๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Zoรซ
@zoecyber001
Red teamer working in the GRC world
๊ฐ€์ž… November 2022
438 ํŒ”๋กœ์ž‰ ์ค‘    3.8K ํŒฌ
> be me > first time going onsite for a high-assurance financial & physical security audit > logical side is heavy: HSMs, cryptographic keys, air-gapped zones, Zero Trust > time to walk the floor for the physical compliance checklist > "Are badge readers installed?" [x] Yes > "Are secure doors locked?" [x] Yes > "Are visitor logs kept?" [x] Yes > Everything checked out. 100% compliant on paper. > but my IoT/hardware hacker brain couldn't rest > walking the floor, I'm not seeing checkboxes, I'm seeing attack surface > standard compliance will only asks if a lock exists or a badge is issued > it never asks how that hardware behaves under 45 seconds of someone actually trying to get past it > a facility can pass every line on the checklist and still fold to a โ‚ฆ15,000 RF cloner or a door left a few mm out of true > compliance would only measures whether the hardware exists on paper > so I've been spending my evenings building APCAF - Adversarial Physical Control Assessment Framework > MITRE ATT&CK for physical & hardware-layer security > quick, non-invasive site checks. Check out what I'm building: ๐Ÿ”—
๋” ๋ณด๊ธฐ