3 ms·
The auditors, were they IT security professionals (if so, about how many years experience?), or accountants, or mixed, or something else? Were there any requir
by KajMagnus 6y ago
The auditors, were they IT security professionals (if so, about how many years experience?), or accountants, or mixed, or something else?
Were there any requirements about pentesting one's company somehow?
Did they look at source code?
- suifbwish 6y agoAuditors looking at source code.. Are you serious? From that question alone I can tell you know nothing about these audits.
- KajMagnus 6y agoActually there are auditors who look at source code — "code audits", https://en.wikipedia.org/wiki/Code_audit https://en.wikipedia.org/wiki/Code_audit And there's a job role called "Source Code Auditor". Question was if GGP's SOC2 case involved any such source code audits or not. Now, having read https://latacora.micro.blog/2020/03/12/the-soc-starting.html https://latacora.micro.blog/2020/03/12/the-soc-starting.html (linked from a nearby comment, https://news.ycombinator.com/item?id=25489586 https://news.ycombinator.com/item?id=25489586), seems SOC2 does not include those types of audits. Could still be nice to hear directly from GGP @necubi though. ("yearly security audit"?)
- suifbwish 6y agoI agree it should be a thing but having been part of a few code audits which were just part of normal company acquisition processes, I know that it takes months to audit the code base of even a moderate sized web application unless it uses a framework whose libraries can be eliminated through md5checks against the originals