Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

271–280 of 327 posts

Re: Delve – Fake Compliance as a Service

#271
post #62

Earlier quoted context omitted.

Yes, but your team claimed this set off "voting ring" behavior [0] and it was suppressed for nearly a day because of that. I am very curious how you determine what is, or is not, "voting ring" behavior. I believe Dang is responding in another thread about that. [0]: https://news.ycombinator.com/item?id=47457689

Obviously we don't publish how HN's voting ring detector works. If we did, it would quickly stop working. What matters in this case is (1) it's a software penalty that has nothing to do with the content of a story, (2) moderators didn't touch the submissions or even know they existed, and (3) once we did know that they existed, we merged the threads and placed the story on the frontpage - that is, we went out of our…

[dead]

Re: Delve – Fake Compliance as a Service

#272

Earlier quoted context omitted.

It's also in the original post. Greptile, HockeyStack, and others from that cohort of 20-year old founders out of YC were having software engineer candidates come in day-in and day-out, staying until 9PM under the threat of being rejected if they left earlier. They were not paid at all, they were working long-term on a "trial period". And yes it's very illegal. I was there and saw it first-hand. The guys they had on…

Yikes

[dead]

Re: Delve – Fake Compliance as a Service

#273

Earlier quoted context omitted.

Do you really want to be compliant to ITIL 4 or do you want to sell to your target market? I'm pretty sure you want customers who pay money, and ITIL 4 badge is just a small mean to achieve that, not a goal per se.

It has to work in with a bunch of organisations who are doing (or attempting to do) ITIL 4 and are fairly insistent on things like consistency across ITSM platforms. The things is, you know and I know, ITIL is like sex in high school. Everyone says they're doing it loads, everyone says they know all about it, everyone says they're really good at it, but no-one is any good at it, no-one knows anything about it, and no…

This is hilarious. I had to steal this for my Twitter post.

Re: Delve – Fake Compliance as a Service

#274
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

What is the purpose of a business though? To make profits for its owners. If the profit lies in doing all this corporate theater then that's the business. A company that focuses only on providing a service and product but ignores how their customer needs to use said service and product is going to go out of business.

If the purpose of every business were making profits every business would be a hedge fund (at which point there could be no hedge funds, but that's a separate issue). Profits are a necessary component of a businesses's activities, but not its purpose.

Re: Delve – Fake Compliance as a Service

#275
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

The risk register is ISO 27001. The "I" in ISO doesn't stand for Internet, it stands for international. You shouldn't be doing business with international customers if you don't have a risk register, which is why they're requesting it.

The D in Democratic People's Republic of Korea means it should be democratic so why is it a dictatorship?

The world doesn't work based on abbreviations. It's very normal for any company to ask you for ISO 27001 whether international or otherwise.

Re: Delve – Fake Compliance as a Service

#276
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

"is very european." ... aa yes consumer protections. very european.

This assumes that there is only 1 way to protect consumers

Re: Delve – Fake Compliance as a Service

#277
post #171
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

Translation: all your rules and regulations are crap, and we don't want to comply with any of them. When in reality most rules and regulations are not crap, and you should care about them. Especially when your startup advertises compliance with HIPAA (medical records), PCI-DSS (payments data) and a bunch of other data protection standards and regulations.

Data protection is a tiny component of what certifications like ISO and SOC2 involve. The data protection stuff is welcome and often pre-existing, the other stuff is what annoys people.

Re: Delve – Fake Compliance as a Service

#278
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

SOC 2 is mostly about proving you do what your policies say, and there’s more flexibility than people think. For small teams it doesn’t have to be heavyweight. A risk register can be a simple doc with a few real risks and mitigations. That said, I agree there’s a lot of theater. For smaller companies and budgets, it often turns into rubber stamping. Auditors rely on the evidence you provide, so the report can look mu…

It ends up being a LARP

In reality the starting point itself is something absurd like "all vendors must be ISO certified no exceptions"

Nobody wants to be the person who says an exception is ok in this case, so you get lumped with having to certify.

Now your color palette generator startup is doing ISO certification. You are holding quarterly "information security governance meetings" and maintaining a risk register for... "blue vs slightly different blue".

Many such cases.

Re: Delve – Fake Compliance as a Service

#279
post #179

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

Okay, so who are we supposed to go to for SOC 2 compliance now if any number of the compliance automation companies might be charging 5 figures to do it fradulently?

Last time I went through SOC 2 we talked to our auditor about this. His view was that there are and basically always have been auditors/companies that will sign off on anything without verifying it if you're paying them. The rest of the industry knows who they are though. If you are taking things seriously and hire an auditor who does, that's one of the things that they look at when you're reviewing the reports from the services/subprocessors that you use. Ie, you can get a SOC 2 that doesn't mean anything but then any of your customers who know/care will flag it and it won't be worth anything.

Re: Delve – Fake Compliance as a Service

#280

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

I’d be amazed if the companies were entirely oblivious to this.

In my experience it’s we know that they know that we know that they know …..

Post reply on HN