4 ms·
> Soc compliance is not ensured by spying on employees activities That part is clearly Security Theater. Having worked with real security for decades (consulti
by illud_tempus 5y ago
> Soc compliance is not ensured by spying on employees activities
That part is clearly Security Theater. Having worked with real security for decades (consulting, training, building server monitoring and alerting tools, building commercial firewalls) I get quite provoked by fake security. For example, this "agent" checks for disk encryption. It does not check for password strength, or even if there is a password (you can use full disk encryption under Linux without any password). It also require anti-virus, which under Linux is more likely to do harm than any good.
What I don't understand is why they choose to do this to their engineering team. I don't know much about SOC 2, but from what I have read, the "concern" is mainly production related. Most of the engineers, including most of the really senior ones, never access production systems.
- GianFabien 5y agoHad a quick look at drata.com. Looks like vendorware. Some manager got hoodwinked into buying the product to justify their existence. Now they have to force everybody to use it to justify the exorbitant price.
- noisy_boy 5y ago> hoodwinked Or they just saw an opportunity :)
- DnDGrognard 5y agoNice day out (aka Jolly) at the golf club :-)
- celeduc 5y agoOr they got a fat kickback