SlideShare a Scribd company logo
1 of 24
Download to read offline
SOC 2 Intro and Mindfulness
Emily Gladstone Cole
PancakesCon 3
Who is this Emily Person Anyway
Background
Fun Facts
● UNIX SysAdmin/Operations/DevOps background
● Experience in Security Incident Response, Security Research,
Security Engineering
● Mentor for SANS’ Women’s CyberTalent Immersion Academy
● Opinionated about SOC 2
● Currently recovering from burnout
● My favorite computer game is Nethack
● Only one of the cats you will see here today is mine
My goofball cat
My pancakes of choice: latkes aka potato pancakes
Why SOC 2
1. SALES
2. Useful for SaaS companies when they
are ready for customers
3. Not as difficult to get as FedRAMP,
PCI, or HIPAA
4. SALES
SOC 2 Background
● SOC stands for System and Organization Controls
(formerly Service Organization Controls)
● The AICPA sets the standards for these reports:
they’re auditors and CPAs
● SOC 1 is all about a company’s financials
● SOC 2 is about a company’s security
SOC 2 is about COMPLIANCE, not SECURITY.
Key Vocabulary
Trust Services Criteria: formerly Trust Principles, the 5 areas you can get certified in
Policies: you need a set of policies that define how your company does security
Control Item: an individual thing you have to do to meet your Trust Services Criteria
Type 1 and Type 2: Type 1 is a point in time report. Type 2 shows that you meet the
requirements over a period of time.
Auditor: you have to have one. Remember this is a CPA and not a security person
Trust Services Criteria (formerly Trust Principles)
● Security (aka the Common Criteria, every SOC 2 cert includes it)
○ Access Control: protect against unauthorized access and disclosure
● Availability
○ systems are available as needed
● Processing Integrity
○ processing is complete, valid, accurate, and timely
● Confidentiality
○ information designated as Confidential is protected
● Privacy
○ personal information is only collected, stored, used, and disclosed as necessary
SOC 2 Simplified
1. Pick your Trust Services Criteria.
2. Make sure you do the things that you need to
meet your Control Items.
3. Write policies and processes that match what
you do.
4. Pick an Auditor.
5. Prove to the Auditor that you do what you say
you’re doing.
SOC 2 can help your security team
There are a few key things that you can do that will help your SOC 2 efforts and also
help security.
● Single Sign On: this will greatly simplify all of the Access Control requirements
● Centralized Logging: you need somewhere to examine your logs and alert based
on oddities.
● Protecting Production: set up protections around pushing code (Change
Management), and accessing production (Roles, not direct user access)
SOC 2 - can I automate that?
You can do all of the work of proving your policies are backed up by your actions by
hand. However, there are vendors that will allow you to automate much of the work of
tracking your progress and collecting evidence.
● A-Lign
● Drata
● Tugboat Logic
● Vanta
Opinions from a weary security/compliance person
1. Don’t try to use SOC 2 to build your security program. That’s not what it’s for.
2. Make sure your executives understand what they’re committing themselves and
the company to before you agree to work toward any compliance certification,
including SOC 2. If you hear any executive at your company say that they don’t
want to learn about Security, it’s a bad sign.
3. Start with only the Common Criteria (Security) for your first year, you can always
add on later, especially if you’re at a smaller startup. It’s much harder to reduce
the scope of your work after the fact.
4. Make friends with the SRE/infrastructure team. They will help you integrate
everything and get you your evidence.
Mindfulness
What Mindfulness Isn’t
Mindfulness is a tool to help you become more aware of your feelings and the world
around you. It won’t fix any problems, but it can reduce tension and help you relax.
“You cannot self-love your way
out of systemic oppression.”
- Ragen Chastain
Mindfulness is the basic human ability to be fully present, aware of where we
are and what we’re doing, and not overly reactive or overwhelmed by what’s
going on around us.
● Reducing tension
● Body awareness
A Quick Exercise: Shoulder Tension and Relaxing
1. Start in a neutral position with
your shoulders down.
2. Raise your shoulders up toward
your ears as high as you can.
3. Hold for 5 seconds.
4. Lower your shoulders back to
neutral.
A Quick Exercise: Breathing
1. Breathe in for 5 seconds.
2. Breathe out for 10 seconds.
3. Repeat.
Optionally, say a few words to as you inhale
and exhale, like “It’s OK… let it go.”
Peaceful Place
Progressive Tension/Relaxation
You work your way through the major muscle groups,
starting from your feet and moving up your body. Tense,
hold for 5 seconds, then relax.
Do this either when sitting with your feet flat on the
floor, or when lying in bed.
Other Ideas for Relaxing
● Animal Web Cams (I’m fond of the
Monterey Bay Aquarium Jelly
Cam)
● Mindfulness meditations on
YouTube (including ones with
profanity)
● An app for that: the Calm app
Next Steps with Mindfulness - Body Awareness
Tension in a specific part of
the body can be tied to a
specific emotional state or
mood.
Closing thoughts
Thank you!
References
● https://us.aicpa.org/content/dam/aicpa/interestareas/frc/assuranceadvisoryservices/downl
oadabledocuments/trust-services-criteria.pdf
● https://fractionalciso.com/soc-2-compliance-software-vendors/
● https://latacora.micro.blog/2020/03/12/the-soc-starting.html
● https://positivepsychology.com/history-of-mindfulness/
● https://www.mindful.org/meditation/mindfulness-getting-started/
● https://www.physiomed.ca/carrying-the-weight-of-the-world-why-our-emotions-cause-m
uscle-tension/
● https://www.montereybayaquarium.org/animals/live-cams
● Mindfulness with profanity: https://www.youtube.com/watch?v=92i5m3tV5XY
● Calm app: https://www.calm.com/
● https://www.painawaydevices.com/exercises-relieve-neck-shoulder-pain/
● https://www.pexels.com/search/cat/

More Related Content

What's hot

NIST CyberSecurity Framework: An Overview
NIST CyberSecurity Framework: An OverviewNIST CyberSecurity Framework: An Overview
NIST CyberSecurity Framework: An Overview
Tandhy Simanjuntak
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
PECB
 
A project approach to HIPAA
A project approach to HIPAAA project approach to HIPAA
A project approach to HIPAA
Daniel P Wallace
 

What's hot (20)

NIST Risk Management Framework (RMF)
NIST Risk Management Framework (RMF)NIST Risk Management Framework (RMF)
NIST Risk Management Framework (RMF)
 
Control Standards for Information Security
Control Standards for Information SecurityControl Standards for Information Security
Control Standards for Information Security
 
NIST Cybersecurity Framework 101
NIST Cybersecurity Framework 101  NIST Cybersecurity Framework 101
NIST Cybersecurity Framework 101
 
ISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process OverviewISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process Overview
 
Risk Management Framework (RMF) STEP 4- Access Security Controls - NIST SP 80...
Risk Management Framework (RMF) STEP 4- Access Security Controls - NIST SP 80...Risk Management Framework (RMF) STEP 4- Access Security Controls - NIST SP 80...
Risk Management Framework (RMF) STEP 4- Access Security Controls - NIST SP 80...
 
CRISC Course Preview
CRISC Course PreviewCRISC Course Preview
CRISC Course Preview
 
SOC 2: Build Trust and Confidence
SOC 2: Build Trust and ConfidenceSOC 2: Build Trust and Confidence
SOC 2: Build Trust and Confidence
 
NIST CyberSecurity Framework: An Overview
NIST CyberSecurity Framework: An OverviewNIST CyberSecurity Framework: An Overview
NIST CyberSecurity Framework: An Overview
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
 
Soc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organizationSoc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organization
 
Supply management 1.1.pdf
Supply management 1.1.pdfSupply management 1.1.pdf
Supply management 1.1.pdf
 
Basic introduction to iso27001
Basic introduction to iso27001Basic introduction to iso27001
Basic introduction to iso27001
 
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdfISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
 
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security ControlsSOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
 
A project approach to HIPAA
A project approach to HIPAAA project approach to HIPAA
A project approach to HIPAA
 
isms-presentation.ppt
isms-presentation.pptisms-presentation.ppt
isms-presentation.ppt
 
Cybersecurity roadmap : Global healthcare security architecture
Cybersecurity roadmap : Global healthcare security architectureCybersecurity roadmap : Global healthcare security architecture
Cybersecurity roadmap : Global healthcare security architecture
 
Infosec Audit Lecture_4
Infosec Audit Lecture_4Infosec Audit Lecture_4
Infosec Audit Lecture_4
 
Project plan for ISO 27001
Project plan for ISO 27001Project plan for ISO 27001
Project plan for ISO 27001
 

Similar to SOC2 Intro and Mindfulness

5-Human Performance Improvement-Why Is It Important.pptx
5-Human Performance Improvement-Why Is It Important.pptx5-Human Performance Improvement-Why Is It Important.pptx
5-Human Performance Improvement-Why Is It Important.pptx
alphazone47
 

Similar to SOC2 Intro and Mindfulness (20)

behavior based safety
behavior based safetybehavior based safety
behavior based safety
 
How Fast and Slow Thinking Helps in Agile
How Fast and Slow Thinking Helps in AgileHow Fast and Slow Thinking Helps in Agile
How Fast and Slow Thinking Helps in Agile
 
5-Human Performance Improvement-Why Is It Important.pptx
5-Human Performance Improvement-Why Is It Important.pptx5-Human Performance Improvement-Why Is It Important.pptx
5-Human Performance Improvement-Why Is It Important.pptx
 
10 Things an Operations Supervisor can do Today to Improve Reliability
10 Things an Operations Supervisor can do Today to Improve Reliability10 Things an Operations Supervisor can do Today to Improve Reliability
10 Things an Operations Supervisor can do Today to Improve Reliability
 
Great Learning & Information Security - English edition
Great Learning & Information Security - English editionGreat Learning & Information Security - English edition
Great Learning & Information Security - English edition
 
7 Must Follow Steps For Safe and Secured Workplace
7 Must Follow Steps For Safe and Secured Workplace7 Must Follow Steps For Safe and Secured Workplace
7 Must Follow Steps For Safe and Secured Workplace
 
Icinga camp ams 2016 icinga2
Icinga camp ams 2016 icinga2Icinga camp ams 2016 icinga2
Icinga camp ams 2016 icinga2
 
Icinga Camp Amsterdam - Monitoring – When to start
Icinga Camp Amsterdam - Monitoring – When to startIcinga Camp Amsterdam - Monitoring – When to start
Icinga Camp Amsterdam - Monitoring – When to start
 
Ooda loop Smart decision process model
Ooda loop   Smart decision process modelOoda loop   Smart decision process model
Ooda loop Smart decision process model
 
Monitoring - When To start (or Metrics led development)
Monitoring - When To start (or Metrics led development)Monitoring - When To start (or Metrics led development)
Monitoring - When To start (or Metrics led development)
 
Tri Net Wp Complete Rif Checklist
Tri Net Wp Complete Rif ChecklistTri Net Wp Complete Rif Checklist
Tri Net Wp Complete Rif Checklist
 
Product Agility: 3 fundamentals from the trenches
Product Agility: 3 fundamentals from the trenchesProduct Agility: 3 fundamentals from the trenches
Product Agility: 3 fundamentals from the trenches
 
Emergency Decision Making in Business
Emergency Decision Making in BusinessEmergency Decision Making in Business
Emergency Decision Making in Business
 
All about compliance mantra
All about compliance mantra All about compliance mantra
All about compliance mantra
 
Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck - CISSP Mentor Program Class Session 1Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck - CISSP Mentor Program Class Session 1
 
GrrCON 2018: Stop boiling the ocean!
GrrCON 2018: Stop boiling the ocean!GrrCON 2018: Stop boiling the ocean!
GrrCON 2018: Stop boiling the ocean!
 
Designing for Safety by Lyft Product Lead
Designing for Safety by Lyft Product LeadDesigning for Safety by Lyft Product Lead
Designing for Safety by Lyft Product Lead
 
11) HND_SEC_W11_Security Policies_111312.pdf
11) HND_SEC_W11_Security Policies_111312.pdf11) HND_SEC_W11_Security Policies_111312.pdf
11) HND_SEC_W11_Security Policies_111312.pdf
 
The Productive Entrepreneur
The Productive EntrepreneurThe Productive Entrepreneur
The Productive Entrepreneur
 
Modern agile devspace - 2017-10-14
Modern agile   devspace - 2017-10-14Modern agile   devspace - 2017-10-14
Modern agile devspace - 2017-10-14
 

More from EmilyGladstoneCole (6)

My AWS Access Key Nightmares... and Solutions
My AWS Access Key Nightmares... and SolutionsMy AWS Access Key Nightmares... and Solutions
My AWS Access Key Nightmares... and Solutions
 
Technically Compliant: the best kind of compliant
Technically Compliant: the best kind of compliantTechnically Compliant: the best kind of compliant
Technically Compliant: the best kind of compliant
 
Getting Started with AWS Security
Getting Started with AWS SecurityGetting Started with AWS Security
Getting Started with AWS Security
 
LISA18 - How to be your Security Team's Best Friend
LISA18 - How to be your Security Team's Best FriendLISA18 - How to be your Security Team's Best Friend
LISA18 - How to be your Security Team's Best Friend
 
Security and DevOps are Really Best Friends
Security and DevOps are Really Best FriendsSecurity and DevOps are Really Best Friends
Security and DevOps are Really Best Friends
 
How to be your Security Team's Best Friend
How to be your Security Team's Best FriendHow to be your Security Team's Best Friend
How to be your Security Team's Best Friend
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 

SOC2 Intro and Mindfulness

  • 1. SOC 2 Intro and Mindfulness Emily Gladstone Cole PancakesCon 3
  • 2. Who is this Emily Person Anyway Background Fun Facts ● UNIX SysAdmin/Operations/DevOps background ● Experience in Security Incident Response, Security Research, Security Engineering ● Mentor for SANS’ Women’s CyberTalent Immersion Academy ● Opinionated about SOC 2 ● Currently recovering from burnout ● My favorite computer game is Nethack ● Only one of the cats you will see here today is mine
  • 4. My pancakes of choice: latkes aka potato pancakes
  • 5. Why SOC 2 1. SALES 2. Useful for SaaS companies when they are ready for customers 3. Not as difficult to get as FedRAMP, PCI, or HIPAA 4. SALES
  • 6. SOC 2 Background ● SOC stands for System and Organization Controls (formerly Service Organization Controls) ● The AICPA sets the standards for these reports: they’re auditors and CPAs ● SOC 1 is all about a company’s financials ● SOC 2 is about a company’s security SOC 2 is about COMPLIANCE, not SECURITY.
  • 7. Key Vocabulary Trust Services Criteria: formerly Trust Principles, the 5 areas you can get certified in Policies: you need a set of policies that define how your company does security Control Item: an individual thing you have to do to meet your Trust Services Criteria Type 1 and Type 2: Type 1 is a point in time report. Type 2 shows that you meet the requirements over a period of time. Auditor: you have to have one. Remember this is a CPA and not a security person
  • 8. Trust Services Criteria (formerly Trust Principles) ● Security (aka the Common Criteria, every SOC 2 cert includes it) ○ Access Control: protect against unauthorized access and disclosure ● Availability ○ systems are available as needed ● Processing Integrity ○ processing is complete, valid, accurate, and timely ● Confidentiality ○ information designated as Confidential is protected ● Privacy ○ personal information is only collected, stored, used, and disclosed as necessary
  • 9. SOC 2 Simplified 1. Pick your Trust Services Criteria. 2. Make sure you do the things that you need to meet your Control Items. 3. Write policies and processes that match what you do. 4. Pick an Auditor. 5. Prove to the Auditor that you do what you say you’re doing.
  • 10. SOC 2 can help your security team There are a few key things that you can do that will help your SOC 2 efforts and also help security. ● Single Sign On: this will greatly simplify all of the Access Control requirements ● Centralized Logging: you need somewhere to examine your logs and alert based on oddities. ● Protecting Production: set up protections around pushing code (Change Management), and accessing production (Roles, not direct user access)
  • 11. SOC 2 - can I automate that? You can do all of the work of proving your policies are backed up by your actions by hand. However, there are vendors that will allow you to automate much of the work of tracking your progress and collecting evidence. ● A-Lign ● Drata ● Tugboat Logic ● Vanta
  • 12. Opinions from a weary security/compliance person 1. Don’t try to use SOC 2 to build your security program. That’s not what it’s for. 2. Make sure your executives understand what they’re committing themselves and the company to before you agree to work toward any compliance certification, including SOC 2. If you hear any executive at your company say that they don’t want to learn about Security, it’s a bad sign. 3. Start with only the Common Criteria (Security) for your first year, you can always add on later, especially if you’re at a smaller startup. It’s much harder to reduce the scope of your work after the fact. 4. Make friends with the SRE/infrastructure team. They will help you integrate everything and get you your evidence.
  • 14. What Mindfulness Isn’t Mindfulness is a tool to help you become more aware of your feelings and the world around you. It won’t fix any problems, but it can reduce tension and help you relax. “You cannot self-love your way out of systemic oppression.” - Ragen Chastain
  • 15. Mindfulness is the basic human ability to be fully present, aware of where we are and what we’re doing, and not overly reactive or overwhelmed by what’s going on around us. ● Reducing tension ● Body awareness
  • 16. A Quick Exercise: Shoulder Tension and Relaxing 1. Start in a neutral position with your shoulders down. 2. Raise your shoulders up toward your ears as high as you can. 3. Hold for 5 seconds. 4. Lower your shoulders back to neutral.
  • 17. A Quick Exercise: Breathing 1. Breathe in for 5 seconds. 2. Breathe out for 10 seconds. 3. Repeat. Optionally, say a few words to as you inhale and exhale, like “It’s OK… let it go.”
  • 19. Progressive Tension/Relaxation You work your way through the major muscle groups, starting from your feet and moving up your body. Tense, hold for 5 seconds, then relax. Do this either when sitting with your feet flat on the floor, or when lying in bed.
  • 20. Other Ideas for Relaxing ● Animal Web Cams (I’m fond of the Monterey Bay Aquarium Jelly Cam) ● Mindfulness meditations on YouTube (including ones with profanity) ● An app for that: the Calm app
  • 21. Next Steps with Mindfulness - Body Awareness Tension in a specific part of the body can be tied to a specific emotional state or mood.
  • 24. References ● https://us.aicpa.org/content/dam/aicpa/interestareas/frc/assuranceadvisoryservices/downl oadabledocuments/trust-services-criteria.pdf ● https://fractionalciso.com/soc-2-compliance-software-vendors/ ● https://latacora.micro.blog/2020/03/12/the-soc-starting.html ● https://positivepsychology.com/history-of-mindfulness/ ● https://www.mindful.org/meditation/mindfulness-getting-started/ ● https://www.physiomed.ca/carrying-the-weight-of-the-world-why-our-emotions-cause-m uscle-tension/ ● https://www.montereybayaquarium.org/animals/live-cams ● Mindfulness with profanity: https://www.youtube.com/watch?v=92i5m3tV5XY ● Calm app: https://www.calm.com/ ● https://www.painawaydevices.com/exercises-relieve-neck-shoulder-pain/ ● https://www.pexels.com/search/cat/