Live data from Hacker News

Viewing profile — akshatpradhan

akshatpradhan

HN member
Joined
Wed, Apr 18, 2012, 5:48 AM UTC
HN karma
369
Public activity
295 items

About akshatpradhan

http://www.ComplianceChaos.com

Policy Writer for the Big 5 (i.e. ISO 27001, HIPAA, FEDRAMP, PCI-DSS, and now GDPR!)

I’m also familiar with SSAE-18 SOC 2 and SOX ITGC.

##CompSec on irc.freenode.org

/r/HIPAA /r/PCICompliance /r/ISO27001 /r/SOC2 /r/FEDRAMP

Recent public activity

  1. comment
  2. comment
    Comment #38711390

    The situation you described doesn’t sound like “Right Way Guys”. It actually sounds like “Bikeshedding” [1]. This means giving a disproportionate amount of attention or importance …

  3. comment
    Comment #19449404

    >and the ability to have different tips on them to increase fit for more people and to provide the option of sealing out outside noise. This is the single biggest reason why I won'…

  4. comment
    Comment #19316595

    This is a really good point and I'm not sure why you're being downvoted. Think of it this way, who the heck approves of an Incident Response Policy or an Information Security Polic…

  5. comment
    Comment #18826032

    Can GDPR be used as an audit mechanism for breached passport numbers? And if so, what would that process look like? Can hotels be fined if they’re found to not be GDPR compliant?

  6. comment
    Comment #18825931

    How does GDPR play into the requirement to store passport numbers?

  7. comment
  8. comment
  9. comment
    Comment #17842027

    Yeah but all of a sudden this new title seems waaay more interesting considering the recent journalist describing his experience working as an Amazon Flex Driver. Just saying.

  10. comment
    Comment #17768153

    Nutrition Label upfront, in words and text. I know there is a picture but I missed it, some of the nutrition labels are like the 4th picture. Some of the starter packs don’t have n…

  11. comment
    Comment #17762227

    Don’t encourage heavy handedness by the government, instead push for a better system of checks and balances.

  12. comment
  13. comment
    Comment #17365896

    Double Pasta, now that’s embarrassing.

  14. comment
  15. comment
    Comment #17358158

    >Coverage is a measure used to describe the degree to which the source code of a program is executed when a particular test suite runs. A program with high test coverage, measured …

  16. comment
    Comment #17358135

    >Coverage is a measure used to describe the degree to which the source code of a program is executed when a particular test suite runs. A program with high test coverage, measured …

  17. comment
    Comment #17319586

    I think issues left open > 12 months is antithetical to the idea of lean/agile and could be a sign of suboptimal project management. But don’t get me wrong, I <3 Ruby and am excite…

  18. comment
    Comment #17099190

    I started ComplianceChaos.com to sell my Policy Writing Services. I specialize in ISO 27001, HIPAA, and PCI-DSS. I’d love the opportunity to add GDPR to my current list of speciali…

  19. comment
    Comment #16613451

    It's in your best interest to reduce your risk by going through a De-identification process for data collected: >De-identification is adopted as one of the main approaches of data …

  20. comment
    Comment #16611958

    If you want to collect and process data on individuals, then start implementing Security 101 basics: * Data Classifications * Privacy Impact Assessments * Log Reviews * Incident Re…

  21. comment
    Comment #16607921

    You’re saying the following from GDPR doesn’t help? * Data Classifications * Privacy Impact Assessmemts * Breach Escalations * Access Controls That’s more like Security 101 Basics …

  22. comment
    Comment #16607863

    >I know from direct personal experience to be real threats Access Controls, Data Classifications, and Privacy Impact Assessments requested by GDPR are not a threat. That’s just sec…

  23. comment
    Comment #16607837

    Exactly, GDPR is only asking for Security 101 Basics. * Data Classifications * Privacy Impact Assessments * Log Reviews * Incident Reponse

  24. comment
    Comment #16607677

    >The GDPR is trying to do a good thing, but it goes too far By asking for: * Data Classifications? * Privacy Impact Assessments? * Access Controls? * Breach Escalations? If your bu…

  25. comment
    Comment #16607605

    Then refrain from collecting and processing data on individuals.