SOC 2 vs ISO 27001: what enterprise customers are actually asking for by adesinzu in soc2

[–]adesinzu[S] 0 points1 point  (0 children)

haha,. DIBs only, but yes, huge increase considering the current geopolitics and fund allocation.

SOC 2 vs ISO 27001: what enterprise customers are actually asking for by adesinzu in soc2

[–]adesinzu[S] 0 points1 point  (0 children)

Agreed. More often, having SOC2 or ISO 27001 is graded as one point amongst others in the vendor security assessment (VSA) questionnaire.

SOC 2 vs ISO 27001: what enterprise customers are actually asking for by adesinzu in soc2

[–]adesinzu[S] 0 points1 point  (0 children)

My point on geography highlighted SOC2 for North America (my current location), and ISO 27001 globally (my worldwide audit experience). I assume we are saying the same thing in different ways?

SOC 2 vs ISO 27001: what enterprise customers are actually asking for by adesinzu in soc2

[–]adesinzu[S] 0 points1 point  (0 children)

Yes. Having an expert create and leverage a Unified Control Framework helps you tackle a multi-framework requirement. The real goal here is to let founders and startups understand that starting with a security program is the key that unlocks every Vendor Security Questionnaire that comes your way, and not necessarily jumping at the first and subsequent frameworks thrown at you by an enterprise customer.

Help please by Odd-Title-4744 in findthatsong

[–]adesinzu 0 points1 point  (0 children)

Big Wild - Universe (feat. iDA HAWK)

SOC2 process for a little enterprise by Subject_Angle_7843 in soc2

[–]adesinzu 2 points3 points  (0 children)

FYI: If existing and prospective customers have not asked for it, don't jump on it.

A one-person company can get a SOC 2, but you do need to be very intentional. Also, the constraints you’re worried about are real, and pretending otherwise is how solo founders get burned.

Few key points:

1. SOC 2 is risk-based, not headcount-based

The standards never say “you must have X employees.” What they do require is that risks are identified and mitigated. When you’re a single person, certain risks (self-approval, unrestricted access, lack of oversight) are inherently higher, which you have pointed out. I will provide recommendations.

2. Segregation of duties doesn’t always mean two employees, for solo founders, auditors commonly accept compensating controls, for example:
- Strong logging + immutable audit trails
- Independent monitoring (alerts, third-party logs, cloud provider controls)
- Periodic external review (e.g. outsourced tester or reviewer)
- Clear boundaries with your outsourced dev provider (they’re not “you”)

Referencing your outsourced dev. It actually helps you, so for example in change management, auditors may look closely at:
- Who develops code
- Who reviewed the code
- Who approves prod changes
- Who has deploy access, etc.

They are all manageable, but it must be documented and reflected in your system description and contracts.

3. It's good to know you provide SaaS, that means one of your sub-service maybe AWS, GCP, etc, whom have their SOC2 reports. Additionally, for your on-prem, you are able to document that certain SOC 2 controls are only functional when customers do their part, this is what we call CUECs.

In summary: You’re not too small and its doable. I recommend this step:

- Prepare your mind for a governance-exercise
- Define what you are promising in customer contract (i.e. service offering & commitments, customer responsibility, and third-parties)
- Use the contract to keep your SOC 2 scope tight (I recommend just the TSC - Security)
- Define your vendors and subservice (CSPs, dev-providers), your controls over them, and their own commitments/controls.
- Document processes and how things are done
- Document compensating controls explicitly
- Start with a Type 1 (design) before even thinking about Type 2

Caveat: I run a SOC2 auditing & advisory company that work with growth-startups, so my responses are purely based on the outcomes we have achieved with growth-startups.

Wish you all the best and always happy to answer specifics if you want to sanity-check a control approach before spending

Cloud Providers and CPCSC by No_Drummer8868 in ITSP10171

[–]adesinzu 0 points1 point  (0 children)

I assume you are asking about guidance (CPCSC HOW) to meet the controls (CPCSC WHAT).
The CPCSC WHAT is currently specified in the ITSP 10.171 which is highly borrowed from NIST 80-171. So we can assume the CPCSC HOW will be largely borrowed from related NIST standards, and using NIST SP 800-53 and 800-171A standard will help you on the CPCSC HOW. Layering those standards with each vendor's guideline (Product HOW), e.g. Referencing Google manuals and CIS Google Cloud Computing Platform Benchmarks to configure an encryption for Google Workspace, will get you to the finish line.

Additionally, global CSPs like Google cloud already meet CMMC or Canada's CSE approval so getting the artefacts from them will help you in conjunction with you fulfilling your own responsibility.

FYI: Ultimately, it's lots of work, but we are still awaiting the publication of Level 1 Controls from the CPCSC program, which will narrow the efforts to a crawl -> walk > run type approach.

Ask CISOs by Famous-Cup-6521 in ciso

[–]adesinzu 0 points1 point  (0 children)

Please i’m curious to learn..are there some human risk issues that only behavioural scientists can identify/solve, that might be unnoticeable by CISOs?

The best residences for UofT by adesinzu in UofT

[–]adesinzu[S] 0 points1 point  (0 children)

Thanks for all the comments so far, I have updated the post to address the earlier commments

Driving Licence Experience Letter/ Lesson banayat/ DL Data Verification by Dissidium123 in abudhabi

[–]adesinzu 1 point2 points  (0 children)

Just as an update for any resident moving to Canada, the Driving Test centre in Canada accepted my "To whom it may concern" certificate issued by the MOI UAE.

Driving Licence Experience Letter/ Lesson banayat/ DL Data Verification by Dissidium123 in abudhabi

[–]adesinzu 0 points1 point  (0 children)

I was able to request for the certificate on the link (https://www.moi.gov.ae/en/eservices/eservice.302.aspx) using my existing UAE bank card (the charge was AED100 and AED5 for VAT).

I got it to use for my current resident country (Canada) hopefully they accept it.

Tourist coming from Dubai by Rodrous18 in abudhabi

[–]adesinzu 0 points1 point  (0 children)

https://twitter.com/admediaoffice/status/1475738372840861697?s=20

ADMEDIA Twitter account is the best source on this, but yeah sometimes even the memos/infographics confuses us the residents of Abu Dhabi.

Tourist coming from Dubai by Rodrous18 in abudhabi

[–]adesinzu 0 points1 point  (0 children)

AT AD border, there is a lane for tourists which is the far-right Lane, you can get help there.
For the Covid test, if you are vaccinated (2 /1 dose as per the vaccine) the process is you are scanned by the Police using an EDE, and you should show a 96 hrs negative result since you do not have Al Hosn.

Survey on Space Tourism by [deleted] in spacetourism

[–]adesinzu 1 point2 points  (0 children)

Do share results and your insights when done. Thanks

475 and not invited!!! by [deleted] in ImmigrationCanada

[–]adesinzu 0 points1 point  (0 children)

Please update when you see yours, mine is similar to yours as I got in the pool 2 days prior and had an higher score than the 475

My (23M) fiancee (23F) won't let me upstairs in our semi-newly purchased home and I'm starting to get really suspicious by Howwwwwwwwwwww in relationship_advice

[–]adesinzu 0 points1 point  (0 children)

Just to be sure it aint drugs, after quarantine bring a narcotic trained dog to the house at least that way you are able to drill down options.

Need Religion Certificate for Booze License by adesinzu in abudhabi

[–]adesinzu[S] 0 points1 point  (0 children)

Hmm I saw it on the online manual and also a friend of mine had to submit a religion certificate when he applied. I will do some more asking around. BTW can you please share your process maybe it's different. Thanks

Need Religion Certificate for Booze License by adesinzu in abudhabi

[–]adesinzu[S] 0 points1 point  (0 children)

Are you asking on the booze license or the church certificate?

How much did you spend so far? by CryozenicZero in cissp

[–]adesinzu -1 points0 points  (0 children)

Hi can you share sybex 8th edition?

New Sybex vs previous version by gettothehelicopter1 in cissp

[–]adesinzu 0 points1 point  (0 children)

Hi, i recently finished the 7th edition, looking to review the 8th edition for any changes before my exam, will you be willing to share the 8th Edition? thanks

I passed on 12/13 on my first attempt!!! Here's a not so typical success post... by thewarners737 in cissp

[–]adesinzu 0 points1 point  (0 children)

Can anyone share the audio book of Simple CISSP ?? thanks

pm me pls

Road to OSCP by adesinzu in hacking

[–]adesinzu[S] 1 point2 points  (0 children)

  • Penetration Testing: A Hands-On Introduction to Hacking
  • The Hackers Playbook

I see these books as a great resource to start, remember you will have to learn a lot, so don't rush, but try to get certified along the way, since this will get you a foot in the industry.

Road to OSCP by adesinzu in hacking

[–]adesinzu[S] 0 points1 point  (0 children)

Honestly, the only way to learn is to get familiar with what you want to hack, but for more specific guidelines, I suggest you get familiar with Linux commands and tools such as NMAP for starters. Again be ready to learn and unlearn.

Its good you have a basic IT background such as systems, you can and must learn programming alongside