Standards & review process
Last updated
This page documents how work is scoped, executed, and reviewed here — both the paid engagements and the technical guides published on this site. It exists so a prospective client, or a reader following one of the guides, can see the method before committing to either.
How engagements are scoped
Every engagement starts with a 30-minute scoping call to walk the environment, goals, constraints, and timeline. You get a written fit assessment the same business day, with either a fixed quote or an honest referral elsewhere if the work is not a fit. No retainer or NDA is required to reach that point. Engagements are bounded — a defined start and end date, not an open-ended retainer.
The review process before production
No change touches production before it is written down and reviewed. For each engagement that means an ordered runbook, explicit validation gates, a rollback procedure, and a short risk register. Changes run inside a defined window; results are validated against the runbook gates; and if a gate fails, the rollback is executed rather than improvised. The runbook, the validation output, and the decision log are handed off to you at the end — committed to your repository so they survive after the engagement closes.
The sources work is measured against
Hardening, compliance, and detection-engineering recommendations are applied according to published authoritative catalogs, not vendor marketing, and each recommendation traces back to one of them:
- ▸DISA Security Technical Implementation Guides — public.cyber.mil/stigs
- ▸NIST SP 800-53 control catalog — csrc.nist.gov
- ▸CISA cybersecurity best-practice guidance — cisa.gov
- ▸MITRE ATT&CK and the Splunk Common Information Model, for SIEM and detection-content work.
Editorial standards for the guides
The articles and walkthroughs on the blog follow the same discipline. Each one describes an approach that has been run in a real environment; commands and configurations are the ones actually used, not sketches. Where a guide references a standard, it links the primary source so you can verify it rather than taking the claim on trust. Guides are dated, and material corrections are made in place rather than quietly. None of it is a substitute for a scoped engagement — see the disclaimer for the limits of educational content.
Corrections
If something on this site is wrong — a broken procedure, an outdated reference, or a factual error in a guide — email kevin.kirk@lonestarspec.com with the page and a short description. Corrections that affect accuracy are made promptly and noted on the page.