Getting through a SOC 2 audit with your nerves intact

Getting through a SOC 2 audit with your nerves intact

Once a company reaches a certain size, their customers might start asking for proof that it has good security and data habits. They want to know if there’s a business continuity plan in place in case disaster strikes. For many companies, formalizing this proof means submitting to an auditing process known as SOC 2. If you’re a developer at one of these companies, particularly if you provide or use SaaS applications, you’ll end up having to implement the controls these audits require.

On this sponsored episode of the podcast, Ben and Ryan talk with James Ciesielski, CTO and co-founder, and Megan Dean, information security and risk compliance manager, both of Rewind. We talk about how you can prep for and successfully get through a SOC 2 audit, how backing up your SaaS data can provide business continuity, and the benefits of establishing a relationship with your auditor.

A SOC 2 report shows your customers the level of security controls that you have in place. It’s based on the auditing standards set by the American Institute of Certified Public Accountants. You tell them what controls you have in place and they verify it. Once a company starts attracting enterprise-level customers, a SOC 2 becomes a must-have.

Companies perform SOC 2 audits using a variety of tools: sometimes it’s purpose-built SaaS tools; sometimes it’s a cascade of spreadsheets. Ultimately, what’s important is providing an audit trail for your controls, a record that proves that your security does what you claim it does. Trust, but verify.

The process can grow complicated, as companies can have 100 to as many as 300 SaaS applications running in their business. That’s a lot of important business data on someone else’s cloud. Many of these SaaS applications operate data on the shared responsibility model: they ensure the service is available and secure, and you ensure that your data is accurate and secure.

A key part of these security controls is disaster recovery and business continuity. Imagine that you’re using a SaaS application to track your audit process. What happens if a disgruntled employee wrecks your data, or your cat walks over your keyboard, hitting just the right combination of keys to delete something important? Or what if you unwittingly get flagged on a T&C violation and get deplatformed? Your audit trail could be lost if you haven’t upheld your end of the shared responsibility model and backed up your data.

Ultimately, having experts who know the process can help. Your auditor, too, can be a resource, so get to know them. They want you to succeed. They want to help you improve your audit process because it makes their lives easier.

See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Avsnitt(889)

Treating your agents like microservices

Treating your agents like microservices

Ryan is joined by Outshift by Cisco’s VP of Engineering Guillaume De Saint Marc to discuss the future of multi-agent architectures as microservices, the challenges and limitations of the infrastructure for these multi-agent systems, and the importance of communication protocols and interoperability in order to build decentralized and scalable architectures. Episode notes:Outshift is Cisco’s tech incubator that pursues emerging technologies like agentic AI, quantum computing, and next-gen infrastructure. Learn more about multi-agent architecture at their open-source collective AGNTCY.Connect with Guillaume on Linkedin. Today we’re shouting out a Socratic badge winner, Avraam Mavridis, who won the badge for asking well received questions on 100 separate days. See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

5 Dec 35min

Abstraction, but for robots

Abstraction, but for robots

Ryan welcomes Simone Kalmakis, VP of Engineering at Viam, to dive into how her team is bridging the gap between software and robotics, the importance of abstraction layers in making robotics more accessible, and the real-world applications of robotics from lobster traps to industrial sanding robots.Episode notes:Viam is a robotics platform that brings modern software development tools into hardware applications. Connect with Simone on Linkedin. This week’s shoutout goes to Lifejacket winner Sergey Kalinichenko for their answer to How does this K&R code for reading an int work?.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

2 Dec 24min

Lightning-as-a-service for agriculture

Lightning-as-a-service for agriculture

Darryl Lyons, co-founder and Chief Rainmaker at Rainstick, joins the show to dive into advancements in AgTech and how Rainstick is using bioelectricity to enhance agricultural productivity. They discuss how Rainstick mimics natural thunderstorms to create electric fields and frequencies that promote plant growth, challenges and breakthroughs in their research, and their participation in the AWS Compute for Climate Fellowship.Episode notes:Rainstick uses electricity to mimic the natural effects of lightning to grow crops bigger, faster, and more sustainably. Want to learn more about the Compute for Climate program? Check our podcast with Lisbeth Kaufman, Head of Climate Tech at AWS.Ryan wrote about how software is being applied to agriculture a few years ago. Connect with Darryl on LinkedIn.Congrats to Lifeboat badge winner WestCoastProjects for their answer to Test accuracy is greater than train accuracy what to do?.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

28 Nov 21min

You’re probably underutilizing your GPUs

You’re probably underutilizing your GPUs

Ryan is joined by Jared Quincy Davis, CEO and co-founder of Mithril, to explore the importance of efficient resource allocation and GPU utilization in AI, the myth and misconceptions of the GPU shortage, and how the economics of GPU will change with new scheduling and utilization strategies. Episode notes:Mithril’s omnicloud platform aggregates and orchestrates multi-cloud GPUs, CPUs, and storage so you can access your infrastructure through a single platform.Connect with Jared on Twitter and LinkedIn.Shoutout to user Razzi Abuissa for winning a Populist badge on their answer to How to find last merge in git?.TRANSCRIPTSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

25 Nov 26min

Only you can stop AI database drops

Only you can stop AI database drops

Ryan is joined by David Hsu, CEO and founder of Retool, to explore how AI is transforming the role of a software developer into a software architect, the increasing accessibility of coding for non-engineers, and the importance of placing guardrails and higher-level programming primitives on AI coding assistants.Episode notes:Retool is an enterprise AI AppGen platform for internal software development, allowing you to create apps, agents, and workflows with any LLM, datasource, or API.David Hsu previously joined the podcast to complain about maintaining internal tools. Connect with David on Twitter.Today’s shoutout is for user Waseem Wisa, who won a Populist badge on their answer to Sass compiler throws 'undefined mixin' error when mixins are kept in seperate folder.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

21 Nov 32min

How to create agents that people actually want to use

How to create agents that people actually want to use

Ryan welcomes Assaf Elovic, head of AI at monday.com, to discuss creating AI tools that users will actually adopt, how they created their Monday Sidekick agent with the user experience in mind, and the opportunities that AI creates for better productivity and more efficiency.Episode notes:monday.com is a work management platform that allows you to plan and execute work across departments with a unified, AI-first product suite.Connect with Assaf on LinkedIn and Twitter. Congrats to Populist badge winner Vilx-, who received the badge for their answer to How do you provide a default type for generics?.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

18 Nov 27min

The fastest agent in the race has the best evals

The fastest agent in the race has the best evals

Ryan welcomes Benjamin Klieger, lead engineer at Groq, to explore the infrastructure behind AI agents, how you can turn a one-minute agent into a ten-second agent, and how they used fast inference and effective evals to build their efficient and reliable Compound agent. Episode notes: Groq delivers fast, low-cost inference using their custom-designed LPU, the first chip built for inference. Check out their agent, Compound, which can search the web and run code.Connect with Benjamin on LinkedIn and X. Congrats to user Bart Kiers for winning a Stellar Answer badge on their response to Regular expression to match a line that doesn't contain a word. See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

14 Nov 32min

One thing enterprise AI projects need to succeed? Community.

One thing enterprise AI projects need to succeed? Community.

In this episode of Leaders of Code, Stack Overflow CEO Prashanth Chandrasekar chats with Ramprasad Rai, VP of Platform Engineering at JPMorgan Chase & Co., about the unique challenges of implementing AI in an enterprise environment. They discuss how organizations can balance AI-driven productivity with strict compliance and security requirements by leveraging a community-driven knowledge system that grounds probabilistic AI tools in internal, trusted expertise.The discussion also:Explores why AI models often hallucinate in enterprise environments due to a lack of internal context. Highlights how Stack Overflow’s structured Q&A data provides ideal fine-tuning material for the next generation of AI models.NotesConnect with Ramprasad Rai on LinkedIn.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

13 Nov 23min

Populärt inom Business & ekonomi

badfluence
framgangspodden
varvet
rss-jossan-nina
rss-borsens-finest
uppgang-och-fall
rss-svart-marknad
lastbilspodden
fill-or-kill
avanzapodden
rss-kort-lang-analyspodden-fran-di
affarsvarlden
rss-dagen-med-di
24fragor
borsmorgon
rss-inga-dumma-fragor-om-pengar
kapitalet-en-podd-om-ekonomi
bathina-en-podcast
market-makers
svd-tech-brief