Skip to content

Reading between lines of SOC 2 reports for DC selection

Datacenter Talk by RAJ 2 replies 132 views
2 #1

Been on both sides of this as auditor and reseller. SOC 2 Type II looks shiny but heres what they dont teach you in compliance school.

1. Scope games
Provider audits "core platform" but excludes network ops done by third party. You think youre covered. You arent. Ask for explicit boundary diagrams.

2. "Management response" weasel words
"Management believes controls were operating effectively" = we found gaps but wrote a letter to ourselves saying its fine.

3. Subservice orgs
Most DCs use someone elses physical security. Their SOC 2 is not your SOC 2. You need the full vendor list.

4. Testing frequency tricks
Quarterly testing done in last week of quarter. Three months of blind faith.

Had a compliance firm send me DMCA for posting excerpts from "their" template language. Fought it. Its fair use for educational purpose + I wrote half the language working there lol. Won. Took 6 months.

Any leads on providers who actually include network layer in scope? Looking for margin-friendly options for my panel guys.

your margin is my opportunity
#2

Thank you for share this. I am trying to make a server up for client in EU and SOC 2 is requirement but I never know how to read between lines.

You say ask for boundary diagram. Is possible to request before sign contract? Or only after?

Regards

siesta first, deploy later
#3

The subservice org thing is hugee I got burned by thsi recieved a report that looked good but the physical security was outsourcedt o some shell companyy noone could find

You figure it out he says

Never trust the management response paragraph its all fluff

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft