Viewing profile — whatinthenote
whatinthenote
HN member- Joined
- Thu, Jul 07, 2022, 9:05 PM UTC
- HN karma
- 11
- Public activity
- 13 items
- HN profile
- View on Hacker News ↗
About whatinthenote
No profile information was provided.
Recent public activity
-
comment
Comment #47462212
It feels like I'm screaming into the void, but compliance work is bad is because people make it so. Willfully paying for a service that offers SOC 2 reports at 1/5th the usual rate…
-
comment
Comment #47460048
Doesn't seem like a problem with SOC 2 compliance, seems like a problem where a company appointed someone who is not suited to handle a SOC 2 project. As for the pre-filled stuff, …
-
comment
Comment #39133989
Same people that thinks they can build an Uber/Lyft/Instagram competitor by themselves over the weekend.
-
comment
Comment #33987137
As the Americans learned so painfully in Earth's final century, free flow of information is the only safeguard against tyranny. The once-chained people whose leaders at last lose t…
-
comment
Comment #32358666
The source being a tweet from clear right wing nutcase. Not gonna waste my time looking through his tweets to learn that he thinks there are "election fraud" in AZ. I'm not a labor…
-
comment
Comment #32023614
What's actual security? Looking for zero days? Malware research? Continuous red team? I think at the end of the day, SOC 2 aims to instill a basic level of organizational security …
-
comment
Comment #32023488
I don't deny that there are certainly companies that act in bad faith (say one thing in their SOC 2, but do another), but I don't consider it to be a fault of the SOC 2 process. Ju…
-
comment
Comment #32021270
I love it when nothing is documented and every process exists in someone's head.
-
comment
Comment #32021057
Actually, the easiest thing is to find a better auditor. A SOC audit isn't like an IRS audit, you actually pay them to come in and audit. Not all are created equal and sometimes yo…
-
comment
Comment #32021016
I don't understand why people assume SOC 2 can cover every single possible scenario. Especially scenarios that have nothing to do with actual SOC 2 controls, but the result of lax …
-
comment
Comment #32020892
I'm trying hard to figure out what any of this has to do with SOC 2. Perhaps consider the phrase "Don't let perfect be the enemy of good". Okta had a shitty breach, but does that m…
-
comment
Comment #32019604
I think one thing that doesn't get covered enough is SOC 2's value in providing additional data for vendor security reviews. That poor CISO that have to work on SOC 2 is probably t…
- comment