Apple Private Cloud Compute SoC 3 audit reports

(support.apple.com)

92 points | by throwfaraway4 6 hours ago ago

39 comments

  • arkadiyt 4 hours ago ago

    For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it.

    Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

    • Terretta 4 hours ago ago

      Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves.

      SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1).

      Both may also allow general lag time.

      Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they picked. Pick basic controls, it's cheaper to pass easily, and now you have a logo.

      This means SOC2s of either type cannot be compared to one another (and SOC2 Type 1 are roughly logo-ware).

      SOC3 is, roughly, SOC2 redacted.

      Recap:

      SOC2 Type 1 is a firm picking some controls to say they'll do them, SOC2 Type 2 is roughly a firm having someone look at whether they're doing that (warning, screenshots might suffice, audit verification is probably not what you think), and SOC3 is public or non-confidential water down of that, typically without findings.

      The only thing that matters is what controls, specifically, they're actually audited on. So ideally you want to know what the controls they picked are, and that a SOC2 Type 2 was audited on those.

      Btw, keep in mind that "end to end encryption" means "https" and most controls have similarly basic ways of achieving them. It's difficult to fail SOC2 Type 2 core controls if you know "don't be useless" is how you pass them.

      Also, it's not $50K even through the big five DIY SOC2 Type 2 shops. You can use the same ones trillion dollar firms use, by signing up online, and you'll be surprised how inexpensive relative to the cost of failing to let a business check that box in their procurement process.

      • michaelt an hour ago ago

        > SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1).

        Even with an external audit - think of how many projects and repositories and servers and libraries and legacy systems Apple, a 50-year-old company with 166,000 employees, could have.

        Then think about how much inspection is involved in a $50,000 audit. I doubt you get more than one inspector working full time for a year. In which case they've got 45 seconds of to audit each employee's entire work output. And places like EY will bill some people out at $700/hour, so it could be an order of magnitude less than that.

        So this isn't some fine-toothed-comb forensic investigation or adversarial penetration test.

        • tptacek an hour ago ago

          A $50k audit is going to be team of 2 CPAs collecting evidence for 2 weeks.

      • FinnKuhn 3 hours ago ago

        I think companies like Deel showed that SOC2 is more show than anything else.

        For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

        • nerdsniper 24 minutes ago ago

          Delve. Not Deel. Very different startups.

        • paulryanrogers 3 hours ago ago

          Hasn't Deel been run out of business though?

          IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.

          • nerdsniper 26 minutes ago ago

            I think both of you meant “Delve”, not “Deel”. Deel is a pretty successful HR startup that’s still growing at a good rate and AFAIK free of major scandals.

            Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.

            • paulryanrogers 21 minutes ago ago

              Right, Delve was the company I was thinking of. Thanks for pointing that out.

          • FinnKuhn 2 hours ago ago

            Their website is still up, but I have a hunch you can find some other certificate mill that will give you a SOC2 certificate just as easily.

        • a-priori 2 hours ago ago

          A SOC2's quality entirely depends on how much you trust the auditing firm.

          Delve used an audit mill they paid to rubber-stamp the cookie-cutter and AI slop reports it authored. I hope it ends up in fraud charges.

          But I wouldn't assume that's the case for all SOC2 reports. Any decent auditing firm should be far more rigorous.

          • FinnKuhn 2 hours ago ago

            These audits for Apple were done by EY.

            As a German I remember that they were banned from doing certain audits in Germany until earlier this year due to their involvement in the wirecard scandal. So at least my personal believe that their audits are done rigorously is nonexistent.

            https://edition.cnn.com/2023/04/03/business/wirecard-ey-ban-...

          • tptacek 2 hours ago ago

            Not really. The more expensive the auditor, the more they'll work with you to craft something that will avoid exceptions. There's no real "rigor" involved in SOC2! The "audit" here is in audit in the accounting sense: "do your records square up?". SOC2 auditors are generally not technical people.

      • tptacek 2 hours ago ago

        Literally any firm can get a SOC2 Type 1, because there's no lookback to it; the Type 1 is a pinky swear.

        In practice, if you're careful about how you do your Type 1, the Type 2 is almost as trivial. Your HR/bizops practice is much more likely to screw up and cause exceptions than anything you do in IT or engineering.

      • deepsun 3 hours ago ago

        Well you "claiming controls" to an independent CPA auditor. If a licensed CPA helps you lie -- they might lose their license (and can even get to prison), just like a tax preparer CPA can.

    • tptacek an hour ago ago

      (Specifically: the SOC3 is a public report; the SOC2 report generally isn't supposed to be handed out except to named clients under contract. You pay extra to get the auditors to give you a report you can just stick on a website.)

    • shye 3 hours ago ago

      Last I chatted with some friends who were going through their first SOC2, they quoted a much lower number.

      • sethhochberg 2 hours ago ago

        The details people gloss over when throwing SOC 2 or whatever other audit costs around are the complexity of the system being audited, the chosen criteria to audit (AICPA defines 5 families of criteria... Security is one, but you can optionally add Processing Integrity, Confidentiality, etc etc) and the reputation of the auditor.

        A security-only audit for a small company with a narrow product focus can indeed be very inexpensive. A full SOC 2 examination for a large organization with a mix of legacy and modern systems by a name-recognizable public accounting firm can be many hundreds of thousands of dollars, or more if you need a Big 4 firm.

        In my opinion, there's not much value to the "cheap" audits... If you're doing enterprise sales to a certain kind of client, your partners who demand an audit are going to want a reputable auditor or they're just going to put you through their own in-depth procurement due diligence regardless. The segment of the industry where a SOC 2 attestation is mandatory to participate but where any random auditor will do feels pretty narrow.

        • tptacek an hour ago ago

          Unless you have a very good reason (I compare notes with people at dozens of firms and have never heard one), the only criteria you ever want to get SOC2'd on is Security.

          My experience is the opposite of yours: having a security SOC2 ends the vendorsec process it any enterprise buyer, and enterprise buyers virtually never read anything in the SOC2 other than a glance at the exceptions. A very large, very security-intensive vendor we have all heard of told me a story about a vendor they had that gave them several years of repeated Type 1 reports. Went fine.

      • tptacek 2 hours ago ago

        You can get a SOC2 done for mid to mid-high thousands.

    • datakan 4 hours ago ago

      Everyone lies on SOC2. Auditors don't understand the technologies and just take peoples word for it. It's a shit practice

      • paulryanrogers 3 hours ago ago

        Citation needed. This is not my experience at all, after participating in such efforts at three different companies.

        • tptacek 2 hours ago ago

          I wouldn't put it the way they did but they're directionally sane about this. I would worry a lot more about someone repping their SOC2 as important or meaningful than I would worry about someone who was cynical about SOC2.

          (I don't mean Apple; Apple spends more on security than almost any firm in the world.)

          https://fly.io/blog/soc2-the-screenshots-will-continue-until...

        • datakan 3 hours ago ago

          I'll just cite my 30 years in IT/InfoSec. Believe it or not, I really don't give a damn. It's common knowledge int he field regardless of what your experience is.

    • deepsun 3 hours ago ago

      > "look I can afford 50k"

      Oh no. Looks like you never went through SOC2.

      1. No, it does not require 50k, an auditor can cost way less (10k? maybe even less).

      2. But the process of preparing for the audit will take a lot of work securing your systems (and increasing reliability and privacy as well), as long as you take it seriously. Of course you can lie to the auditor, but it's up on you. And auditor -- they might lose their CPA license and go to prison. Their job is to catch your lies.

      Source -- went through it, and took it seriously. It really did increase our security stance, even though we thought we were good at it.

      • bayesnet 3 hours ago ago

        That auditors are responsible for catching the lies of an audited company on penalty of being suspended is a position that the big audit firms would not agree with. They might agree that they are responsible for ensuring the material accuracy of accounts if fraud occurs, but even here EY has disclaimed responsibility if the fraud were sufficiently complex [0]. Indeed auditors lobbied very hard against being mandated with a broader anti-fraud role [1].

        Admittedly this is on the "real" audit side and not the advisory/consulting side, which would be the ones to handle SOC I imagine, but nonetheless a position I find a bit absurd.

        [0]: https://www.ft.com/content/a9deb987-df70-4a72-bd41-47ed8942e...? [1]: https://www.ft.com/content/c25de9fb-a808-4946-ade6-80d76a66a...

        • FireBeyond 2 hours ago ago

          > Admittedly this is on the "real" audit side and not the advisory/consulting side, which would be the ones to handle SOC I imagine, but nonetheless a position I find a bit absurd.

          I mean, it's not like the supposed "Chinese wall" at the Big 4 has ever been accused of being "illusory" on multiple occasions.

      • tptacek 2 hours ago ago

        I co-ran a business with a significant SOC2 practice (we ran security programs for startups), and then oversaw Fly.io's SOC2 Type 2. The person you're responding to is more right than you are, and I would push back in a variety of ways on your point (2).

  • dzonga 22 minutes ago ago

    can someone correct me - so apple is using servers that are running a closed down version of iOS on what I would assume is apple silicone, probably excess chips or older chips for the iCloud Private Cloud ?

  • ProAm 8 minutes ago ago

    Every audit is a cooked book audit. At least every single one Ive been a part of. Check mark tests.

  • bstsb 4 hours ago ago

    the page keeps 301ing to the home page for me - could be a region issue

    https://archive.ph/JYC9B

    • fuomag9 21 minutes ago ago

      Same in Italy

    • rogerrogerr 4 hours ago ago

      Works for me on a major US cell network.

  • Havoc 4 hours ago ago

    I'm glad they're doing them.

    Audits are decidedly imperfect, but on balance people tend to toe the line better on good practices when they know they're being audited.

  • qurren 4 hours ago ago

    I thought they were working on M5 already? Why are they still auditing M3?