3 ms·
The underlying problem is they are asking you to trust Drata implicitly, sight-unseen, and give them unfettered access to their laptop. There is nothing prevent
by joekrill 5y ago
The underlying problem is they are asking you to trust Drata implicitly, sight-unseen, and give them unfettered access to their laptop. There is nothing preventing Drata from changing their minds and altering how their agent works or what it collects.
Then there's the unintentional aspect. There is, of course, no guarantee their agent is bug-free. Data leaks and compromises happen all the time, by every facet of company (large, small, respected, hated, etc).
This is really a huge risk IMO. If anything, it's being downplayed and far from "nonsense".
- lucraft 5y agoGrown-up companies doing SOC2 usually provide developers with hardware, and in that case the company is installing an agent from a vendor they have selected, onto their own computers. True, the grey area is slightly odd situations like this where the protagonist is a freelancer rather than an employee and presumably also the company isn't willing to provide hardware to them in that case?? Because they're a freelancer? Sounds like a case that isn't going to survive too long in any company that's getting serious about compliance and risks.