3 ms·
Actually there are auditors who look at source code — "code audits", https://en.wikipedia.org/wiki/Code_audit https://en.wikipedia.org/wiki/Code_audit And the
by KajMagnus 6y ago
Actually there are auditors who look at source code — "code audits",
https://en.wikipedia.org/wiki/Code_audit https://en.wikipedia.org/wiki/Code_audit
And there's a job role called "Source Code Auditor".
Question was if GGP's SOC2 case involved any such source code audits or not.
Now, having read https://latacora.micro.blog/2020/03/12/the-soc-starting.html https://latacora.micro.blog/2020/03/12/the-soc-starting.html (linked from a nearby comment, https://news.ycombinator.com/item?id=25489586 https://news.ycombinator.com/item?id=25489586), seems SOC2 does not include those types of audits. Could still be nice to hear directly from GGP @necubi though. ("yearly security audit"?)
- suifbwish 6y agoI agree it should be a thing but having been part of a few code audits which were just part of normal company acquisition processes, I know that it takes months to audit the code base of even a moderate sized web application unless it uses a framework whose libraries can be eliminated through md5checks against the originals