social.coop is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Fediverse instance for people interested in cooperative and collective projects. If you are interested in joining our community, please apply at https://join.social.coop/registration-form.html.

Administered by:

Server stats:

488
active users

#soc2

0 posts0 participants0 posts today
Tuist<p>5. What’s next?</p><p>We’ve launched the Tuist Security Center <a href="https://security.tuist.dev/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">security.tuist.dev/</span><span class="invisible"></span></a> where you can:<br> 🔹 See how we protect your data<br> 🔹 Request our SOC 2 report</p><p>Security is a journey. We’re just getting started. 🚀🔒<br><a href="https://fosstodon.org/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a> <a href="https://fosstodon.org/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://fosstodon.org/tags/DevTools" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevTools</span></a> <a href="https://fosstodon.org/tags/SaaS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SaaS</span></a></p>
Dr. HermanSJr.<p>Industry's 1st &amp; only book/#bible on <a href="https://mastodon.social/tags/compliance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>compliance</span></a>/#governance for <a href="https://mastodon.social/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a> for all <a href="https://mastodon.social/tags/enterprise" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>enterprise</span></a> &amp; <a href="https://mastodon.social/tags/startups" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>startups</span></a> <a href="https://mastodon.social/tags/serviceProviders" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>serviceProviders</span></a> worldwide regarding <a href="https://mastodon.social/tags/IT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IT</span></a>, <a href="https://mastodon.social/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a>, <a href="https://mastodon.social/tags/InformationTechnology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InformationTechnology</span></a>.</p><p>"The Framework Efficiency Architect: Transforming SOC 2 Into A Monetization Weapon"</p><p>More info at DrHermanSJr.carrd.co (last book at bottom).</p><p>Launching late April 2025 as the first in a series covering major frameworks.</p><p>Pre-sales, with an added free 1-hour consultation, available now at <a href="https://ko-fi.com/s/0727fa33a1" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">ko-fi.com/s/0727fa33a1</span><span class="invisible"></span></a>.</p>
passbolt<p>Over the last four months, passbolt underwent three independent assessments to evaluate and strengthen our security posture.</p><p>These assessments help us identify and address areas for improvement while confirming our existing security strengths. </p><p>Read more about the latest security reviews: <a href="https://hubs.li/Q039csDh0" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">hubs.li/Q039csDh0</span><span class="invisible"></span></a></p><p>See the findings in the thread.</p><p><a href="https://mastodon.social/tags/SecurityAudit" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityAudit</span></a> <a href="https://mastodon.social/tags/Cryptography" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cryptography</span></a> <a href="https://mastodon.social/tags/OpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSource</span></a> <a href="https://mastodon.social/tags/PasswordSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordSecurity</span></a> <a href="https://mastodon.social/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a> <a href="https://mastodon.social/tags/Pentesting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Pentesting</span></a></p>
Frederic Branczyk :verified:<p>Compliance is one of those things that all businesses have to go through, so it's not all that special, but I'm really excited about what this is about to unlock for Polar Signals! <a href="https://hachyderm.io/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://hachyderm.io/tags/soc2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>soc2</span></a> <a href="https://hachyderm.io/tags/compliance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>compliance</span></a></p><p><a href="https://www.polarsignals.com/blog/posts/2025/01/14/soc2type2" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">polarsignals.com/blog/posts/20</span><span class="invisible">25/01/14/soc2type2</span></a></p>
AGR Risk Intelligence&gt; Compliance is a byproduct of security engineering. Good security engineering has little to do with compliance. <br><br>**The SOC2 Starting Seven**<br><br><a href="https://www.latacora.com/blog/2020/03/12/the-soc-starting/" rel="nofollow noopener noreferrer" target="_blank">https://www.latacora.com/blog/2020/03/12/the-soc-starting/</a><br><br><a class="hashtag" href="https://pleroma.envs.net/tag/cybersecurity" rel="nofollow noopener noreferrer" target="_blank">#Cybersecurity</a> <a class="hashtag" href="https://pleroma.envs.net/tag/soc2" rel="nofollow noopener noreferrer" target="_blank">#SOC2</a> <a class="hashtag" href="https://pleroma.envs.net/tag/compliance" rel="nofollow noopener noreferrer" target="_blank">#Compliance</a>
Mr. Crab - Sysadmin from Heck<p>Once again fighting with the <a href="https://infosec.exchange/tags/soc2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>soc2</span></a> auditors because they don't understand EDR/XDR vs basic AV.</p><p>The auditors make vague requests and then disappear for a few days before replying with even murkier responses.</p><p>They reject reports even though some systems only have the option of outputting to a .csv files, even with screenshots of the parameters included.</p><p>How do I show that a spreadsheet has been only shared on a need to know basis??</p><p>Not sure if this level of tedium is the norm for a soc2 type II engagement but this has been the most frustrating thing I've worked on all year.</p>
NosirrahSec 🏴‍☠️<p>Need some help making sure what I'm writing for SOC2 compliance isn't pure shit, and since searching for anything SOC2 related just results in sales bullshit...</p><p>Was hoping the community had resources saved from their own pains doing this.</p><p>Anyone got resources related to writing up compliant policies for SOC2 compliance? </p><p>I'm shooting out of my depth I feel going from engineering/infosec/operations to writing policies, but if I don't who will? lol</p><p><a href="https://infosec.exchange/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a> <a href="https://infosec.exchange/tags/grc" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grc</span></a></p>
passbolt<p>🚀 <a href="https://mastodon.social/tags/Passbolt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passbolt</span></a> has successfully renewed its SOC2 Type II audited report, with no exception noted by the auditors, for the third time in a row! Contact us to review the report: <a href="https://hubs.li/Q02sxvf00" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">hubs.li/Q02sxvf00</span><span class="invisible"></span></a></p><p><a href="https://mastodon.social/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://mastodon.social/tags/Compliance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Compliance</span></a> <a href="https://mastodon.social/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a> <a href="https://mastodon.social/tags/OpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSource</span></a></p>
Thijs Kromhout<p>Fairly simple question regarding <a href="https://infosec.exchange/tags/soc2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>soc2</span></a> reporting:</p><p>Is it possible for an organization to decide not to do a type 1 assurance report and straight go for a type 2?</p><p>Or should one always do type 1 and then type 2?</p>
Marcel Waldvogel<p>Der <a href="https://waldvogel.family/tags/Republik" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Republik</span></a>-Artikel von <span class="h-card" translate="no"><a href="https://chaos.social/@adfichter" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>adfichter</span></a></span> zu <a href="https://waldvogel.family/tags/Xplain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Xplain</span></a> zeigt auf, dass<br>1️⃣ die Behörden sich selbst immer tiefer in Abhängigkeiten zu Xplain navigiert hatten, <br>2️⃣ für diesen Lock-In keine Exit-Szenarien existieren und<br>3️⃣ Due Diligence vernachlässigt wurde (wieso?).</p><p>Übrigens: Ein IT-Sicherheitszertifikat wie <a href="https://waldvogel.family/tags/ISO27001" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ISO27001</span></a> oder <a href="https://waldvogel.family/tags/SoC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SoC2</span></a> sagt nichts über die tatsächliche Sicherheit aus, nur dass man viel Text dazu geschrieben hat.</p><p>1/2<br><a href="https://waldvogel.family/tags/TooBigToFail" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TooBigToFail</span></a> <a href="https://waldvogel.family/tags/LockIn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LockIn</span></a> <a href="https://waldvogel.family/tags/FOSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FOSS</span></a> <br><a href="https://www.republik.ch/2023/09/25/xplain-ein-beschaffungsskandal" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">republik.ch/2023/09/25/xplain-</span><span class="invisible">ein-beschaffungsskandal</span></a></p>
isecjobs.com<p>HIRING: Senior Cybersecurity Analyst, GRC / Concord, MA 👉 <a href="https://infosec-jobs.com/J40475/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">infosec-jobs.com/J40475/</span><span class="invisible"></span></a> <a href="https://mastodon.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://mastodon.social/tags/infosecjobs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosecjobs</span></a> <a href="https://mastodon.social/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mastodon.social/tags/CyberCareer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberCareer</span></a> <a href="https://mastodon.social/tags/cyber" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cyber</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/jobs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>jobs</span></a> <a href="https://mastodon.social/tags/jobsearch" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>jobsearch</span></a> <a href="https://mastodon.social/tags/techjobs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>techjobs</span></a> <a href="https://mastodon.social/tags/hiringnow" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hiringnow</span></a> <a href="https://mastodon.social/tags/job" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>job</span></a> <a href="https://mastodon.social/tags/SeniorJobs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SeniorJobs</span></a> <a href="https://mastodon.social/tags/compliance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>compliance</span></a> <a href="https://mastodon.social/tags/GRCjobs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GRCjobs</span></a> <a href="https://mastodon.social/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a> <a href="https://mastodon.social/tags/PCIDSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PCIDSS</span></a> <a href="https://mastodon.social/tags/ConcordMA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ConcordMA</span></a> <a href="https://mastodon.social/tags/KAYAK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>KAYAK</span></a> <a href="https://mastodon.social/tags/NIST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NIST</span></a> <a href="https://mastodon.social/tags/flexiblehours" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>flexiblehours</span></a></p>
Ivan Moscoso<p>Remembering the time I worked with a vendor on a <a href="https://indieweb.social/tags/soc2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>soc2</span></a> audit and how one of the people assigned to the job was so amazing at what they did.</p><p>Reminder that no matter how much you feel what’s tedious for you must feel tedious to everyone, someone out there is incredibly passionate about that thing you aren’t thrilled to do on your own.</p>
Thomas Strömberg 🚲🌳🛵<p><span class="h-card"><a href="https://hachyderm.io/@renice" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>renice</span></a></span> well said. <a href="https://triangletoot.party/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a> my favorite sort of Ponzi scheme: one with a purpose.</p>
Thomas Strömberg 🚲🌳🛵<p>Today it's my turn to present at the company all-hands meeting, discussing the importance of the <a href="https://triangletoot.party/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a> "certification".</p><p>I hope the first slide captures my feelings appropriately.</p>
Phillip Upton<p>Encrypting your database at rest.</p><p>For those times when you expect your adversary to be smart enough to infiltrate your system, but dumb enough to not decrypt it while they are in there. <a href="https://mastodon.sdf.org/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a></p><p>See also: <a href="https://stackoverflow.com/questions/58901688/how-to-confirm-data-at-rest-encrypted-by-mariadb" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">stackoverflow.com/questions/58</span><span class="invisible">901688/how-to-confirm-data-at-rest-encrypted-by-mariadb</span></a></p>
isecjobs.com<p>HIRING: Senior Manager, Security Risk and Compliance / Campbell, CA <a href="https://infosec-jobs.com/J28282/" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="">infosec-jobs.com/J28282/</span><span class="invisible"></span></a> <a href="https://mastodon.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://mastodon.social/tags/InfoSecJobs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSecJobs</span></a> <a href="https://mastodon.social/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://mastodon.social/tags/jobsearch" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>jobsearch</span></a> <a href="https://mastodon.social/tags/hiringnow" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hiringnow</span></a> <a href="https://mastodon.social/tags/CyberCareers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberCareers</span></a> <a href="https://mastodon.social/tags/Campbell" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Campbell</span></a> <a href="https://mastodon.social/tags/CA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CA</span></a> <a href="https://mastodon.social/tags/Audits" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Audits</span></a> <a href="https://mastodon.social/tags/Cloud" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cloud</span></a> <a href="https://mastodon.social/tags/Compliance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Compliance</span></a> <a href="https://mastodon.social/tags/FedRAMP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FedRAMP</span></a> <a href="https://mastodon.social/tags/Finance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Finance</span></a> <a href="https://mastodon.social/tags/Governance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Governance</span></a> <a href="https://mastodon.social/tags/Monitoring" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Monitoring</span></a> <a href="https://mastodon.social/tags/NIST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NIST</span></a> <a href="https://mastodon.social/tags/Privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Privacy</span></a> <a href="https://mastodon.social/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a></p>
Thomas Strömberg 🚲🌳🛵<p>Damnit. I just tried to move my work machine to a Mac Mini running <a href="https://triangletoot.party/tags/AsahiLinux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AsahiLinux</span></a> - only to remember that Full Disk Encryption is not yet supported (<a href="https://github.com/AsahiLinux/asahi-installer/issues/137" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/AsahiLinux/asahi-in</span><span class="invisible">staller/issues/137</span></a>), and it's required for logging in to our work systems (thanks, <a href="https://triangletoot.party/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a>!)</p><p>Perhaps it's time to drag the <a href="https://triangletoot.party/tags/Honeycomb" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Honeycomb</span></a> <a href="https://triangletoot.party/tags/LX2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LX2</span></a> out. It's a really great kit for <a href="https://triangletoot.party/tags/arm64" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>arm64</span></a> <a href="https://triangletoot.party/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> - once you can get the fans under control.</p>
mkb<p>Today I got to spend an hour walking a more junior <a href="https://mastodon.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> person through some challenging problems in her first <a href="https://mastodon.social/tags/soc2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>soc2</span></a> audit. So much fun! I love watching people spread their wings.</p>
Thomas Strömberg 🚲🌳🛵<p>Our latest <a href="https://triangletoot.party/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a> drop: <a href="https://github.com/chainguard-dev/acls-in-yaml" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/chainguard-dev/acls</span><span class="invisible">-in-yaml</span></a></p><p>As part of <a href="https://triangletoot.party/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a> <a href="https://triangletoot.party/tags/compliance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>compliance</span></a>, we've been using this to run monthly <a href="https://triangletoot.party/tags/audit" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>audit</span></a> reviews of our ACLs across SaaS platforms: <a href="https://triangletoot.party/tags/GCP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GCP</span></a>, <a href="https://triangletoot.party/tags/Slack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Slack</span></a>, <a href="https://triangletoot.party/tags/Vercel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vercel</span></a>, etc. </p><p>acls-in-yaml dumps <a href="https://triangletoot.party/tags/ACLs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ACLs</span></a> from each platform into a consistent and neutral <a href="https://triangletoot.party/tags/YAML" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>YAML</span></a> format, which makes it easy to visualize change over time. </p><p>We use this by committing the result into a <a href="https://triangletoot.party/tags/Github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Github</span></a> repo and getting the PR reviewed by the admins for each system.</p><p>PS: ACL change alerts are also awesome!</p>