Sonia Notes
92 subscribers
99 photos
1 video
10 files
142 links
Download Telegram
SOC 2 engagement
An examination engagement to report on the fairness of the presentation of
management’s description of the service organization’s system, the suitability of the design of
the controls included in the description, and, in a type 2 engagement, the operating effectiveness
of those controls. This engagement is performed in accordance with the attestation standards and
AICPA Guide SOC 2® Reporting on an Examination of Controls at a Service Organization: Rel-
evant to Security, Availability, Processing Integrity, Confidentiality, or Privacy.

SOC 3 engagement
An examination engagement to report on the suitability of design and the oper-
ating effectiveness of an entity’s controls over a system relevant to one or more of the trust ser-
vices categories.

SOC for Cybersecurity examination
An examination engagement to report on whether (a) man-
agement’s description of the entity’s cybersecurity risk management program is presented in ac-
cordance with the description criteria and (b) the controls within that program were effective to
achieve the entity’s cybersecurity objectives based on the control criteria. A SOC for Cybersecu-
rity examination is performed in accordance with the attestation standards and AICPA Guide
Reporting on an Entity's Cybersecurity Risk Management Program and Controls.

SOC for Supply Chain examination
An examination engagement to report on whether (a) the de-
scription of the entity’s system is presented in accordance with the description criteria and (b) the
controls stated in the description, which are necessary to provide reasonable assurance that the
entity achieved its principal system objectives, were effective based on the applicable trust ser-
vices criteria. Such an examination is based on guidance contained in AICPA Guide SOC for
Supply Chain: Reporting on an Examination of Controls Relevant to Security, Availability, Pro-
cessing Integrity, Confidentiality, or Privacy in a Production, Manufacturing, or Distribution
System.
The AICPA’s Assurance Services Executive Committee (ASEC), through its Trust Information Integrity
Task Force’s SOC 2 Working Group, has developed a set of benchmarks, known as description criteria,
to be used when preparing and evaluating the description of the service organization’s system (descrip-
tion) in an examination of a service organization’s controls over security, availability, processing integ-
rity, confidentiality, or privacy (SOC 2 examination). This document presents the description criteria for
use in that examination. (This document does not address the AICPA’s trust services criteria, fn 3 which
are used in a SOC 2 examination to evaluate whether controls stated in the description were suitably de-
signed and operated effectively to provide reasonable assurance that the service organization’s service
commitments and system requirements were achieved based on the applicable trust services criteria.)
AICPA revises guidance on applying
its Trust Services Criteria and SOC 2

Key considerations

Revisions to the Trust Services Criteria guidance
While the AICPA didn’t change the criteria in the TSC, it added new points of focus and clarified
existing points of focus that address the evaluation of whether controls are suitably designed
and operating effectively to achieve the entity’s service commitments and system requirements.
The AICPA said the revised points of focus are intended “to better support application of the
criteria” in an environment of ever-changing threats and vulnerabilities; new technologies;
legal, regulatory and cultural expectations regarding privacy; and changing expectations
regarding data management and confidentiality. The revisions also provide guidance on topics
that entities have struggled with, such as which privacy points of focus apply to data controllers
and which ones apply to data processors.
Service organizations should consider whether and how their controls address the clarifications
and new points of focus. In evaluating the new guidance, organizations should pay particular
attention to the following changes:

Types of relevant information — New points of focus clarify that the types of information
relevant to systems of internal control include information about data flow, asset
inventory and location, information classification, and the completeness and accuracy of
information used in the system.

Risk assessment — The revised points of focus on risk assessment provide users with a
more granular approach to evaluating risks by understanding the underlying components
of risk assessment: threat and vulnerability identification and the evaluation of the
likelihood and magnitude of a threat event intersecting with a vulnerability. The revised
points of focus also include the consideration of residual risk after considering internal
controls and management’s decisions to accept, reduce or share risks.

Monitoring activities — The revised points of focus encourage service organizations to
consider activities performed by the first and second lines of defense (i.e., monitoring
performed by the people who perform a function and monitoring performed by managers
who oversee them, respectively) in addition to internal audit functions and other recurring
information technology (IT) assessments many service organizations have historically
identified in their SOC 2 reports.

Logical access — Modified points of focus encourage consideration of logical access controls
across the system architecture, including all relevant infrastructure, IT tools, and types of
access, such as employee, contractor, vendor, business partner, system and service accounts.
In addition, recovery of devices, such as laptops, is now considered in the points of focus.
2 | To the Point AICPA revises guidance on applying its Trust Services Criteria and SOC 2 Description Criteria 2 November 2022

Change management — Two new points of focus have been added to address change
management. The first relates to the identification, testing and implementation of
software patches. The second addresses the consideration of resilience requirements
during the change management process if a SOC 2 report addresses system availability.

Availability — Given the increase in ransomware attacks, a new point of focus was added on
management’s identification of threats to data recoverability and mitigation procedures.

Privacy — A number of points of focus were revised to better align with widely used
privacy practices.
The AICPA also emphasized that the applicability of any particular point of focus depends on
the facts and circumstances and that the points of focus provided are unlikely to be exhaustive
for most service organizations. Consequently, use of the TSC does not require that every
point of focus be met. However, a service organization should consider the applicability of the
new points of focus and whether other points of focus also need to be met to achieve their
service commitments and system requirements.
#TODO: snapshot cron
P10.pdf
241.5 KB
The Power of Ten –
Rules for Developing Safety Critical Code

NASA/JPL Laboratory for Reliable Software
🔥1
1. Migrate to Proxmox VE https://pve.proxmox.com/wiki/Migrate_to_Proxmox_VE
2. smartmontools homepage https://www.smartmontools.org
3. OpenZFS dRAID https://openzfs.github.io/openzfs-docs/Basic%20Concepts/dRAID%20Howto.html
4. Systems installed with Proxmox VE 6.4 or later, EFI systems installed with Proxmox VE 5.4 or later
5. https://bugzilla.proxmox.com/show_bug.cgi?id=2350
6. https://github.com/openzfs/zfs/issues/11688
7. acme.sh https://github.com/acmesh-official/acme.sh
8. These are all installs with root on ext4 or xfs and installs with root on ZFS on non-EFI systems
9. Booting ZFS on root with GRUB https://openzfs.github.io/openzfs-docs/Getting%20Started/Debian/Debian%20Bookworm%20Root%20on%20ZFS.html
10. GRUB Manual https://www.gnu.org/software/grub/manual/grub/grub.html
11. Systems using proxmox-boot-tool will call proxmox-boot-tool refresh upon update-grub.
12. votequorum_qdevice_master_wins manual page https://manpages.debian.org/stable/libvotequorum-dev/votequorum_qdevice_master_wins.3.en.html
13. token_coefficient in the corosync manual page https://manpages.debian.org/stable/corosync/corosync.conf.5.en.html#token_coefficient
14. token in the corosync manual page https://manpages.debian.org/stable/corosync/corosync.conf.5.en.html#token
15. consensus in the corosync manual page https://manpages.debian.org/stable/corosync/corosync.conf.5.en.html#consensus
16. Ceph User Management
17. RBD configuration reference https://docs.ceph.com/en/tentacle/rbd/rbd-config-ref/
18. Ceph intro https://docs.ceph.com/en/tentacle/start/
19. Ceph architecture https://docs.ceph.com/en/tentacle/architecture/
20. Ceph glossary https://docs.ceph.com/en/tentacle/glossary
21. Full Mesh Network for Ceph https://pve.proxmox.com/wiki/Full_Mesh_Network_for_Ceph_Server
22. Ceph Monitor https://docs.ceph.com/en/tentacle/rados/configuration/mon-config-ref/
23. Ceph Manager https://docs.ceph.com/en/tentacle/mgr/
24. Ceph Bluestore https://ceph.com/community/new-luminous-bluestore/
25. Ceph config sources https://docs.ceph.com/en/latest/rados/configuration/ceph-conf/#config-sources
26. Ceph MON DB commands https://docs.ceph.com/en/latest/rados/configuration/ceph-conf/#commands
27. PG calculator https://web.archive.org/web/20210301111112/http://ceph.com/pgcalc/
28. Placement Groups https://docs.ceph.com/en/tentacle/rados/operations/placement-groups/
29. Automated Scaling https://docs.ceph.com/en/tentacle/rados/operations/placement-groups/#automated-scaling
30. Ceph pool operation https://docs.ceph.com/en/tentacle/rados/operations/pools/
31. Ceph Erasure Coded Pool Recovery https://docs.ceph.com/en/tentacle/rados/operations/erasure-code/#erasure-coded-pool-recovery
32. Ceph Erasure Code Profile https://docs.ceph.com/en/tentacle/rados/operations/erasure-code/#erasure-code-profiles
33. Ceph Erasure Code https://docs.ceph.com/en/tentacle/rados/operations/erasure-code/
34. https://ceph.com/assets/pdfs/weil-crush-sc06.pdf
35. CRUSH map https://docs.ceph.com/en/tentacle/rados/operations/crush-map/
36. Configuring multiple active MDS daemons https://docs.ceph.com/en/tentacle/cephfs/multimds/
37. Ceph scrubbing https://docs.ceph.com/en/tentacle/rados/configuration/osd-config-ref/#scrubbing
38. Ceph troubleshooting https://docs.ceph.com/en/tentacle/rados/troubleshooting/
39. Ceph log and debugging https://docs.ceph.com/en/tentacle/rados/troubleshooting/log-and-debug/
40. See this benchmark on the KVM wiki https://www.linux-kvm.org/page/Using_VirtIO_NIC
41. See this benchmark for details https://events.static.linuxfound.org/sites/events/files/slides/CloudOpen2013_Khoa_Huynh_v3.pdf
42. TRIM, UNMAP, and discard https://en.wikipedia.org/wiki/Trim_%28computing%29
43. Meltdown Attack https://meltdownattack.com/
44. spectre-meltdown-checker https://meltdown.ovh/
45. PCID is now a critical performance/security feature on x86 https://groups.google.com/forum/m/#!topic/mechanical-sympathy/L9mHTbeQLNU
46. https://en.wikipedia.org/wiki/Non-uniform_memory_access
47. if the command numactl --hardware | grep available returns more than one node, then your host system has a NUMA architecture
48. A good explanation of the inner workings of the balloon driver can be found here https://rwmj.wordpress.com/2010/07/17/virtio-balloon/
49. https://www.kraxel.org/blog/2014/10/qemu-using-cirrus-considered-harmful/ qemu: using cirrus considered harmful
50. See the OVMF Project https://github.com/tianocore/tianocore.github.io/wiki/OVMF
51. Alex Williamson has a good blog entry about this https://vfio.blogspot.co.at/2014/08/primary-graphics-assignment-without-vga.html
52. Microsoft support article about the issue https://support.microsoft.com/en-us/topic/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e
53. Looking Glass: https://looking-glass.io/
54. Official vmgenid Specification https://docs.microsoft.com/en-us/windows/desktop/hyperv_v2/virtual-machine-generation-identifier
55. Online GUID generator http://guid.one/
56. https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/virtualized-domain-controller-architecture
57. this includes all newest major versions of container templates shipped by Proxmox VE
58. for example Alpine Linux
59. /etc/os-release replaces the multitude of per-distribution release files https://manpages.debian.org/stable/systemd/os-release.5.en.html
60. AppId https://developers.yubico.com/U2F/App_ID.html
61. Multi-facet apps: https://developers.yubico.com/U2F/App_ID.html
62. Lempel–Ziv–Oberhumer a lossless data compression algorithm https://en.wikipedia.org/wiki/Lempel-Ziv-Oberhumer
63. gzip - based on the DEFLATE algorithm https://en.wikipedia.org/wiki/Gzip
64. Zstandard a lossless data compression algorithm https://en.wikipedia.org/wiki/Zstandard
65. pigz - parallel implementation of gzip https://zlib.net/pigz/
66. see man 7 systemd.time for more information