Earlier quoted context omitted.
Hasn't Deel been run out of business though? IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.
I think both of you meant “Delve”, not “Deel”. Deel is a pretty successful HR startup that’s still growing at a good rate and AFAIK free of major scandals. Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.
Apple Private Cloud Compute SoC 3 audit reports
41–50 of 61 posts
Re: Apple Private Cloud Compute SoC 3 audit reports
#42the page keeps 301ing to the home page for me - could be a region issue https://archive.ph/JYC9B
Re: Apple Private Cloud Compute SoC 3 audit reports
#43Re: Apple Private Cloud Compute SoC 3 audit reports
#44Earlier quoted context omitted.
Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they pic…
Literally any firm can get a SOC2 Type 1, because there's no lookback to it; the Type 1 is a pinky swear. In practice, if you're careful about how you do your Type 1, the Type 2 is almost as trivial. Your HR/bizops practice is much more likely to screw up and cause exceptions than anything you do in IT or engineering.
Re: Apple Private Cloud Compute SoC 3 audit reports
#45Earlier quoted context omitted.
Literally any firm can get a SOC2 Type 1, because there's no lookback to it; the Type 1 is a pinky swear. In practice, if you're careful about how you do your Type 1, the Type 2 is almost as trivial. Your HR/bizops practice is much more likely to screw up and cause exceptions than anything you do in IT or engineering.
From my 8 years of working SOC2 Type 2 audits done by PwC for a large PaaS Cloud with a worldwide presence (not the big 3) saying Type 2 is almost as trivial as type 1 is absolutely false. This might be true for someone running their own low volume SaaS in one region but for someone the size of Apple they are investing a lot of resource to stay on top of the controls, especially patching and permissions. If you've in…
I wrote an article about this, and I think it's the Correct advice for virtually every startup thinking about SOC2:
https://fly.io/blog/soc2-the-screenshots-will-continue-until...
A few years before that, I wrote an article about what we learned from the consulting practice we ran building SOC2-supporting security programs for startups:
https://www.latacora.com/blog/2020/03/12/soc2-starting-seven...
I've had the experience, many times, of offering this advice in some forum and having someone try to rebut it, claiming that SOC2 is difficult, or that real customers will pick a SOC2 attestation apart with a fine-toothed comb looking for shortcuts you took, or that they built their whole security practice around SOC2. I can go all 12 rounds with someone on any of those points, but I think you can get most of my take from those two posts.
Re: Apple Private Cloud Compute SoC 3 audit reports
#46Earlier quoted context omitted.
Citation needed. This is not my experience at all, after participating in such efforts at three different companies.
I wouldn't put it the way they did but they're directionally sane about this. I would worry a lot more about someone repping their SOC2 as important or meaningful than I would worry about someone who was cynical about SOC2. (I don't mean Apple; Apple spends more on security than almost any firm in the world.) https://fly.io/blog/soc2-the-screenshots-will-continue-until...
Re: Apple Private Cloud Compute SoC 3 audit reports
#47Earlier quoted context omitted.
From my 8 years of working SOC2 Type 2 audits done by PwC for a large PaaS Cloud with a worldwide presence (not the big 3) saying Type 2 is almost as trivial as type 1 is absolutely false. This might be true for someone running their own low volume SaaS in one region but for someone the size of Apple they are investing a lot of resource to stay on top of the controls, especially patching and permissions. If you've in…
I'm not going to, like, whip out my resume here, but I am going to confidently assert that if you structure your Type 1 carefully, you can trivialize your Type 2, and as someone currently operating a globally deployed public cloud I can tell you right now that SOC2 doesn't really touch on anything interesting in our engineering. I wrote an article about this, and I think it's the Correct advice for virtually every st…
Re: Apple Private Cloud Compute SoC 3 audit reports
#48For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting
> "look I can afford 50k" Oh no. Looks like you never went through SOC2. 1. No, it does not require 50k, an auditor can cost way less (10k? maybe even less). 2. But the process of preparing for the audit will take a lot of work securing your systems (and increasing reliability and privacy as well), as long as you take it seriously. Of course you can lie to the auditor, but it's up on you. And auditor -- they might lo…
Re: Apple Private Cloud Compute SoC 3 audit reports
#49Earlier quoted context omitted.
I'm not going to, like, whip out my resume here, but I am going to confidently assert that if you structure your Type 1 carefully, you can trivialize your Type 2, and as someone currently operating a globally deployed public cloud I can tell you right now that SOC2 doesn't really touch on anything interesting in our engineering. I wrote an article about this, and I think it's the Correct advice for virtually every st…
It doesn't look like fly.io publicly disclose who there auditor is so it is hard to judge that specific part of your experience. I'm not disagreeing with your perspective on startups. I'm saying that type 2 gets much harder when you are large. non-homogenous and lack sufficient automation and monitoring.
Re: Apple Private Cloud Compute SoC 3 audit reports
#50Earlier quoted context omitted.
Hasn't Deel been run out of business though? IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.
I think both of you meant “Delve”, not “Deel”. Deel is a pretty successful HR startup that’s still growing at a good rate and AFAIK free of major scandals. Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.