts be deactivated before being deleted?
How long should accounts be deactivated before being deleted? Should accounts be deactivated?
For example, our organization uses 1Password Business, which allows for accounts to be deactivated. How long should we keep deactivated accounts around?…
0
votes
1 answer
Ansible playbook "path specified in src not found"
I am runnning into this message when I do this :
ansible-playbook -i inventory junos_config_new.yml --check -vvv
ansible-playbook 2.9.9 config file = /etc/ansible/ansible.cfg configured module search path = ['/root/.ansible/plugins/modules',…
0
votes
1 answer
Strange Errors in Security and Compliance
I'm getting an odd error in many of my security and compliance pages, error is as follows or a varient of the same:
The requested search root 'APCPR06A002.prod.outlook.com/ConfigurationUnits/XXXXXXXXXX.onmicrosoft.com/Configuration/Transport…