> This isn’t something we were doing prior to SOC2. We have components that are effectively teams-of-one; getting reviews prior to merging changes for those components would be a drag.
This mindset kind of blows my mind. As a customer, it makes me want to ask all my vendors for SOC2 now.
As a comparison, we have a small in-house team that develops some nonprofit websites; no PR goes to production without being reviewed by another developer.
I’m honestly flabbergasted at such a seemingly blasé attitude about insider threats. It doesn’t have to be a top-secret Chinese operation to subvert your company. It can be as simple as a developer you know well who is nursing some simmering resentment over a perceived slight.