Earlier quoted context omitted.
Shouldn’t according to who? Who appointed ISO to say what should and shouldn’t be done?
The majority of countries that do business today have backed it. You are welcome to ignore it and work against the 160 countries that are using it.
Delve – Fake Compliance as a Service
291–300 of 327 posts
Re: Delve – Fake Compliance as a Service
#292Earlier quoted context omitted.
HN would be an entirely different place if people could just arrange to get their stuff upvoted onto the front page! We've spent hundreds of hours working on this over the years. Still not perfect of course.
My theory is that a lot of people may have looked for a story like this on the home page and then searched ‘Delve’ to see if anything was submitted recently and then upvoted one of those recently submitted posts.
Re: Delve – Fake Compliance as a Service
#293Re: Delve – Fake Compliance as a Service
#294Earlier quoted context omitted.
Well, yes, but that's the point of many contracts, they are often designed to shift risk to parties that are better equipped to handle those risks. We run our app on GCP because as a 20 person company I don't want to be responsible for physical security and a million other risks. With ISO27001 or SOC 2, I have more information about the other party's ability to manage those risks than just taking their word for it. I…
> With ISO27001 or SOC 2, I have more information about the other party's ability to ... spend time and money to emulate the asinine requirements of outdated standards instead of actually making the product better and more secure. > I'm trusting a third party auditor to vouch for them. Like Delve?
And Delve isn't an auditor. Though they were apparently in cohoots with equally criminal third party auditors. So I guess I'm going to be looking more closely at just exactly who exactly are auditing our vendors in the future...
Re: Delve – Fake Compliance as a Service
#295Forbes 30u30 pipeline remains undefeated. How did none of this come up during diligence? Feels like a prime example of too good to be true.
Re: Delve – Fake Compliance as a Service
#296Earlier quoted context omitted.
Most people only care about compliance if it stops them from closing a deal. I was at a startup where some enterprise said we needed a SOC 2. The founder talked them out of it by giving them a discount if they'd waive the requirement.
My company is tiny (just me) and at one point a client sent over a questionnaire that I needed to fill out. Half the things I already did, about 1/4th I did right then so I could check the box (added features/reports/etc), and the last 1/4th I looked into (including SOC2) and decided I’d rather lose the deal than try to do those things. I was completely truthful in the questionnaire and for those sections I just put…
Same boat about 2 years ago: the compliance is a lot more flexible than you would think - it doesn't matter if you have a poor password policy, what matters is that you document you have a poor password policy.
Your client didn't have to get a compliant vendor to remain compliant themselves; what matters to their compliance is formal attestations from their vendor about where they are not compliant.
As a 1-man show I went through the same thing, still got the contract even though I had to formally attest to not having maybe 25% of those boxes ticked. The whole point is that it is recorded that you don't have MFA, or that you failed a pentest on these 5 items... or that you have a vendor who fails these specific 43 requirements.
Re: Delve – Fake Compliance as a Service
#297I remember having sales calls with them and the vibe was that it was "cheap and quick"... exactly what you want for your compliance
If you read through the report PDFs of affected companies, you'll find a lot of stock wording and phrases that don't even make sense.
Re: Delve – Fake Compliance as a Service
#29880% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
> 80% of Compliance has always been a performative box checking exercise. You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did. If you didn't check that box you could always claim you didn't know you weren't…
The company may be legally in troble if the planets are aligned but that's all.
Re: Delve – Fake Compliance as a Service
#299Earlier quoted context omitted.
The majority of countries that do business today have backed it. You are welcome to ignore it and work against the 160 countries that are using it.
who . Countries are not people.