Live data from Hacker News

Apple Private Cloud Compute SoC 3 audit reports

support.apple.com

11–20 of 61 posts

Re: Apple Private Cloud Compute SoC 3 audit reports

#11
post #6

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they pic…

I think companies like Deel showed that SOC2 is more show than anything else.

For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

Re: Apple Private Cloud Compute SoC 3 audit reports

#12
post #6

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

> "look I can afford 50k"

Oh no. Looks like you never went through SOC2.

1. No, it does not require 50k, an auditor can cost way less (10k? maybe even less).

2. But the process of preparing for the audit will take a lot of work securing your systems (and increasing reliability and privacy as well), as long as you take it seriously. Of course you can lie to the auditor, but it's up on you. And auditor -- they might lose their CPA license and go to prison. Their job is to catch your lies.

Source -- went through it, and took it seriously. It really did increase our security stance, even though we thought we were good at it.

Re: Apple Private Cloud Compute SoC 3 audit reports

#13
post #6

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they pic…

Well you "claiming controls" to an independent CPA auditor. If a licensed CPA helps you lie -- they might lose their license (and can even get to prison), just like a tax preparer CPA can.

Re: Apple Private Cloud Compute SoC 3 audit reports

#15
post #12
post #6

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

> "look I can afford 50k" Oh no. Looks like you never went through SOC2. 1. No, it does not require 50k, an auditor can cost way less (10k? maybe even less). 2. But the process of preparing for the audit will take a lot of work securing your systems (and increasing reliability and privacy as well), as long as you take it seriously. Of course you can lie to the auditor, but it's up on you. And auditor -- they might lo…

That auditors are responsible for catching the lies of an audited company on penalty of being suspended is a position that the big audit firms would not agree with. They might agree that they are responsible for ensuring the material accuracy of accounts if fraud occurs, but even here EY has disclaimed responsibility if the fraud were sufficiently complex [0]. Indeed auditors lobbied very hard against being mandated with a broader anti-fraud role [1].

Admittedly this is on the "real" audit side and not the advisory/consulting side, which would be the ones to handle SOC I imagine, but nonetheless a position I find a bit absurd.

[0]: https://www.ft.com/content/a9deb987-df70-4a72-bd41-47ed8942e...? [1]: https://www.ft.com/content/c25de9fb-a808-4946-ade6-80d76a66a...

Re: Apple Private Cloud Compute SoC 3 audit reports

#16
post #6

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

Last I chatted with some friends who were going through their first SOC2, they quoted a much lower number.

Re: Apple Private Cloud Compute SoC 3 audit reports

#17

Earlier quoted context omitted.

Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they pic…

I think companies like Deel showed that SOC2 is more show than anything else. For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

Hasn't Deel been run out of business though?

IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.

Re: Apple Private Cloud Compute SoC 3 audit reports

#18
post #9
post #6

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

Everyone lies on SOC2. Auditors don't understand the technologies and just take peoples word for it. It's a shit practice

Citation needed. This is not my experience at all, after participating in such efforts at three different companies.

Re: Apple Private Cloud Compute SoC 3 audit reports

#20
post #9

Earlier quoted context omitted.

Everyone lies on SOC2. Auditors don't understand the technologies and just take peoples word for it. It's a shit practice

Citation needed. This is not my experience at all, after participating in such efforts at three different companies.

I'll just cite my 30 years in IT/InfoSec. Believe it or not, I really don't give a damn. It's common knowledge int he field regardless of what your experience is.
Post reply on HN