Coffee, Chaos and ProdSec
🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 37 Your vendor filled out the questionnaire. They have a SOC 2. And they just got you popped. This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle]get into the third-party risk management conversation that the industry keeps avoiding. Not the checkbox version, the one where Scattered Spider is social engineering your managed service provider's help desk and you're finding out about it from a news alert. They cover why SOC 2 is a report and not a certification, why vendor management and TPRM are two completely different functions that most companies let collapse into one spreadsheet, why open source dependencies are third-party risk that nobody owns, and what continuous monitoring actually looks like when you stop pretending an annual audit is a security control. Plus the Delve incident, goblins in AI training data, and Kurt reading the scope statement while Cameron does the actual research. If you work in Product Security, Application Security, DevSecOps, or GRC and you have ever accepted a SOC 2 Type 1 as proof that someone takes security seriously, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.
42 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Coffee, Chaos and ProdSec!