logoalt Hacker News

rileymat2today at 3:38 AM1 replyview on HN

If our need to update fips certified packages out paces the ability to certify packages, that is absolutely a problem with the design of FIPs certifications.


Replies

beardedwizardtoday at 4:11 AM

+1, been all the way to fed ramp high and this is a huge part of the security theater that is fedramp.

The second best part is either getting really good at patching every single thing, or playing the POA&M game.