Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

True as it is, not a thing you list here addresses the security of the product. Except for IaCs. And the site describes securing the product.

Will edit with commentary in a moment.

Edit: alright, fair criticism re business security controls given that the checklist's first section is specifically about business controls.

And the rest should be focusing on automating those outcomes rather than just what the outcomes are. I agree that manually creating DFDs is just going to slow teams down, though it's definitely a capability that more security-mature or regulation-burdened organizations will need. When you're this early though, better to harden IaCs based on secure reference architectures up front and lint the heck out of code than to encumber all of ones processes with manual controls.



Read my above replies. Product gets secured by defense in depth on the enterprise side edit - plus say a WAF and being disciplined about public endpoints and dialing into how users Authnz.

Unless you have the unicorn dev who’s doing appsec also focusing largely on appsec early on is a losing battle politically, will get your 1x sec eng at the startup - who also has to do a ton of other stuff for the startup - to quit for a better job in 12 months, and so on.

Defense in depth and threat modeling needs to rule a security program for a startup and doing MSVP as your guideline would miss that nuance.


That's a valid point. We will address this in our upcoming work group meeting.

If you're working for a startup, we would greatly appreciate it if you could try implementing MVSP in your organization and let us know which controls were difficult or problematic to implement. These controls can potentially be considered for removal.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: