Currently still missing a lot of stuff I'd consider to be minimal on the corpsec side; the earlier it's implemented then the easier it is to keep in the company rather than trying to add it later after inertia sets in. Namely:
* Enforce security keys on the SSO side
* Set up email security - SPF, DMARC, explicitly enumerating every source of email sent from your domain with full enforcement to catch new sources before they become critical and untracked
Comments
Great idea.
Currently still missing a lot of stuff I'd consider to be minimal on the corpsec side; the earlier it's implemented then the easier it is to keep in the company rather than trying to add it later after inertia sets in. Namely:
* Enforce security keys on the SSO side * Set up email security - SPF, DMARC, explicitly enumerating every source of email sent from your domain with full enforcement to catch new sources before they become critical and untracked