Skip to content

Comment on Minimum Viable Secure Product

Comments

Great idea.

Currently still missing a lot of stuff I'd consider to be minimal on the corpsec side; the earlier it's implemented then the easier it is to keep in the company rather than trying to add it later after inertia sets in. Namely:

* Enforce security keys on the SSO side * Set up email security - SPF, DMARC, explicitly enumerating every source of email sent from your domain with full enforcement to catch new sources before they become critical and untracked

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.