Hacker News new | past | comments | ask | show | jobs | submit login
Open source HIPAA compliance benchmark for AWS (github.com/turbot)
58 points by dboeke on June 16, 2021 | hide | past | favorite | 8 comments



I recently completed a SOC 2 Type I audit and tools like Lynis are indispensable not only to configure your servers according to a standard, but more importantly being able to produce evidence that the servers meet the standard.

This tool looks like it is for AWS / GCP accounts and help to both secure and to prove audit and compliance. The easier it is for the auditor to review your controls and evidence the easier to pass the audit. Really looking forward to using this tool and checking to see what has changed in the CIS.


That's exactly one of the use cases we are targeting. Beyond the standard benchmarks, Steampipe has a simple HCL + SQL language to write your own controls [1]. It feels like writing Terraform, but is for operational and security controls.

Hope you can give it a try, we'd love your feedback and suggestions!

1 - https://steampipe.io/docs/using-steampipe/writing-controls


Hmmm. The stuff for HIPAA isn’t great. If this is meant to actually be of value to covered entities and business associates then NIST CSF (and related) is the benchmark to use.

There are known gaps in HIPAA per OCR. The actual expectation is that entities identify these gaps under the annual risk management mandate thus the more frequently updated NIST is what’s preferred (or even HITRUST…yuck)

https://www.hhs.gov/hipaa/for-professionals/security/nist-se...

Feel free to check out OCRs resolution agreements as well for details. They are all online.


Agree that adding NIST controls would be great - so far we've focused on CIS, PCI and HIPAA.


I haven’t seen many engineers who know the first thing about controls. But it’s literally most of what internal audit, compliance, privacy & risk people do.

How about an export feature from Archer or <name your internal audit tool here> that would save everyone a bunch of time and effort.

The other issue is that most of these client audits are a word or excel doc. Throwing your SOC back at them doesn’t work in most cases.


Steampipe [1] looks cool, previously I have used lynis[2].

It looks like there is also a steampipe GCP Compliance mod[3] steampipe too.

[1] https://steampipe.io/docs

[2] https://cisofy.com/lynis/

[3] https://github.com/turbot/steampipe-mod-gcp-compliance


Steampipe has open source cost and compliance mods for AWS, Azure, GCP, GitHub and Zoom. Full docs are available at https://hub.steampipe.io/mods

Disclaimer - I'm a lead on the team. We'd love your feedback and are excited to see what other custom controls people build!


I heard someone describe steampipe as Dev DB ops. It's kind of stuck to my brain.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: