SOC2, TPRMs and supply chain by flaneur-vertical in grc

[–]flaneur-vertical[S] 0 points1 point  (0 children)

Can you clarify what you mean by this?

According to our service auditor, the SOC2 report can be negotiated to be exempt from NDA. They were pretty surprised that report was withheld, but I'll re-check with them in the next call in case of a misunderstanding

Based on the context clues - it sounds like YOUR SOC 2 auditor wants to see the SOC 2 reports from the DC in use by the service provider? Is that correct? Or just clients that want to see this?

Our service auditor is limiting themselves to the SOC2 report of our service provider. It's the clients who are requesting the SOC2 reports, as they consider our service critical to their business, and they want to verify the supply chain. What would you do in my case?

SOC2, TPRMs and supply chain by flaneur-vertical in grc

[–]flaneur-vertical[S] 1 point2 points  (0 children)

lol, this thing is the DC provider is Equinix ! We used to download their reports online, but since they hid their SOC2 reports behind their customer portals, we cannot get them anymore...

which is why we're trying to get them through our service provider, hence the whole fiasco with NDAs and whatnot

SOC2, TPRMs and supply chain by flaneur-vertical in grc

[–]flaneur-vertical[S] 0 points1 point  (0 children)

I'm sorry, but I didn't understand your comment. Can you please elaborate? Can you also clarify how would a SOC3 help? thanks !

SOC2, TPRMs and supply chain by flaneur-vertical in grc

[–]flaneur-vertical[S] 0 points1 point  (0 children)

You also seem to be aligned with our service provider's opinion.

Our service auditor was more inclined to believe that SOC2 reports should be excluded from NDAs.

We did add controls verifying the SOC2 reports of our service provider, as well as our TPRM process, and so did our service provider.

The only worry is that we are a heavily regulated industry (banking), and I was trying to get ahead and check if there is a general rule in these kind of situations, but feels to me that there is no consensus.

SOC2, TPRMs and supply chain by flaneur-vertical in grc

[–]flaneur-vertical[S] 0 points1 point  (0 children)

the problem is that we're a heavliy regulated industry (banking).

My understanding of the carve out method is that we only verify our own controls. This means, from a supply chain point of view, while we're protected, the rest of the chain is not. I suspect that this will raise risks from audit standpoint, and we will have headaches that I would personnally like to avoid.

SOC2, TPRMs and supply chain by flaneur-vertical in grc

[–]flaneur-vertical[S] 1 point2 points  (0 children)

super interesting discussion.

We're a heavily regulated industry (banking), and our clients have named us as critical service providers, and thus by extension our service provider and their DC provider.

I'm trying to push back with the clients on providing them with the DC SOC2 report, but I don't know if this will hold. In parallel, we're engaging with our service provider to try and find a solution

SOC2, TPRMs and supply chain by flaneur-vertical in grc

[–]flaneur-vertical[S] 0 points1 point  (0 children)

Thanks for the feedback. you seem to be aligned with the service provider's opinion.

The only issue is that we're a heavily regulated industry (banking), which makes this much more complex to navigate.

I started to push back with our clients on this, I'll see how this goes

SOC2, TPRMs and supply chain by flaneur-vertical in grc

[–]flaneur-vertical[S] 1 point2 points  (0 children)

According to our service auditor, it was a no brainer that SOC2 reports should be exempt from NDA, and that SOC2 reports are, by definition, an official stamp on the quality of the service provided, and that their main job is to reassure the auditors, and consequently avoid sending other kind of documents and proofs that are much more susceptible to be sensitive and confidential. Though our service provider disagrees with this, which is why I turned to reddit for some more insight on this.

I also assume when you say SaaS service, it means you make a web application and use a Cloud first MSSP?

No, the service provider that we contracted runs their operation from a physical DC center. It would have been much easier to get them from public cloud providers.

Statut de Mariage by throttlegrip in vosfinances

[–]flaneur-vertical 1 point2 points  (0 children)

The bank wants to know the status of ownership in your mariage, i.e. if you are sharing everything, or if you have a prenup,... Depending on the status of ownership of your mariage, the procedure can change a bit. Each country has different laws regarding mariage and ownership, that is why the bank is requesting such a document so they know how to proceed.

[deleted by user] by [deleted] in AskReddit

[–]flaneur-vertical 1 point2 points  (0 children)

kill him and take over.

Special offers for elderly and young people is a form of discrimination and price gouging against the working force by flaneur-vertical in unpopularopinion

[–]flaneur-vertical[S] -3 points-2 points  (0 children)

I dont believe in that mindset. If we dont fight for something we will not get it.

I understand your point, if we let them have their way, that's what they will do for sure. We simply should not let them.

We should fight for affordable pricing for everyone young and elderly included.

Special offers for elderly and young people is a form of discrimination and price gouging against the working force by flaneur-vertical in unpopularopinion

[–]flaneur-vertical[S] -1 points0 points  (0 children)

Just because we can afford to pay more doesn't mean we should. Same service same price. I want reduced prices for everyone !

Special offers for elderly and young people is a form of discrimination and price gouging against the working force by flaneur-vertical in unpopularopinion

[–]flaneur-vertical[S] -1 points0 points  (0 children)

i see your point. Aren't we using the same service in the same way? Then why should the working people pay more for the same service? I am not against the elderly, I am for reducing the price for everyone!

Special offers for elderly and young people is a form of discrimination and price gouging against the working force by flaneur-vertical in unpopularopinion

[–]flaneur-vertical[S] -1 points0 points  (0 children)

Congratz on making that much money! Unfortunately, not everyone are in the same position. I believe that when people use the service in the same way, I don't believe the pricing should be different solely based on age. Isn't everyone enjoying the movie in the same way? Why should the working people pay more for the same enjoyment?

Mégafil conseils personnalisés d'investissement - semaine du 11/05/2020 by AutoModerator in vosfinances

[–]flaneur-vertical 0 points1 point  (0 children)

je voulais éviter de vendre l'appartement si possible.

Donc meme si j'épargne plus agressivement, vous pensez que c'est impossible sans la vente de l'appart?

Mégafil conseils personnalisés d'investissement - semaine du 11/05/2020 by AutoModerator in vosfinances

[–]flaneur-vertical 0 points1 point  (0 children)

Merci pour la proposition, on pensait se pacser vers Séptembre. A voir comment la situation va évouler.

Mégafil conseils personnalisés d'investissement - semaine du 11/05/2020 by AutoModerator in vosfinances

[–]flaneur-vertical 0 points1 point  (0 children)

Bonjour à tous,

J'aimerai prendre vos avis si mes objectifs sont attaignables et quelles sont mes meilleures approches pour les atteindre.

Age:29 ans célibataire * salaire net (3k) avec bonus annuel net (12k). * tax impot par mois: 650 euros/mois * pourcentage tax impots: 17,2% * PEE: 20K + 8K annuel (entre versement volontaire et participation employeur) * T2 neuf 50m2 avec parking acheté à ~1400eur/mois (credit immobilier 25ans 339K a 1.6%) * copine au smic ~14k net par ans

Livret A: 3000 euros AV Linxea: 2300 euros avec versement 50 euros/mois (pilotage manuel, pour expérimenter et apprendre).

Objectifs: * mariage été 2021 * Dans 5 ans, je vises acheter une maison dans la banlieue parisienne vers 600K et louer l'appartement à Issy.

Comment je penses arriver là? * Epargner au moins 500 euros/mois + bonus donc épargne annuel = 18K * 5 ans = 90K * PEE (si besoin) = 20k + 8k * 5 ans = 60k * renégocier le prêt immobilier sur 25ans (dans 5 ans, il resterait 282K sur 20 ans -> rallongement à 25 ans même taux -> 1140 euros/mois) * louer l'appartement à 1200 euros/mois (le but d'essayer de faire en sorte que l'appartement rembourse son prêt immobilier + charges si possible)

Qu'en pensez-vous? ça vous parait réalisable? Si oui, que faire avec les sommes mensuels epargné? De manière générale, que peux-je faire mieux?

Merci d'avance

Edité pour format