Live data from Hacker News

Apple Private Cloud Compute SoC 3 audit reports

support.apple.com

31–40 of 61 posts

Re: Apple Private Cloud Compute SoC 3 audit reports

#31
post #12
post #6

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

> "look I can afford 50k" Oh no. Looks like you never went through SOC2. 1. No, it does not require 50k, an auditor can cost way less (10k? maybe even less). 2. But the process of preparing for the audit will take a lot of work securing your systems (and increasing reliability and privacy as well), as long as you take it seriously. Of course you can lie to the auditor, but it's up on you. And auditor -- they might lo…

I co-ran a business with a significant SOC2 practice (we ran security programs for startups), and then oversaw Fly.io's SOC2 Type 2. The person you're responding to is more right than you are, and I would push back in a variety of ways on your point (2).

Re: Apple Private Cloud Compute SoC 3 audit reports

#32
post #6

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they pic…

Literally any firm can get a SOC2 Type 1, because there's no lookback to it; the Type 1 is a pinky swear.

In practice, if you're careful about how you do your Type 1, the Type 2 is almost as trivial. Your HR/bizops practice is much more likely to screw up and cause exceptions than anything you do in IT or engineering.

Re: Apple Private Cloud Compute SoC 3 audit reports

#33
post #16

Earlier quoted context omitted.

Last I chatted with some friends who were going through their first SOC2, they quoted a much lower number.

The details people gloss over when throwing SOC 2 or whatever other audit costs around are the complexity of the system being audited, the chosen criteria to audit (AICPA defines 5 families of criteria... Security is one, but you can optionally add Processing Integrity, Confidentiality, etc etc) and the reputation of the auditor. A security-only audit for a small company with a narrow product focus can indeed be very…

Unless you have a very good reason (I compare notes with people at dozens of firms and have never heard one), the only criteria you ever want to get SOC2'd on is Security.

My experience is the opposite of yours: having a security SOC2 ends the vendorsec process it any enterprise buyer, and enterprise buyers virtually never read anything in the SOC2 other than a glance at the exceptions. A very large, very security-intensive vendor we have all heard of told me a story about a vendor they had that gave them several years of repeated Type 1 reports. Went fine.

Re: Apple Private Cloud Compute SoC 3 audit reports

#34
post #6

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they pic…

> SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1).

Even with an external audit - think of how many projects and repositories and servers and libraries and legacy systems Apple, a 50-year-old company with 166,000 employees, could have.

Then think about how much inspection is involved in a $50,000 audit. I doubt you get more than one inspector working full time for a year. In which case they've got 45 seconds of to audit each employee's entire work output. And places like EY will bill some people out at $700/hour, so it could be an order of magnitude less than that.

So this isn't some fine-toothed-comb forensic investigation or adversarial penetration test.

Re: Apple Private Cloud Compute SoC 3 audit reports

#35

Earlier quoted context omitted.

Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they pic…

> SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Even with an external audit - think of how many projects and repositories and servers and libraries and legacy systems Apple, a 50-year-old company with 166,000 employees, could have. Then think about how much inspection is involved in a $50,000 audit. I doubt you get more than one inspector working full time fo…

A $50k audit is going to be team of 2 CPAs collecting evidence for 2 weeks.

Re: Apple Private Cloud Compute SoC 3 audit reports

#36
post #6

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

(Specifically: the SOC3 is a public report; the SOC2 report generally isn't supposed to be handed out except to named clients under contract. You pay extra to get the auditors to give you a report you can just stick on a website.)

Re: Apple Private Cloud Compute SoC 3 audit reports

#37

Earlier quoted context omitted.

I think companies like Deel showed that SOC2 is more show than anything else. For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

Hasn't Deel been run out of business though? IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.

I think both of you meant “Delve”, not “Deel”. Deel is a pretty successful HR startup that’s still growing at a good rate and AFAIK free of major scandals.

Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.

Re: Apple Private Cloud Compute SoC 3 audit reports

#38

Earlier quoted context omitted.

Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they pic…

I think companies like Deel showed that SOC2 is more show than anything else. For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

Delve. Not Deel. Very different startups.

Re: Apple Private Cloud Compute SoC 3 audit reports

#39

Earlier quoted context omitted.

Can you name the names of SOC auditors that are rubber stamping? Or point me to some public critiques within the industry?

Wasn’t that YC startup Delve doing exactly this? https://www.iansresearch.com/resources/all-blogs/post/securi...

That I'm familiar with. Is it part of a trend or just one bad apple?
Post reply on HN