Hacker News new | ask | show | jobs
by akerl_ 7 days ago
I'm scared of companies where SOC2 auditors are driving their security improvements. It's a bit like letting my toddler drive how I stock my pantry: surely by the end the pantry will be more full, but not really in the way I want.
1 comments

It's not auditors, it's the compliance requirements and controls. You should not even reach to an auditor before fixing the controls (most of them, the ones you lack auditor must flag, as sometimes it's not feasible to fix most of the controls). I'd say going through an audit is easy, but preparing for the audit is hard.

PS: regarding "most of them" -- if you're one-person shop, you'll likely fail a control that requires your board of directors to be independent of company management (i.e. having directors that do not work for the company). That's OK, but will be reported on your SOC2 report.

Security and compliance are totally different functions and one has little to do with the other.
I mean, if you don’t think about it that’s true.