Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Document something akin to the following:

164.308(a)(5)(ii)(B): We have policies for guarding against, detecting, and reporting malicious software. Specifically, we require our workforce to use Macs or Linux machines, and we exclusively host our applications on Linux machines, as industry consensus is that these machines are less vulnerable to infection by viruses than Windows machines. We will revisit this policy annually and revise if we determine that the risk of infection of a Mac or Linux machine is greater than Very Low. Our present assessment is Very Low. See also $POINTER, where we discuss securing the applications we host. Accordingly, our risk analysis recommends against spending engineering resources on this threat. Note that this subsection is Addressable, not Required, so we believe that this is sufficient for this subsection.

Welcome to HIPAA! You can do almost anything as long as you document the heck out of it.



"Welcome to HIPAA! You can do almost anything as long as you document the heck out of it."

There's already lists of code smells where you know the code might be shit if you see things on the list. I propose regulation or certification smells for things like above. Your process has it? Then it's not going to make things better for real.


Mac and Linux being less vulnerable is not a guarantee anymore. There's some that argue that the past few years, Mac and Linux have had more vulnerabilities than Windows has, especially severe ones (and especially Mac). Here's [one article](http://thehackernews.com/2015/02/vulnerable-operating-system...) on it, but there's plenty out there.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: