Getting through a SOC 2 audit with your nerves intact

Getting through a SOC 2 audit with your nerves intact

Once a company reaches a certain size, their customers might start asking for proof that it has good security and data habits. They want to know if there’s a business continuity plan in place in case disaster strikes. For many companies, formalizing this proof means submitting to an auditing process known as SOC 2. If you’re a developer at one of these companies, particularly if you provide or use SaaS applications, you’ll end up having to implement the controls these audits require.

On this sponsored episode of the podcast, Ben and Ryan talk with James Ciesielski, CTO and co-founder, and Megan Dean, information security and risk compliance manager, both of Rewind. We talk about how you can prep for and successfully get through a SOC 2 audit, how backing up your SaaS data can provide business continuity, and the benefits of establishing a relationship with your auditor.

A SOC 2 report shows your customers the level of security controls that you have in place. It’s based on the auditing standards set by the American Institute of Certified Public Accountants. You tell them what controls you have in place and they verify it. Once a company starts attracting enterprise-level customers, a SOC 2 becomes a must-have.

Companies perform SOC 2 audits using a variety of tools: sometimes it’s purpose-built SaaS tools; sometimes it’s a cascade of spreadsheets. Ultimately, what’s important is providing an audit trail for your controls, a record that proves that your security does what you claim it does. Trust, but verify.

The process can grow complicated, as companies can have 100 to as many as 300 SaaS applications running in their business. That’s a lot of important business data on someone else’s cloud. Many of these SaaS applications operate data on the shared responsibility model: they ensure the service is available and secure, and you ensure that your data is accurate and secure.

A key part of these security controls is disaster recovery and business continuity. Imagine that you’re using a SaaS application to track your audit process. What happens if a disgruntled employee wrecks your data, or your cat walks over your keyboard, hitting just the right combination of keys to delete something important? Or what if you unwittingly get flagged on a T&C violation and get deplatformed? Your audit trail could be lost if you haven’t upheld your end of the shared responsibility model and backed up your data.

Ultimately, having experts who know the process can help. Your auditor, too, can be a resource, so get to know them. They want you to succeed. They want to help you improve your audit process because it makes their lives easier.

See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Jaksot(906)

Spy vs spy at scale

Spy vs spy at scale

Ryan welcomes Anthony Vinci, former senior intelligence officer and author of The Fourth Intelligence Revolution, to explore AI’s evolving role in intelligence in places like translation and image ana...

27 Tammi 35min

AI can 10x developers...in creating tech debt

AI can 10x developers...in creating tech debt

Ryan sits down with Michael Parker, VP of Engineering at TurinTech to discuss the newest kind of tech debt—AI-generated tech debt. They dive into the uneven productivity results of AI tools, how tech ...

23 Tammi 29min

Don’t let your backend write checks your frontend can’t cache

Don’t let your backend write checks your frontend can’t cache

Ryan welcomes Prakash Chandran, CEO and co-founder of Xano, to the show to discuss the intricate relationship between frontend and backend development, the potential challenges that universal frontend...

20 Tammi 30min

How AWS re:Invented the cloud

How AWS re:Invented the cloud

From the floor at AWS re:Invent, Ryan is joined by AWS Senior Principal Engineer David Yanacek to chat about all things AWS, from the truth behind AWS’s Black Friday origin mythos to the development o...

16 Tammi 28min

Transforming enterprise workflows: How IBM is unlocking AI's potential

Transforming enterprise workflows: How IBM is unlocking AI's potential

In this episode of Leaders of Code, Stack Overflow Chief of Product and Technology Jody Bailey chats with Matt Lyteson, CIO of Technology Platform Transformation at IBM, about the processes and challe...

15 Tammi 41min

Vibe code anything in a Hanselminute

Vibe code anything in a Hanselminute

Ryan welcomes back the mighty Scott Hanselman, VP of Developer Community at Microsoft, for a crossover episode about all things vibe coding. They cover the ways it can really improve the software deve...

13 Tammi 35min

Every ecommerce hero needs a Sidekick

Every ecommerce hero needs a Sidekick

Ryan is joined by Vanessa Lee, VP of Product at Shopify, to discuss how AI is a tech renaissance and how these new technologies are affecting the ecommerce world. They cover the development of Sidekic...

9 Tammi 29min

You need quality engineers to turn AI into ROI

You need quality engineers to turn AI into ROI

SPONSORED BY MONGODBPete Johnson, Field CTO, Artificial Intelligence at MongoDB, joins the podcast to talk about a recent OpenAI paper on the impact that AI will have on jobs and overall GDP. Pete, wh...

7 Tammi 29min

Suosittua kategoriassa Liike-elämä ja talous

sijotuskasti
psykopodiaa-podcast
rss-rahapodi
mimmit-sijoittaa
ostan-asuntoja-podcast
herrasmieshakkerit
rss-h-asselmoilanen
rss-neuvottelija-sami-miettinen
rahapuhetta
io-techin-tekniikkapodcast
oppimisen-psykologia
pomojen-suusta
rss-rahamania
rss-lahtijat
rss-bisnesta-bebeja
rss-laakispodi
rss-startup-ministerio
rss-sisalto-kuntoon
rss-rahataito-podcast
rss-oppimisen-etua