
"The Building Has Malware." Adventures in Appsec 🕷 Darknet Diaries Ep. 165: Tanya
Source: YouTube · Jack Rhysider · published Nov 4, 2025 · 41:02
The video explores the disconnect between having security policies and making them genuinely accessible to employees when needed 0:00.
Key Takeaways:
• Companies typically have security policies that satisfy audit requirements but remain difficult for employees to locate 0:10
• Important security documents are often buried in systems like SharePoint with cryptic filenames such as "isp_overview" 0:23
• Merely having policies available doesn't ensure employees can find or use them when necessary 0:36
This highlights the importance of designing security documentation that is not only compliant but also genuinely accessible and usable for the entire workforce.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Episode 165
[START OF RECORDING] JACK: Hey, it’s Jack, host of the show. For a
while, I worked at a big company doing security engineering, and every year, someone would come in
and do an audit on us, and they would ask us the same question; do you have a security policy?
Yes, of course we do. Is it available for all your employees to find? Yep. It’s right there
on SharePoint. But this got me thinking — yeah, sure, it was right there in SharePoint, but it was
called something ridiculous like isp_overview or something like that. ISP stood for information
security policy. It made me wonder; if this document was so important that we would be audited
to check to see if we had it and make sure all our employees had access to it, could any of them
actually find it if they needed it? This…