SOC 2 from the DevOps Angle: Why Your Infrastructure Engineer Is Your Best Compliance Lead

https://hackernoon.imgix.net/images/DFMsGPFH1idycAkB5tbjIRQffnz1-5g83eni.jpeg

When leadership announced we were pursuing SOC2, the first idea was the same every company has: hire a compliance consultant. Still, as a DevOps Engineer, I realised straight away that almost every control the auditor or readiness consultant were going to ask about lived in systems I already owned.

Access reviews? That’s our IAM and authentication directory. Change management? It lives in our CI/CD. Encryption at rest and in transit is reflected across our networking and configuration management. Logging and monitoring? Our observability stack. Vulnerability management? Already was on my plate as the common security exercise.

So instead of assisting in SOC2, I decided to own it. And this is the story of taking a company with hybrid infrastructure through a full SOC2 Type II audit, and why I’ve come to believe DevOps is the most viable owner and facilitator for this journey, not just a contributor to it.

SOC...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/JyaCZed2wVhxJpHqsSiovd-2560-80.jpg

Dynaudio's wild soundbar with moving 'kinetic fins' is one of the most impressive I've ever seen — I spoke to the company's CCO about building a luxe soundbar for giant TVs and its impressive 24-driver design

Recently, I had the chance to attend High End Vienna, where I bore witness to an incredible array of audio gear. Whether it was new flagship loudspeakers from Bowers & Wilkins, futuristic looking headphones, or innovative portable DACs, there was a lot to get excited about. But one product really