Readit News logoReadit News
ram18 commented on The SOC2 Starting Seven (2020)   latacora.micro.blog/... · Posted by u/Ballu
Hallucinaut · 5 years ago
Having been spammed by them out of the blue, a couple of times already this year, my feeling is that like most businesses, I already know what changes I'd have to make to improve.

Paying someone to give me a list of problems isn't at all useful until we have nothing else to do. Appreciate there may be others out there without the same understanding of Infosec, but frankly that's a greater risk to companies without those resources.

ram18 · 5 years ago
This is a great point, getting a checklist of your problems to fix and a way to project manage certain pieces of the process isn’t solving the real problem. Also many of these tools don’t give you great insight into where you stand going into your audit or in between your annual audits.

A newer tool that I’ve heard great feedback on is Drata. They’re more focused on automation and continuous evidence collection.

ram18 commented on The SOC2 Starting Seven (2020)   latacora.micro.blog/... · Posted by u/Ballu
travisluis · 5 years ago
Any views on Vanta vs Tugboat Logic vs Laika? I’m trying to choose among them am leaning towards Tugboat Logic. It’s policies seem more thoroughly drafted and they let you test drive the platform, which none of the others allow. Vanta has more integrations but doesn’t currently do Jamf from what I can tell.
ram18 · 5 years ago
I think this depends on your internal resources. TugBoat and Laika are more project management tools, a great question to ask is if you integrate with my Infrastructure, how many controls within the SOC2 framework are you actually automating. Vanta has been around awhile but I’ve heard mixed feedback from auditors as well as companies that use the tool. I’d recommend looking into Drata, they have the most automation and great auditor relationships. Happy to provide an intro to one of their audit partners that I used to work with to learn more from their perspective.

u/ram18

KarmaCake day1January 18, 2021View Original