So, my take on GDPR and osquery: 1. GDPR requires ...
# general
m
So, my take on GDPR and osquery: 1. GDPR requires you to implement effective security measures like intrusion detection systems. An osquery based intrusion detection system has a lot of advantages. 2. Use of osquery (or any other intrusion detection system) itself adds a GDPR risk, so it can become a bit of a catch-22. The blog article I posted tries to address how we can use osquery in a GDPR compliant way. 3. The full (and, I would say, the primary "new" requirement that has made GDPR so interesting - namely, the requirement that participant has the right to "opt out") is probably beyond the scope of osquery, as it requires parsing application data, probably at massive scale. I think DLP systems are probably a good place to start to solve this part of the problem.