|
|
|
|
|
by too_pricey
1650 days ago
|
|
You're completely right re Drata as a company (we use a different compliance vendor, but very similar setup re the agent). You're a bit off on whether this would fail a SOC2 audit, thankfully. As the OP said, they don't have access to production systems, which basically means you can treat that employee however you want from a SOC2 (and ISO, and most other control framework perspectives). The company OP is working for can state "We do not require these controls on contractors without production access" and that is totally fine for SOC2. Pushing back on the agent requirement is totally reasonable! |
|