Skip to content

Comment on Apple Private Cloud Compute SoC 3 audit reportsparent

Comments

Citation needed. This is not my experience at all, after participating in such efforts at three different companies.

I wouldn't put it the way they did but they're directionally sane about this. I would worry a lot more about someone repping their SOC2 as important or meaningful than I would worry about someone who was cynical about SOC2.

(I don't mean Apple; Apple spends more on security than almost any firm in the world.)

https://fly.io/blog/soc2-the-screenshots-will-continue-until...

My experience with pen tests that you put above or on par with SOC2 Type 2 security mirrors the discussion here. It all comes down to the reputation of the firm doing the testing.

I'll just cite my 30 years in IT/InfoSec. Believe it or not, I really don't give a damn. It's common knowledge int he field regardless of what your experience is.

Can you name the names of SOC auditors that are rubber stamping?

Or point me to some public critiques within the industry?

Wasn’t that YC startup Delve doing exactly this?

https://www.iansresearch.com/resources/all-blogs/post/securi...

That I'm familiar with. Is it part of a trend or just one bad apple?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.