"That's not SoC 2 compliant"

14 points | by tosh 44 minutes ago

7 comments

  • aleda145 2 minutes ago

    This stance is a breath of fresh air. In my experience change management is the first thing to slap on when a bad release happens.

    I've worked at a large enterprise that have a "Change Advisory Board", that you need to convince when you want to bump the major version on your linter. It has the effect of velocity slowing down to a crawl. Changes have to large, since otherwise it wouldn't be approved by the CAB. A slow mess.

    At my current place we have to loudly declare "I CONFIRM COMPLIANCE" in every PR description. I'm not sure that anyone knows why, but it keeps the bureaucrats happy. Shrug

  • jpollock 9 minutes ago

    I was in a high trust environment that didn't use dual auth on some things. They lost $250k to embezzlement.

    High trust is high trust until someone exploits it, and the likelihood of encountering an exploit (embezzlement, fraud, political speech, etc.) approaches zero as the total number of staff hours increase.

  • abofh 10 minutes ago

    Youre required to have a policy. That policy may be throwing bananas at the wall, but if it's documented and you follow it, you're compliant with policy.

  • NewJazz 15 minutes ago

    Soc2 is pointless.

    But how do they review each other's work? Prs are indispensable for collaboration...

      Tomte 2 minutes ago

      We‘ve had code reviews before GitHub existed. PRs are a tool. And just one tool among many.

      mparramon 4 minutes ago

      You can pair program.

  • rohansood15 3 minutes ago

    So an engineer who knows your codebase and tests can sneak in malicious code/backdoors because you're high trust.

    And I am guessing you'll extend that high trust to your agents/'orbs' next. And I am sure you'll find an auditor who'll go with it coz frankly most don't care.

    I am not surprised there are folks willing to do this, but I am surprised that you feel you must brag about it. And you ARE bragging when you title the post the way you did. Good luck.