Getting through a SOC 2 audit with your nerves intact

Getting through a SOC 2 audit with your nerves intact

Once a company reaches a certain size, their customers might start asking for proof that it has good security and data habits. They want to know if there’s a business continuity plan in place in case disaster strikes. For many companies, formalizing this proof means submitting to an auditing process known as SOC 2. If you’re a developer at one of these companies, particularly if you provide or use SaaS applications, you’ll end up having to implement the controls these audits require.

On this sponsored episode of the podcast, Ben and Ryan talk with James Ciesielski, CTO and co-founder, and Megan Dean, information security and risk compliance manager, both of Rewind. We talk about how you can prep for and successfully get through a SOC 2 audit, how backing up your SaaS data can provide business continuity, and the benefits of establishing a relationship with your auditor.

A SOC 2 report shows your customers the level of security controls that you have in place. It’s based on the auditing standards set by the American Institute of Certified Public Accountants. You tell them what controls you have in place and they verify it. Once a company starts attracting enterprise-level customers, a SOC 2 becomes a must-have.

Companies perform SOC 2 audits using a variety of tools: sometimes it’s purpose-built SaaS tools; sometimes it’s a cascade of spreadsheets. Ultimately, what’s important is providing an audit trail for your controls, a record that proves that your security does what you claim it does. Trust, but verify.

The process can grow complicated, as companies can have 100 to as many as 300 SaaS applications running in their business. That’s a lot of important business data on someone else’s cloud. Many of these SaaS applications operate data on the shared responsibility model: they ensure the service is available and secure, and you ensure that your data is accurate and secure.

A key part of these security controls is disaster recovery and business continuity. Imagine that you’re using a SaaS application to track your audit process. What happens if a disgruntled employee wrecks your data, or your cat walks over your keyboard, hitting just the right combination of keys to delete something important? Or what if you unwittingly get flagged on a T&C violation and get deplatformed? Your audit trail could be lost if you haven’t upheld your end of the shared responsibility model and backed up your data.

Ultimately, having experts who know the process can help. Your auditor, too, can be a resource, so get to know them. They want you to succeed. They want to help you improve your audit process because it makes their lives easier.

See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Episoder(906)

Spy vs spy at scale

Spy vs spy at scale

Ryan welcomes Anthony Vinci, former senior intelligence officer and author of The Fourth Intelligence Revolution, to explore AI’s evolving role in intelligence in places like translation and image ana...

27 Jan 35min

AI can 10x developers...in creating tech debt

AI can 10x developers...in creating tech debt

Ryan sits down with Michael Parker, VP of Engineering at TurinTech to discuss the newest kind of tech debt—AI-generated tech debt. They dive into the uneven productivity results of AI tools, how tech ...

23 Jan 29min

Don’t let your backend write checks your frontend can’t cache

Don’t let your backend write checks your frontend can’t cache

Ryan welcomes Prakash Chandran, CEO and co-founder of Xano, to the show to discuss the intricate relationship between frontend and backend development, the potential challenges that universal frontend...

20 Jan 30min

How AWS re:Invented the cloud

How AWS re:Invented the cloud

From the floor at AWS re:Invent, Ryan is joined by AWS Senior Principal Engineer David Yanacek to chat about all things AWS, from the truth behind AWS’s Black Friday origin mythos to the development o...

16 Jan 28min

Transforming enterprise workflows: How IBM is unlocking AI's potential

Transforming enterprise workflows: How IBM is unlocking AI's potential

In this episode of Leaders of Code, Stack Overflow Chief of Product and Technology Jody Bailey chats with Matt Lyteson, CIO of Technology Platform Transformation at IBM, about the processes and challe...

15 Jan 41min

Vibe code anything in a Hanselminute

Vibe code anything in a Hanselminute

Ryan welcomes back the mighty Scott Hanselman, VP of Developer Community at Microsoft, for a crossover episode about all things vibe coding. They cover the ways it can really improve the software deve...

13 Jan 35min

Every ecommerce hero needs a Sidekick

Every ecommerce hero needs a Sidekick

Ryan is joined by Vanessa Lee, VP of Product at Shopify, to discuss how AI is a tech renaissance and how these new technologies are affecting the ecommerce world. They cover the development of Sidekic...

9 Jan 29min

You need quality engineers to turn AI into ROI

You need quality engineers to turn AI into ROI

SPONSORED BY MONGODBPete Johnson, Field CTO, Artificial Intelligence at MongoDB, joins the podcast to talk about a recent OpenAI paper on the impact that AI will have on jobs and overall GDP. Pete, wh...

7 Jan 29min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
lydartikler-fra-aftenposten
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
pengepodden-2
utbytte
tid-er-penger-en-podcast-med-peter-warren
pengesnakk
livet-pa-veien-med-jan-erik-larssen
stormkast-med-valebrokk-stordalen
okonomiamatorene
morgenkaffen-med-finansavisen
lederpodden
finansredaksjonen
rss-markedspuls-2
flypodden
rss-finansforum-2
rss-kantsonen