9 Matching Annotations
  1. Apr 2025
    1. The base of application security starts with proper identity management. ASP.NET Core provides built-in tools to implement secure authentication and authorization that must be configured correctly to meet SOC 2 security requirements.

      Ensure your .NET Core and ASP.NET MVC applications meet rigorous SOC 2 requirements with CMARIX’s comprehensive guide. Discover a step‑by‑step SOC 2 compliance checklist, practical best practices for MVC projects, and tailored strategies for integrating security controls into your .NET Core codebase. Master audit readiness and protect customer data with proven techniques designed for modern Microsoft‑stack applications.SOC 2 compliance

  2. Dec 2024
    1. We asked peers who had done their own SOC2 and stole their answer: post-facto reviews. We do regular reviews on large components, like the Rust fly-proxy that powers our Anycast network and the Go flyd that drives Fly machines. But smaller projects like our private DNS server, and out-of-process changes like urgent bug fixes, can get merged unreviewed (by a subset of authorized developers). We run a Github bot that flags these PRs automatically and hold a weekly meeting where we review the PRs.

      This is a nice idea - you can push to main, but the review still happens at a weekly session. This removes the slowness, but still makes sure that there is a shared understanding of what changes were made.

  3. Apr 2021
  4. Dec 2020
  5. Oct 2020
  6. Sep 2020
  7. Mar 2015
    1. lowRISC is producing fully open hardware systems. From the processor core to the development board, our goal is to create a completely open computing eco-system. Our open-source SoC (System-on-a-Chip) designs will be based on the 64-bit RISC-V instruction set architecture. Volume silicon manufacture is planned as is a low-cost development board. There are more details on our plans in these slides from a recent talk lowRISC is a not-for-profit organisation working closely with the University of Cambridge and the open-source community.