HNHacker News
TopNewBestAskShowJobs

shravvmehtaa

126 karma · joined September 11, 2013

submissionscomments
shravvmehtaa··on Ask HN: My client want an agent on my laptop. Is this the new normal?
Hi, founder of Secureframe (https://secureframe.com) here. Secureframe helps streamline compliance across SOC 2, ISO 27001, HIPAA, PCI DSS, and more.

There are so many accurate responses in this thread. Like many have mentioned, SOC 2 is indeed not a prescriptive framework. Much of the confusion behind SOC 2 stems from that fact. It allows you to customize your InfoSec program to your company's needs. As we know, this can vary from company to company, hence why I read so many correct ways of approaching this specific situation in the thread.

Why SOC 2? SOC 2 is primarily customer-driven (this is why it becomes so urgent on your org). Buyer's require their vendors to undergo these third-party audits for their own vendor security management. While they would love to take you at your word, they feel a bit better knowing that a third-party took a look under the hood of your InfoSec program.

Employee vs. Contractor The legal status of an employee vs. contractor doesn't really matter for SOC 2 or most other InfoSec frameworks. At a minimum, what they really care about is the individuals ability to access, modify, view or otherwise have an effect on production/customer data. If an individual has that ability, they are likely in-scope (this can mean a lot of things). If an individual is indeed in-scope for your audit, they should follow your InfoSec program. You can always have carveouts for certain scenarios (for example, background checks are illegal in many countries so you may exclude them for individuals in those countries).

Company Policy What this all comes down to is the policy that the company has put in place. Does the company require all employees and contractors regardless of access to have hard drives encrypted without any carveouts? If so, then the company must follow that practice, or they will risk get an exception on their SOC 2 audit report. SOC 2 has some minimum standards that auditors look for but ultimately the company sets its controls and policies (if they are barebones they might not get accepted). Auditors are human and since SOC 2 is not prescriptive, reasonable minds will differ as to what those minimums exactly are.

Common Recommendation This has been mentioned a number of times in this thread but what we typically see and recommend is that you treat all employees as in-scope (this makes it easier on the company so they don't have to make determinations about who should and shouldn't be in-scope) and then for all contractors, you create a carveout where if they don't have access etc to production/customer data then they are not in-scope. In this case, such contractors would not need to track things like hard drive encryption, rendering the need for the agent moot. This seems in-line with the original posters role, and we would typically not have our customers require this of such a contractor.

There is nuance needed to make some of these determinations. For example, a company could hire a contractor who only has access to source code. In this case, an auditor may say that this contractor is indeed in-scope since they have control to modify source code that is pushed to production, even though they don't have direct access to the production itself.

We can't speak to the Drata agent, but based on what we would expect, the organization in OP's question is most likely trying to simplify evidence gathering when it comes time for the audit. There are other ways to grab such evidence (manual screenshots), but they are time consuming. Based on OP's job description it doesn't seem like its necessary for OP to be in-scope in this scenario and therefore the organization shouldn't need to collect such data. However, as we mentioned, this organization could have more stringent policies and without more information there isn't a wrong or right answer here. What we can confidently say is that it isn't a hard SOC 2 requirement.

shravvmehtaa··on Ask HN: Is the ISO 27001 certification worth it?
Hi, I'm one of the founders of Secureframe.com.

At Secureframe we help customers streamline their SOC 2, ISO 27001, HIPAA, and PCI compliance. And much more! If you are selling to customers in Europe or Asia, ISO 27001 is quite commonly requested. In the US, SOC 2 tends to be more common.

When it comes to the process, an ISO 27001 certification has two stages and includes an annual renewal.

- Stage 1: Evaluates the right documentation and controls in place in order to progress to Stage 2. - Stage 2: Evaluates the evidence to prove your controls and ISMS are effective, and that they meet the ISO 27001 requirements. Passing Stage 2 results in an ISO 27001 certification.

Stage 1 can be completed pretty quickly, but Stage 2 can take a bit more time to evaluate the evidence for. It can be done in a few weeks with a tool like Secureframe. It can cost < $10k for smaller companies. It often can make or break deals, so customers tend to get certified earlier rather than later.

Secureframe is the only security & compliance platform that has an ISO 27001 certification of its own. We save customers dozens of hours by automatically generating key documents like your Statement of Applicability. These can be incredibly time consuming and complex when you try to do it yourself.

Happy to chat more! shrav[at]secureframe.com

shravvmehtaa··on Ask HN: As a new SaaS business, how do you find your first 10 paying clients?
shrav[at]secureframe.com here. We can help you with the SOC 2 side of things pretty quickly!
shravvmehtaa··on Ask HN: Who is hiring right now?
Secureframe | Software Engineer | San Francisco, CA | Full-time | Onsite

Secureframe is on a mission to help companies secure themselves and their customers. We are building software to address problems that affect nearly every modern business, like achieving SOC 2 compliance fast, and for a fraction of the cost.

The full job description is available here: https://angel.co/company/secureframe/jobs/750671-software-en...

shravvmehtaa··on Ask HN: What is your go-to example for a good REST API?
https://lob.com/docs.

I'm an engineer at Lob. We'd love any feedback! support@lob.com.

shravvmehtaa··on Show HN: Mailform – Print and Mail in bulk from your browser
Hi, Lob employee here! Mailform actually uses Lob.

Lob's focus is on building printing and mailing infrastructure accessible through our API. Mailform is creating an easy to use interface (via Lob) for customers to print their documents.

shravvmehtaa··on Enveloupe: An API for snail mail
Lob employee here. We are running beta services in the UK, please email support@lob.com for more information!
shravvmehtaa··on Enveloupe: An API for snail mail
Hey, Lob employee here! Feel free to email me at shrav@lob.com. I'd be happy to give you any tips or tricks!
shravvmehtaa··on Ask HN: Who is hiring? (September 2015)
Lob.com (YC S13): San Francisco, CA - Full Time, No Remote, Relocation Possible, No Visa Sponsorship Possible

Lob is building a suite of APIs for the enterprise. Built with developers in mind, Lob provides tools that allow businesses to build scalable and powerful applications. The most popular API is a print and mail API that enables companies to send postcards, letters, checks, photos, and more as effortlessly as sending emails. Lob is based in San Francisco, CA and is venture backed with over 5000 customers including Intuit, LendUp, Porch, and Ubiquiti Networks.

You'll be working with a very talented team working on lots of interesting engineering challenges! We're looking for talented engineers passionate about building APIs for the enterprise!

Experience with Angular or Node.js & Hapi is a bonus, but not required.

shravvmehtaa··on Ask HN: What should I do if I feel depressed in my job?
www.hired.com
shravvmehtaa··on Stop Using LinkedIn
Linkedin has been known to shut down competing services prior to this. At hired.com, our API access was revoked (a long while ago), and many of our users were no longer able to login.
shravvmehtaa··on Ask HN: I got let go this morning. What should I do next?
www.hired.com
shravvmehtaa··on One Year Review of Lob.com
Email us at support@lob.com, and I'll see what we can do to help!
shravvmehtaa··on Meet the New Filepicker Team
Hi Jason, What happened to the old team? Why did they quit? What happened to INK?
shravvmehtaa··on The $357 Uber Ride
A while ago my Uber account got banned when I had to leave for a flight at the SJC airport. I wasn't able to contact customer support or even get in touch with someone till almost 3 days later, after various tweets. Really disappointed in how they treat their customers. They also asked me to send pictures of my Drivers License and Debt Card over email to unfreeze my account for no reason. Luckily, I caught a Lyft. Uber needs to work on this.
shravvmehtaa··on Talks from Hackcon, the first Hackathon Organizers' Conference
Wow some really good talks.
shravvmehtaa··on A Hackathon for High Schoolers
Wow this is awesome.
shravvmehtaa··on Hackathon Playbook Part 2: How to Organize an Event
Also, often times the computer that aren't capable of going on 5Ghz WiFi networks have lots of problems connecting. 5Ghz networks are capable of handling more connections and don't have as many problems with interference. All new macs and most new smartphones are capable of 5Ghz. Although many PCs may only be capable of 2.4Ghz, which can have many problems with interference. If you have any questions about your setup and how to do it cheaply, email me at shrav@hshacks.com.
shravvmehtaa··on Hackathon Playbook Part 2: How to Organize an Event
For 1000 Hackers: Backend: At minimum get a 1Gigabit line, try to get a 5Gigabit line. Frontend: This is usually where the problem is. Many hackathons spend 20-40k on this. Do not get super routers (those big routers that claim to handle 250 people at once), they get clogged. Hacktech.io had many problems with that. Have routers placed throughout the area. Get a wired internet connection for your sponsors at the minimum. At hackathon.launch.co they had wired connections for every hacker, which was impressive. You should definitely have 10-20 switches lying around for hackers to connect with. It will help unclog the network. But if you can get a wired connection for everyone that is even better.
shravvmehtaa··on Move Your Domain Day: Support EFF
This is awesome! Love NameCheap. Network solutions is totally screwing me right now by charging me $15 randomly for customer support and things I'm not ordering. And I can't get a refund after 6-7 hours on the phone...
shravvmehtaa··on Network Solutions Auto-Enroll: $1,850
The same thing happened to me. I keep getting charged $15 for customer support I am not ordering, and I can't get it cancelled. After spending over 10 hours on the phone with customer service none of them have the ability to refund orders... Never use them.
shravvmehtaa··on ATT Uverse and Cell Phone Service Down for all of the Bay Area
Yes, it only affected ATT customers as far as I am aware. I meant to include DSL haha.
shravvmehtaa··on How do I get hired as a high schooler?
Thanks for the post!
shravvmehtaa··on APIs are Eating Up Software
Exactly, API are definitely the future. Many companies want to integrate products into their own software or solutions. API are easily allowing people to do that. Lob.com sounds awesome, and the prices are really good!
shravvmehtaa··on I didn't get into YC – here's my project
Wow, this is really cool!
shravvmehtaa··on Why Teens Are Losing Interest In Facebook
Very true!
shravvmehtaa··on Ask HN: What are you working on and why is it cool?
http://www.hshacks.com. Introducing hacking to the younger generation. Our goal is to introduce as many people to computer science as possible with our hackathon, and promote computer science education to as many females as possible. Companies are looking for more computer science talent and want more to see more females in their company ranks. There are almost 30% less females in computer science compared to males. We are here to provide the mentorship and training needed to become a great developer. We aim to teach students the basics of computer science by holding workshops, teaching the basics of web development, developing iPhone and Android applications, and integrating third party products (APIs) into applications.