4 ms·
Here here. The only thing SOC2 has done in my opinion is to create a multibillion dollar business that mainly just drains resources from companies that may not
by nurple 2y ago
Here here. The only thing SOC2 has done in my opinion is to create a multibillion dollar business that mainly just drains resources from companies that may not have them, with no guarantees you're actually secure. This usually devolves into security theatre where the CISO and underlings are putting in tools that drown teams with so much noise it's hard to detect the signal.
The people running these programs rarely understand the security space well enough to even tell you what a lot of the hits even mean, which ramps up disdain and division between the groups. This is arguably more detrimental to security as the scanners give execs/management a false sense of security while the noise makes it incredibly difficult to run a holistic security strategy.
- sillysaurusx 2y ago(It’s "hear hear," since you want people to hear it. Honestly I have no idea whether to say something or not. But I’d want to know, so, just in case it’s helpful.)
- nurple 2y agoCrap, I always get that wrong. Thanks for the reminder! ETA: like I told my kids, if we don't police each other, the LLMs will never learn. ;)
- Alexsky2 2y agoI agree that regulatory compliance and industries around that can often be theater and it creates regulatory barriers that inhibit startups and competition generally but there must be some method of oversight to ensure that people can trust a system or company without needing to see the internals. For example, we trust our food is healthy because the firm that made it is authorized to do so by the FDA as they comply with the rules established by those regulators. Obviously there are flaws, loopholes, etc, and obviously software is different than health but to an extent we want some guarantees from an externally trusted actor. What is needed in the current SOC2 world that might solve some of the issues you outlined without getting rid of it, or the idea of it, entirely?
- stackskipton 2y ago>What is needed in the current SOC2 world that might solve some of the issues you outlined without getting rid of it, or the idea of it, entirely? IMO, nothing. It's not redeemable at all. Since you asked though, here is some thoughts: Be more like FDA process where software is extensively reviewed, rollback procedures established, and you launch specific version with compliance. So basically two releases, maybe 4 a year. Disallowing risk mitigation because IMO, that's result of most of problems. Oh yea, we are doing "Terrible Security thing but since fixing is too expensive, here is a bunch of lies about how we have mitigated it." There is also option to make a government audit with criminal liability for falsifying/misleading auditors. This third-party system where auditors are getting paid results in problems. I've seen plenty of audits where bosses write up auditor requests is extremely specific ways that creatively leave out thing that should never be approved. I've also seen auditors be made aware of problem, then people backtrack, and auditors accept it because "They are also our customer and we need repeat business."