> SOC 2 stands for “Systems and Organizations Controls 2” and is sometimes referred to as SOC II. It is a framework designed to help software vendors and other companies demonstrate the security controls they use to protect customer data in the cloud
A long time ago I was talking with a Google security pro, and he described "SOC2: not the paper it is printed on" :)
When a company makes a press release about SOC2 compliant security credentialing, I generally think the company went with the easiest thing possible under the sun, and they can't meet rigorous security control requirements.
There are certain customers that won't buy your product unless you are SOC2 compliant. So for someone who already does security very well, it still can be a must-do.
I cannot in good conscience associate "someone (an organization) doing security very well" with SOC2.
This may be an example of credentialism that doesn't actually equate to value.
Because I am in a specific industry, I'd prefer to see a Fedramp/NIST 800-53 SSP, their last vulnerability scan, the last penetration test, the last independent code evaluation, and all outstanding POAMs and RBDs. That tells me they are hitting all the basics and have reasonable measures in place.
> SOC2 isn't really about security in a "cyber" sense
SOC2 according to AICPA is, and this could be highly "cyber" if the organization self-asserts a number of cyber security controls.
> Controls affect user entities
> SAE No. 18, Attestation Standards: Clarification and Recodification, which includes AT-C section 105, Concepts Common to All Attestation Engagements, and AT-C section 205, Examination Engagements. AICPA Guide, SOC 2® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy. TSP section 100, 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (AICPA, 2017 Trust Services Criteria)
> Description of service organization’s system. Written assertion by service organization management regarding the description of the service organization’s system and the suitability of the design and the operating effectiveness of the controls to provide reasonable assurance that the service organization’s service commitments and system requirements were achieved based on the applicable trust services criteria. Service auditor’s report that contains an opinion on about whether the description is presented in accordance with the description criteria and the controls stated in the description were suitably designed and operating effectively to provide reasonable assurance that the service organization’s service commitments and system requirements were achieved based on the applicable trust services criteria. In a type 2 report, a description of the service auditor’s tests of controls and the results of the tests
I'm just giving my perspective as someone who's gone through it recently.
It was a lot more about setting up policies and practices than it was practical digital security. More about documents describing security plans than about specific implementations and checking that they work and are effective.
8 comments
[ 3.2 ms ] story [ 37.8 ms ] threadFrom: https://www.strongdm.com/soc2/compliance
> SOC 2 stands for “Systems and Organizations Controls 2” and is sometimes referred to as SOC II. It is a framework designed to help software vendors and other companies demonstrate the security controls they use to protect customer data in the cloud
When a company makes a press release about SOC2 compliant security credentialing, I generally think the company went with the easiest thing possible under the sun, and they can't meet rigorous security control requirements.
This may be an example of credentialism that doesn't actually equate to value.
Because I am in a specific industry, I'd prefer to see a Fedramp/NIST 800-53 SSP, their last vulnerability scan, the last penetration test, the last independent code evaluation, and all outstanding POAMs and RBDs. That tells me they are hitting all the basics and have reasonable measures in place.
You literally do not need a pen test to pass SOC2 Type 1, for example.
SOC2 according to AICPA is, and this could be highly "cyber" if the organization self-asserts a number of cyber security controls.
> Controls affect user entities
> SAE No. 18, Attestation Standards: Clarification and Recodification, which includes AT-C section 105, Concepts Common to All Attestation Engagements, and AT-C section 205, Examination Engagements. AICPA Guide, SOC 2® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy. TSP section 100, 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (AICPA, 2017 Trust Services Criteria)
> Description of service organization’s system. Written assertion by service organization management regarding the description of the service organization’s system and the suitability of the design and the operating effectiveness of the controls to provide reasonable assurance that the service organization’s service commitments and system requirements were achieved based on the applicable trust services criteria. Service auditor’s report that contains an opinion on about whether the description is presented in accordance with the description criteria and the controls stated in the description were suitably designed and operating effectively to provide reasonable assurance that the service organization’s service commitments and system requirements were achieved based on the applicable trust services criteria. In a type 2 report, a description of the service auditor’s tests of controls and the results of the tests
from https://us.aicpa.org/interestareas/frc/assuranceadvisoryserv...
It was a lot more about setting up policies and practices than it was practical digital security. More about documents describing security plans than about specific implementations and checking that they work and are effective.