What two SOC 2 cycles taught me about security engineering
Compliance frameworks are mostly about proving you do what you say. Here's how to make that cheap.
The first SOC 2 audit is about writing down what you do. The second is about discovering whether you actually did it all year.
Make evidence a by-product
If collecting evidence is a separate job, it will be done late and badly. Make it fall out of normal engineering work:
- Access reviews generated from your identity provider, not from spreadsheets.
- Change management that is your pull request process.
- Infrastructure changes only through code, so the git log is the audit log.
Controls engineers don’t route around
A control that slows every deploy will be bypassed. Design controls that sit on the paved road, and keep the dirt track uncomfortable.