can someone correct me - so apple is using servers that are running a closed down version of iOS on what I would assume is apple silicone, probably excess chips or older chips for the iCloud Private Cloud ?
Apple Private Cloud Compute SoC 3 audit reports
51–60 of 61 posts
Re: Apple Private Cloud Compute SoC 3 audit reports
#52macOS Security Compliance Project
Re: Apple Private Cloud Compute SoC 3 audit reports
#53Out of that whole report I got this gem, macOS Security Compliance Project https://pages.nist.gov/macos_security/
Re: Apple Private Cloud Compute SoC 3 audit reports
#54Re: Apple Private Cloud Compute SoC 3 audit reports
#55Earlier quoted context omitted.
Hasn't Deel been run out of business though? IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.
I think both of you meant “Delve”, not “Deel”. Deel is a pretty successful HR startup that’s still growing at a good rate and AFAIK free of major scandals. Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.
Deel is the ycombinator startup that allegedly spied on their competition while Delve is the ycombinator startup that allegedly fakes SOC2 compliance.
Re: Apple Private Cloud Compute SoC 3 audit reports
#56Earlier quoted context omitted.
I think companies like Deel showed that SOC2 is more show than anything else. For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...
Delve. Not Deel. Very different startups.
Deel is the ycombinator startup that allegedly spied on their competition while Delve is the ycombinator startup that allegedly fakes SOC2 compliance.
Re: Apple Private Cloud Compute SoC 3 audit reports
#57Earlier quoted context omitted.
> "look I can afford 50k" Oh no. Looks like you never went through SOC2. 1. No, it does not require 50k, an auditor can cost way less (10k? maybe even less). 2. But the process of preparing for the audit will take a lot of work securing your systems (and increasing reliability and privacy as well), as long as you take it seriously. Of course you can lie to the auditor, but it's up on you. And auditor -- they might lo…
I'm scared of companies where SOC2 auditors are driving their security improvements. It's a bit like letting my toddler drive how I stock my pantry: surely by the end the pantry will be more full, but not really in the way I want.
PS: regarding "most of them" -- if you're one-person shop, you'll likely fail a control that requires your board of directors to be independent of company management (i.e. having directors that do not work for the company). That's OK, but will be reported on your SOC2 report.
Re: Apple Private Cloud Compute SoC 3 audit reports
#58I have absolutely 0 reasons to believe Apple Private Cloud is not a data extraction mechanism for the gullible. Unless I can manually inspect the source, or at least run the binaries on my own hardware that I can firewall and inspect the network traffic, I'm absolutely confident Apple steals all the data to build better ad targeting models, or to sell to the highest bidder.
Re: Apple Private Cloud Compute SoC 3 audit reports
#59Earlier quoted context omitted.
From my 8 years of working SOC2 Type 2 audits done by PwC for a large PaaS Cloud with a worldwide presence (not the big 3) saying Type 2 is almost as trivial as type 1 is absolutely false. This might be true for someone running their own low volume SaaS in one region but for someone the size of Apple they are investing a lot of resource to stay on top of the controls, especially patching and permissions. If you've in…
I'm not going to, like, whip out my resume here, but I am going to confidently assert that if you structure your Type 1 carefully, you can trivialize your Type 2, and as someone currently operating a globally deployed public cloud I can tell you right now that SOC2 doesn't really touch on anything interesting in our engineering. I wrote an article about this, and I think it's the Correct advice for virtually every st…
Either way, go read his links.
Re: Apple Private Cloud Compute SoC 3 audit reports
#60Earlier quoted context omitted.
I'm scared of companies where SOC2 auditors are driving their security improvements. It's a bit like letting my toddler drive how I stock my pantry: surely by the end the pantry will be more full, but not really in the way I want.
It's not auditors, it's the compliance requirements and controls. You should not even reach to an auditor before fixing the controls (most of them, the ones you lack auditor must flag, as sometimes it's not feasible to fix most of the controls). I'd say going through an audit is easy, but preparing for the audit is hard. PS: regarding "most of them" -- if you're one-person shop, you'll likely fail a control that requ…