6 ms·
SOC2 isn’t prescriptive. SOC2 is just a certification that you are following your own internal policies. If the company made the mistake of creating a policy t
by learc83 5y ago
SOC2 isn’t prescriptive. SOC2 is just a certification that you are following your own internal policies.
If the company made the mistake of creating a policy that they use this software as one of their controls, then the auditor will ding them if they don’t use it.
It’s an absurd system.
- georgyo 5y agoReminds me when I was doing PCI compliance. A PCI question asks if all outbound traffic is explicitly authorized. I took that to mean getting a list of all the IPs for the APIs of services we hit, and even constructed that entire list except for one, the payment processor itself. The payment processor did not have any stable IPs, and could not give me a list. Their official solution was to have our policy be that we explicitly allow _all_ outbound traffic. If such an option is allowed by PCI, what is even the point of making it a requirement?
- Vendan 5y agoThe point, with a TON of these certifications/auditing/whatever, is usually "Are you aware of risk X/Y/Z and are you either mitigating it or accepting it?" In this case, you are now aware that all outbound traffic is allowed, and you are accepting that risk as a risk of doing business with that payment processor.
- fatbird 5y agoAs Vendan said, the point is to get explicit acknowledgement that you're aware of something and have either mitigated it or accepted it. Which sounds kind of dumb, like ISO9000 certification, where the joke is "it doesn't matter how bad our processes are as long as we write them down!" I made that joke to a VP once, and he brightened up and said "Yes! Exactly! Because until you're actually following explicit processes, you don't even know what you're doing wrong, in order to fix it!" So I'm a lot less cynical about auditing certifications like this now.
- xtracto 5y ago> If such an option is allowed by PCI, what is even the point of making it a requirement? The point of all those certifications (I took companies through the processes required for PCI, SOC2, and ISO27001 ) is security theater, a path in the back for the execs, the ability to have "I'm not to blame, I have this cert" in case of some shit happening, and the ability for sales to throw TLAs to prospects to show how Seriously(tm) the company takes security. Oh, and to check boxes to be able to transact with some large corporations. There are plenty of stories of highly certified companies that were deeply penetrated and exposed, and all their security theater did not help.
- tptacek 5y agoIt's an extremely low bar for cluefulness. There is space between the bar and the ground, but most serious going concerns clear it easily unless they screw up the compliance process and make things hard for themselves. The problem isn't these low bars, but rather the market for services to "help" people clear them, and the widespread perception that the bars are higher than they actually are.
- thraxil 5y agoYes and no. SOC2 doesn't say you need to install an agent, and may not be explicitly prescriptive about whether computers that have access to production data or systems need encrypted drives, screenlocks, etc. But a non-hack SOC2 auditor is going to expect you to have some reasonable policy and controls in that area. So yeah, the main thrust of SOC2 is "are you following your own internal policies", but the auditors are also expected to hold you to some minimal standards on your policies (or ask you to provide a good explanation why they shouldn't apply in your case). You definitely would't want to tie yourself to a particular agent in your policy, but the auditors will want to see some kind of policy and then require evidence for that, either from something like an agent or screenshots/etc.
- tptacek 5y agoMore importantly: once you start using agents as a control, your auditor is very much going to expect you to be consistent about it; that's essentially the core thing SOC2 measures, is consistent enforcement of a documented policy. The whole point is not making random exceptions.
- DnDGrognard 5y agoThe same thing happened in the early days of ISO 9000
- vidanay 5y agoISO9000: We make a piece of shit product, but it's a very well documented piece of shit product.