SOC2 is pretty heavy duty to achieve and to maintain.
But SOC2 is not a guarantee that your company will be impervious to the kinds of mistakes that landed them in hot water this year.
SOC2 is pretty heavy duty to achieve and to maintain.
But SOC2 is not a guarantee that your company will be impervious to the kinds of mistakes that landed them in hot water this year.
As an auditee who dealt with SOC2 for the last 3 years I'd say that's not true. It's heavy on reviewing documentation and not the true efficacy of your security program.
LOL, no. I've gone through SOC2, and it's not hard at all to achieve. SOC2 is basically just about (1) documenting controls and (2) following them. You have a lot of leeway with your auditor on what those controls entail (and remember, you choose and pay your auditor, so there's also a huge conflict of interest here).
We did have to do a yearly security audit, but it's foolish to think that will catch all issues, and it relies a lot on the company being helpful and open with their auditor. You also a lot of leeway in arguing down issue severity.
We got SOC2 certified because many companies require that their vendors have it, but I personally think it has little to no value, and I would not trust a company any more because they've gone through it.
Were there any requirements about pentesting one's company somehow?
Did they look at source code?
https://en.wikipedia.org/wiki/Code_audit
And there's a job role called "Source Code Auditor".
Question was if GGP's SOC2 case involved any such source code audits or not.
Now, having read https://latacora.micro.blog/2020/03/12/the-soc-starting.html (linked from a nearby comment, https://news.ycombinator.com/item?id=25489586), seems SOC2 does not include those types of audits. Could still be nice to hear directly from GGP @necubi though. ("yearly security audit"?)
https://latacora.micro.blog/2020/03/12/the-soc-starting.html
says that SOC2 is (mostly) about sales and little about validating security practices, only that you have them. I find it telling that SOC2 audits are performed by accountants.