问HN:你们如何对应用进行合规性审计?

2作者: Luxter8 天前原帖
合规软件如 Vanta、Drata 等仅能读取第三方 API(如 AWS、Github、Okta 等),但无法自动审计实际使用这些 API 的应用程序,例如,某个时间点谁在您的应用中拥有管理员访问权限。 我是一名来自波兰的工程师,没有合规背景,因此如果您过去对您的应用进行了审计(如 SOC 2/ISO 27001/HIPAA/PCI 等): 1. 您产生了什么结果(截图?SQL 查询?CSV 文件?) 2. 您公司中是谁负责的?花了多长时间?这是一个重复性的任务吗? 3. 您是否为此在内部开发了任何工具?现在还在维护吗? 如果您使用了某个工具,我将非常感激您告诉我是哪一个。
查看原文
Compliance software like Vanta, Drata and similar only read 3rd party APIs (AWS, Github, Okta etc.) but cannot automatically audit your app that actually uses them, e.g. who had admin access in your app at given point in time.<p>I&#x27;m an engineer in Poland with no compliance background, so if you did an audit for your app in the past (SOC 2&#x2F;ISO 27001&#x2F;HIPAA&#x2F;PCI etc.):<p>1. What did you produce (Screenshots? SQL query? CSV?)<p>2. Who did it in your company? How long did it take? Is it a recurring task?<p>3. Did you build anything in-house for it? Are you still maintaining it?<p>If you used a tool for that then I&#x27;d appreciate if you tell me which one.