|
|
|
|
|
by tptacek
7 days ago
|
|
I'm not going to, like, whip out my resume here, but I am going to confidently assert that if you structure your Type 1 carefully, you can trivialize your Type 2, and as someone currently operating a globally deployed public cloud I can tell you right now that SOC2 doesn't really touch on anything interesting in our engineering. I wrote an article about this, and I think it's the Correct advice for virtually every startup thinking about SOC2: https://fly.io/blog/soc2-the-screenshots-will-continue-until... A few years before that, I wrote an article about what we learned from the consulting practice we ran building SOC2-supporting security programs for startups: https://www.latacora.com/blog/2020/03/12/soc2-starting-seven... I've had the experience, many times, of offering this advice in some forum and having someone try to rebut it, claiming that SOC2 is difficult, or that real customers will pick a SOC2 attestation apart with a fine-toothed comb looking for shortcuts you took, or that they built their whole security practice around SOC2. I can go all 12 rounds with someone on any of those points, but I think you can get most of my take from those two posts. |
|