🔧 Programmierung 🕛 vor 2 Jahren 6 Min Lesezeit SECURITY-FEED
0

Software: Our SOC 2 journey

↗ Quelle (dev.to)
🗣️ Stimme:

SOC stands for System and Organization Controls. It is a standard when dealing with customer data. SOC is a means of verifying a set of standardized controls that are defined by the American Institute of Certified Public Accountants (AICPA). SOC is used to validate the controls that a company utilizes internally to their clients. You will see how automating and exposing this information would benefit a company.



For SOC 2, the main components to being successful and staying successful are threefold. One, a good centralized documentation center (a place to store all of your reviews, and controls). Two, a way to automatically update and verify controls. Three, a good auditor that can work with you and make sure that you are successful. SOC 2 is something that you have to continuously do and publicize so that your clients can see that you are compliant.



At



During the process of acquiring our SOC 2 certification we established a security team that meets monthly for risk assessments, quarterly for access reviews and annually for DR testing. Having good tools in our employ did make this process straightforward. For example our access reviews, we utilize a tool called StrongDM for server access, Kubernetes access, and others. We have a centralized place in which to look for specific access and who has it. Tools do help make getting SOC 2 certification simpler especially if you have a single pane of glass for your auditors to look at.



When we set out to get our SOC 2 certification it was because we knew it would be a great way to announce to our clients that we are consistently following a set of standardized controls. To say that we practice safe means of handling data of all types internally and externally. SOC 2 can help reduce some of the apprehension that most security teams have about companies that access any type of data. From our perspective any tool that we want to utilize has to at least be SOC 2 compliant.



If you want to check out our live security report, you can click on this link: https://app.drata.com/security-report/42b97aed-d394-4c1d-b749-4fe65ab025b9/19559124-3354-46f7-bbd2-1313d773fb36?region=NA

Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
6 Quellen
CVE-2022-44255 | TOTOLINK LR350 9.3.5u.6369_B20220309 buffer overflow (EUVD-2022-47204)
2 Quellen
CVE-2026-68426 | Linux Kernel up to 6.18.41/7.1.5/7.2-rc3 xfrm validate_xmit_skb_list use after free (Nessus ID 346426)
1 Quelle
Windows 11 Probleme mit gültiger Domänenanmeldung nach September-Update [Workaround]
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Software: Our SOC 2 journey

Thematisch verwandte Begriffe: Software, journey · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...