Ask HN:您如何审计您的应用程序以确保合规性?
2 分•作者: Luxter•12 天前
像Vanta、Drata等合规性软件只能读取第三方API(如AWS、Github、Okta等),但无法自动审计实际使用这些API的应用程序,例如在特定时间点谁拥有应用程序的管理员访问权限。
我是一名在波兰的工程师,没有合规背景。因此,如果您过去曾为您的应用程序进行过审计(SOC 2 / ISO 27001 / HIPAA / PCI 等):
1. 您生成了什么(截图?SQL查询?CSV?)
2. 您公司里是谁做的?花了多长时间?这是一个经常性的任务吗?
3. 您是否在内部构建了任何工具来完成这项工作?您还在维护它吗?
如果您使用了某个工具来完成这项工作,我将非常感谢您告诉我具体是哪个工具。
查看原文
Compliance software like Vanta, Drata and similar only read 3rd party APIs (AWS, Github, Okta etc.) but cannot automatically audit your app that actually uses them, e.g. who had admin access in your app at given point in time.<p>I'm an engineer in Poland with no compliance background, so if you did an audit for your app in the past (SOC 2/ISO 27001/HIPAA/PCI etc.):<p>1. What did you produce (Screenshots? SQL query? CSV?)<p>2. Who did it in your company? How long did it take? Is it a recurring task?<p>3. Did you build anything in-house for it? Are you still maintaining it?<p>If you used a tool for that then I'd appreciate if you tell me which one.