Remix.run Logo
datakan 3 hours ago

Everyone lies on SOC2. Auditors don't understand the technologies and just take peoples word for it. It's a shit practice

paulryanrogers 2 hours ago | parent [-]

Citation needed. This is not my experience at all, after participating in such efforts at three different companies.

tptacek 24 minutes ago | parent | next [-]

I wouldn't put it the way they did but they're directionally sane about this. I would worry a lot more about someone repping their SOC2 as important or meaningful than I would worry about someone who was cynical about SOC2.

(I don't mean Apple; Apple spends more on security than almost any firm in the world.)

https://fly.io/blog/soc2-the-screenshots-will-continue-until...

datakan an hour ago | parent | prev [-]

I'll just cite my 30 years in IT/InfoSec. Believe it or not, I really don't give a damn. It's common knowledge int he field regardless of what your experience is.

paulryanrogers an hour ago | parent [-]

Can you name the names of SOC auditors that are rubber stamping?

Or point me to some public critiques within the industry?

an0malous an hour ago | parent [-]

Wasn’t that YC startup Delve doing exactly this?

https://www.iansresearch.com/resources/all-blogs/post/securi...