The SOC2 Starting Seven (2020)
latacora.micro.blog
latacora.micro.blog
* It costs $40k in year one and $30k/year in subsequent years if you do the now typical stack of Vanta, pen test, vulnerability monitoring and audit fees. This makes ROI pretty straight forward to figure out.
* There's really no benefit to getting Type 1, you just need to get the Type 1 posture and then wait out the monitoring period in order to get type 2. If the customers actually care, they are smart enough to know that it's a lot harder to fudge it for 6 months than it is for one four hour Zoom call.
* You can definitely get to about 60% of SOC2 just doing obvious best practice (code reviews, SSO, HTTPS only, database alerting). The next 20% is worthwhile but not intuitive, the final 20% is neither.
Agreed with the top comment about infosec teams being reasonable. At this point I think it would be pretty hard to do deals with public companies without having Type 2, and our domain isn't even that security focused.
Even if you avoid SOC2, the security questionnaires (mostly avoidable if you have SOC2) from large companies can be so onerous if you're doing any sensitive work for them that SOC2 would be cheaper and less effort than the time spent on the questionnaires and infrastructure changes to meet them.
> open source versions of Vanta
... not aware of anything in this field. This has been on my "one day if I have time" lists to build.
I have kind of a meh opinion about Vanta, for what it's worth.
Very much agree with you about SOC 2 == obvious best practices if done reasonably!
That’s one of the “secrets” of SOC 2: if you speak some compliance, you can make most of the SOC 2 work for you, implementing best practices, getting the rest of the org to prioritize them, etc. (This is what we like about SOC 2 at Vanta: it can turn meaningful, difficult-to-measure security work into high-pri sales collateral.)
If you don’t speak compliance and have a SOC 2 consultant who doesn’t speak engineering, you’re more likely to end up with absurd arguments and bookkeeping (“but you have to use a WAF there’s just no other way!” etc.)
The most important thing is committed spend - eg. it's common for Big Corp Inc's infosec team to put you through compliance, potentially asking you to spend $0000's on time and services, without comparing that to the value of the contract you could have with them. You could spend a lot based on zero commitment it you take your eye off this.
Yes, that's the thing--the grueling infosec process is independent of commitment. It's a catch-22.
Teaching your salespersons to help their contacts/champions with convincing their internal security to lower classification will be great ROI for you :)
The article does a great job of cutting through all the noise.
Highlighting here because it is relevant: certification is about sales.
I’d only do it once you either:
1) you spend much more time filling out questionnaires than the time/investment needed to get certified (note, they’ll still ask you to fill out questionnaires though)
2) you want to go after companies that actually care about this (banking, government). Even then, these will have shortcuts through procurement that will lower requirements (ie: innovation projects, small ticket items)
Once you have 1 client in your target industry using your product, it is infinitely easier to get a 2nd client (assuming you can use the 1st as a positive reference).
SOC2 seems like an interview-time item if I were to try to put an analogy around it. Once you have a certain reputation and key players trust you, its a lot easier to navigate around regardless of your specific credentials.
Usually it’s not the certification that will make or break a deal, at least in our case.
I've personally gone through certifying a company as SOC2 and it makes you realize how much you want your vendors to have SOC2 controls.
Putting the things mentioned in the article in place will help a lot in answering to those questionnaires.
We have signed on a publicly-traded entity without having a SOC2 on hand. It's not impossible to make a deal happen if the customer really wants your product, and you can somehow prove to interested parties that you wont sink their ship in the process. We achieved this with technical deep-dive sessions which involved our customer's IT and security people. Being able to communicate with agility and think outside the box is a good way to get around red tape.
For us, the biggest thing our customers seem to be worried about is the continuity of our business relative to support of the product. Offering source code escrow through some 3rd party is a good way to help alleviate some of these types of concerns.
In February 2020 I pointed out that we had not had a single mass work-from-home emergency, so shouldn't we hold the exercise? I convinced enough execs that we held a two-day test, on the basis that nearly anything can be postponed one day in order not to do it from home, but perhaps not two. We solved a bunch of issues... and then we left the office in mid-March and haven't been back en-masse since.
but Vanta/Tugboat won't actually do the reviews and training and HR and executive reviews you need. Basically their deal is that they cut volume discounts with the audit firms and then take the rest. They have nice dashboards, don't get me wrong, but only their hand picked auditors will accept them. Others will require you to manually package up the same evidence anyway and upload to their IRL evidence system.
Re (1): SOC2 is about adherence to a stated portfolio of controls. Different companies use different controls to reach the same control objectives. Almost all of the control objectives can be met with straightforward best-practices engineering, like having a carefully managed and logged SSO (a reason Okta is so popular), or --- I'm not exaggerating here even a little bit --- being able to describe the basic features of Github to an accountant. I've seen tooling that asks people to install all sorts of random security tooling on desktops and (worse) on servers; having been in SOC2 interviews with major-firm auditors, I can say with confidence none of them know what the fuck any of that shit means.
Re (2): SOC2 is not your security program. SOC2 has no good advice for your security program. Any competently run security program can, with enough grueling documentation, achieve SOC2. The very last thing in the universe you want is "SOC2" literally installing itself on your machines.
I think there's a lot of value in things that help you build and fill out checklists that will allow you to quickly and easily satisfy SOC2 IRL questionnaires; also just to keep yourself organized. But remember that the engineering should come from your engineering team, not from the absolute randos who build prefab SOC2 checklists.
Overall, I'd rather being working with a certified vendor than not, but SOC2 ain't PCI.
It appears to be impossible to make people grasp this concept. So much wasted time talking at cross purposes about real security while other people in the room are talking about compliance and vice versa.
Paying someone to give me a list of problems isn't at all useful until we have nothing else to do. Appreciate there may be others out there without the same understanding of Infosec, but frankly that's a greater risk to companies without those resources.
As others have said above, the compliance part will be a by-product and will essentially fall in place modulo some extra documentation effort (which can be heavily borrowed from templates).
Vanta and StrikeGraph etc no doubt will make it more convenient to follow best practices and scaffold your continuous monitoring, but I see it as a nice to have, not a must have.
Though seeing the other comments that Vanta + audit being cheaper than audit alone is an interesting quality and may change the initial defensive rejection I have for receiving cold contact mail on non-public addresses (which means they also buy harvested data).
A newer tool that I’ve heard great feedback on is Drata. They’re more focused on automation and continuous evidence collection.
From a cost perspective, Vanta + a Vanta-partnered auditor was less expensive that just an auditor (presumably because the information was organized so the auditor had to do less work to complete the audit).
The Vanta platform ends up being a place to put documents so the auditor can find them (which is more useful than you might think if you haven't done a SOC-2 audit). They offer several Vanta-developed continuous monitoring tools (e.g., endpoint configuration monitoring, AWS vulnerability monitoring), which are not as well developed as independent tools (e.g., Kandji, AWS Inspector) but are convenient for auditors documenting continuous compliance.
As I understand it, they are working towards being more of an integration center for independent tools, so Kandji/AWS Inspector information can flow into the Vanta system.
A third party audit of your process (documentation, mostly) around managing risk.
You have a service. They want to make sure it's secure before working with you. They ask you to get this compliance done.
But the compliance, as mentioned in this article, doesn't really make sure your service is secure. It just makes sure you follow some security practices.
The "actual" reason big enterprises require SoC2 is not security. If something goes wrong, certain people within that enterprise are gonna be responsible for making the decision to work with you in the first place.
Having SoC2 in place makes sure those people can say "we did our homework".
I scrolled through the article, realized it was not for me, but I still don't know if it is an acronym or what it really does.