LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 06-18-2021, 03:14 AM   #1
andrixnet
Member
 
Registered: Oct 2012
Location: Romania
Distribution: Slackware
Posts: 167

Rep: Reputation: Disabled
Question Slackware and ISO27001


I have recently encountered the following problem ... hosting company offering VPS turned off virtual servers running Slackware and refused to turn them back on citing changes in their ToS requiring something like only ISO27001 certified operating systems be installed as GuestOS on their hardware.
And claiming that Slackware as an operating system had no such certification.
AFAIK this was not a singular case...
  1. Is Slackware (14.2) ISO27001 certified? (I couldn't find any info on this.
  2. Will the upcoming 15 release be?
Assuming NO to both questions above, what can one do as deployer of Slackware based server faced with such demands from hosting companies (AFAIK it's becoming a trend - thus ever decreased hosting options) - does such certification rest with the distributor (Slackware Linux Inc) or with the user/deployer, or is it something of a joint thing? (IDK)

Last edited by andrixnet; 06-18-2021 at 03:15 AM.
 
Old 06-18-2021, 04:04 AM   #2
GazL
LQ Veteran
 
Registered: May 2008
Posts: 6,897

Rep: Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019
As I understand it, ISO27001 certification applies to organisations not products: it's all about internal processes, policies and controls as much as anything else. Now, Redhat may have gone to the trouble of getting themselves, as an organisation, ISO27001 certified, but that doesn't say anything about their product, which lets face it, even if provided by a certified company, could be made insecure with a single config file change.

Having a list of 'sanctioned' distros in their ToS is one thing -- it's kind of silly for the reasons mentioned above, but it's understandable -- Bringing ISO27001 into the picture is just silly. I'd go find a hosting company with a clue.
 
4 members found this post helpful.
Old 06-18-2021, 04:11 AM   #3
rkelsen
Senior Member
 
Registered: Sep 2004
Distribution: slackware
Posts: 4,456
Blog Entries: 7

Rep: Reputation: 2560Reputation: 2560Reputation: 2560Reputation: 2560Reputation: 2560Reputation: 2560Reputation: 2560Reputation: 2560Reputation: 2560Reputation: 2560Reputation: 2560
Yeah, seems like a lame excuse to me.

As above, vote with your wallet.
 
1 members found this post helpful.
Old 06-18-2021, 05:17 AM   #4
Didier Spaier
LQ Addict
 
Registered: Nov 2008
Location: Paris, France
Distribution: Slint64-15.0
Posts: 11,058

Rep: Reputation: Disabled
I am a happy Linode customer and they provide ready-made Qemu Slackware images.
 
1 members found this post helpful.
Old 06-18-2021, 05:36 AM   #5
Bindestreck
Member
 
Registered: Jul 2011
Location: Sweden
Distribution: Slackware
Posts: 820

Rep: Reputation: 440Reputation: 440Reputation: 440Reputation: 440Reputation: 440
They don't have the competence to manage access control to their IT resources using Slackware as distribution. Is not about the Slackware, is about their competence, really. Even if Slackware corporation would be ISO27001 certified, your hosting company would still not provide you with Slackware virtual servers.
 
2 members found this post helpful.
Old 06-18-2021, 01:25 PM   #6
philanc
Member
 
Registered: Jan 2011
Posts: 308

Rep: Reputation: 273Reputation: 273Reputation: 273
Quote:
Originally Posted by andrixnet View Post
(...) citing changes in their ToS requiring something like only ISO27001 certified operating systems be installed as GuestOS on their hardware.
Could you give us a link to their TOS (assuming they have an english version)? - just curious :-)
 
1 members found this post helpful.
Old 06-18-2021, 06:58 PM   #7
ttk
Senior Member
 
Registered: May 2012
Location: Sebastopol, CA
Distribution: Slackware64
Posts: 1,038
Blog Entries: 27

Rep: Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484
Yeah, what they said.

Reviewing ISO27001, it requires that compliant organizations have documented plans for assessing and responding to security risks.

It sounds like they can't be arsed to figure out how to secure or monitor Slackware VMs, which means they can't document doing it, which means they can't be ISO27001 compliant.

Ridding themselves of your Slackware VM eliminates this obstacle, at a fraction of the cost of learning Slackware security.

I suppose if someone (anyone) were to write up a sufficiently corporate-friendly document describing how to monitor and secure Slackware and make that document generally available, companies seeking ISO27001 compliance could drop it into their own documentation and call it done.

Most of that work is already done in http://slackbook.org/html/book.html#SECURITY I think. It needs something about security monitoring and someone presenting it as a ISO27001 compliance document.

Someone sanity-check me here, please. I feel like I might be missing something.
 
2 members found this post helpful.
  


Reply

Tags
certification, slackware 2016 and beyond



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 03:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration