4 ms·
https://latacora.micro.blog/2020/03/12/the-soc-starting.html https://latacora.micro.blog/2020/03/12/the-soc-starting.html That is specifically written for star
by dfc 4y ago
https://latacora.micro.blog/2020/03/12/the-soc-starting.html https://latacora.micro.blog/2020/03/12/the-soc-starting.html
That is specifically written for startups that may have to do SOC2 compliance in the future. But it is a useful starting point for most people.
#1: Single Sign-On
#2: PRs, Protected Branches, and CI/CD
#3: Centralized Logging
#4: Terraform Or Something
#5: CloudTrail And AssumeRole
#6: MDM
#7: VendorSec
- jms703 4y agoCame here to post this!
- number6 4y agoI am currently stuggeling setting up centralized logging; just can´t grok it. Logstash? Beats? Elastic Agent? Is ELK-Stack right in 2022? How do I get Logs out of Docker to Logstash? Do I? Seems I need to get my head around this...
- patrakov 4y agoPlease take a look at Loki. It's more lightweight than the ELK stack.
- zie 4y agoGenerally you will find lots of different solutions to make it all work right. None of them are "wrong" or "right", there are 2 pieces to logs: 1) Capturing them 2) Indexing/acting on them Most tools focus on one or the other, some focus on both. > Logstash? Beats? Elastic Agent? Is ELK-Stack right in 2022? Loki and Graylog solve both issues in an integrated way. logstash, beats and syslog tend to focus only on the 1st part, moving the lots to a central place. > How do I get Logs out of Docker to Logstash? Do I? Yes you want the logs from Docker jobs. You can use a sidecar, or you can have the Docker image ship the logs or if you are running k8s, Nomad, etc they might be able to do it for you. The more important thing is the 1st, getting them all to one host, in pretty much any format. Once you have them there, then you can worry about trying to make sense of them.
- theblazehen 4y agoI'm pretty happy with Loki + promtail so far
- number6 4y agoI will set it up next Day at work, thanks for the advice
- alexjplant 4y agoIf you do I strongly recommend storing the indices with the chunks[0] and configuring a hassle-free, scalable storage solution [1] up front. Migrating chunk storage after the fact is a royal pain. Do also note that the official Helm chart will only get you so far before you have to start horizontally scaling individual components [2]; depending upon your query and log volume you might want to scale these separately and the chart [3] doesn't support this. This GitHub issue [4] has some Kubernetes YAML examples if you need them. [0] https://grafana.com/docs/loki/latest/operations/storage/boltdb-shipper/ https://grafana.com/docs/loki/latest/operations/storage/bolt... [1] https://grafana.com/docs/loki/latest/operations/storage/#supported-stores https://grafana.com/docs/loki/latest/operations/storage/#sup... [2] https://grafana.com/docs/loki/latest/fundamentals/architecture/components/ https://grafana.com/docs/loki/latest/fundamentals/architectu... [3] https://github.com/grafana/helm-charts/blob/main/charts/loki/templates/statefulset.yaml https://github.com/grafana/helm-charts/blob/main/charts/loki... [4] https://github.com/grafana/loki/issues/643 https://github.com/grafana/loki/issues/643
- theptip 4y agoIf you just want to pay someone and move on, Datadog has great connectors, but is expensive. I hear Honeycomb is great, and they have a free tier. (I started with Grafana and Prometheus FWIW)
- pc86 4y agoThe most important (IMO) paragraph from that page: > If there is one thing to understand about SOC2 audits, it’s: SOC2 is about documentation, not reality. SOC2 audits are performed by accountants, not pentesters. You’ll tell your audit team what security things you try to do. They’ll call upon the four cardinal directions of ontology in a ceremony of shamanic accountancy. They’ll tell you those security things are just fine. Then they’ll give you a 52,000-line questionnaire called the Information Request List (IRL), based in some occult way on what you told them you’re doing. And you’ll fill it out. You’ll have a few meetings and then write them a check. They’ll put your company name on a report.
- gooseyman 4y agoFirst job after college was subbing in for a team doing a SOC2 audit. They sent me in to test AD. I googled AD before the client meeting to learn that it was this thing called Active Directory. They had really well documented controls and the screenshot of the AD settings they sent me looked great in my report. (Yup - all AD settings in one screenshot).
- dyeje 4y agoIMO 1, 5, and 6 are not appropriate for early stage startups (unless you’re making enterprise software). They’re going to slow you down, add unnecessary burn, and just generally not be value adds. You should be focused on making a product that people pay money for, not box checking for a hypothetical SOC2.
- tptacek 4y agoI wrote this list, several years ago. I've since had the pleasure of taking a fast-growing startup (Fly.io) through SOC2. (This list was based on my experience consulting with a bunch of large-ish startups while they were SOC2'ing, and interviewing peers). I would hold fast on #1 (Single Sign-On). Do SSO now. Make it one of the first security things you do. It's worth it on its own merits, and if you do it right, it makes things easier, not harder. My one-two punch for most startups would be Google SSO and Tailscale. If you're hosting in AWS, you basically have to turn CloudTrail on, which was my #5. It's not slowing you down; you just need the data collecting. You can't deploy on AWS and not have an audit trail; that's bananas. If I was writing that article over again, I'd strike #6 (MDM). It's fallen out of fashion to do endpoint security in SOC2; you should introduce endpoint security when you have the bandwidth to do it well. So: #1-5 and #7, I'd do right away. #6, I'd wait until after my first security hire.
- dyeje 4y agoIt’s a good list and I’ve referenced it a few times over the years. I misunderstood your intent on #5. I still think SSO is inappropriate because it’s going to bump you into enterprise tiers for random products when you need to be the most frugal with your burn. Going with 1Password or similar gets the job done. You 100% need SSO eventually and it does get harder to implement the longer you wait, but I still don’t think it’s worth it early. I think MDM is still a thing for SOC2, but my point is that most startups will not need a SOC2 immediately and folks should be mindful of what moves the needle security wise vs what auditors want.
- tptacek 4y agoWe just did a SOC2, and were encouraged not to do endpoint stuff in it. You can ask your auditors to require MDM, but you don't have to, and shouldn't. You can pick which apps to enroll in SSO; you don't have to pay the sso.tax on everything. Most of the time it's not material anyways.
- throwawaymanbot 4y ago