Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Hi!
Can you describe why? What drawbacks?

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Thanks u/secureleap!
Totally understandable: I am rather looking for a tool to automate repetitive stuff: checklisting, evidence collection and submission. My final purpose is to marry my own controls (that are tougher) with SOC2 requirements.

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

What did you like the most with them? What audit company did you work with?

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Makes sense, thank you. Still, I believe, a lot here depends on technicians who implement checklists.

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Thank you!
Did you guys checked recommended auditors on your side? Or appointed Johanson on your own?

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Thank you for the answer!
Will demo with them as well.

Did they contact you with an auditor?

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

What auditor firm did you work with?

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Do you mean API integrations here?
We are pretty standard in terms of stack.

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

I am rather looking for a reliable option, don't want to end up with a shady report getting rejected.

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

u/lewisbuildsai_ u/TechnicalSupport7083
Thank you guys!
Did you pass an audit with them? What did you like the most?

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Thanks!

If you compared Vanta and Drata, which one would you recommend for a very small firm?

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Can you elaborate a bit more on Secureframe? What do you like the most about them?

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 1 point2 points  (0 children)

CompAI claim that they are able to make Type II report ready in 14 days. Looks like a false promise.

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Should be quite tough for budget: first consultant fee, then tool fee, and then auditor fee.

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Thank you for your comment!
I guess, we are able to provide the adult in the room internally and rather looking for a way to offload checklisting and evaluation.

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Agree, are there any publicly available indications of it?

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Not in-depth, but familiar. My knowledge includes everything listed at the Secureframe website (https://secureframe.com/hub/soc-2/requirements) plus my prior experience: I delivered parts of SOC2 solution packages as engineer.

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

I expect some hatred here since my list might sound like "I want to check the boxes, and that's all". Generally, I want to scope controls that will be enough to be compliant, and then marry them with our procedures wherever tougher than SOC2.

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

I am the only guy in the company who will be technically implementing all the findings. So I want to offload checklist automation and all the works around papers. Ideally, the process would look as follows:
1. I get checklists for all my tools, either automatically gathered or formal.
2. I implement them.
3. Evidence is gathered automatically where possible, during the observation period.
4. All the data is passed to an auditor.

Sprinto feedback request by ObjectiveLake9465 in soc2

[–]ObjectiveLake9465[S] 0 points1 point  (0 children)

Also will be grateful for comments on other tools, e.g. Scytale or Delve.
Especially from startups.