Hey everyone! We're a small startup, fully remote, and we're looking at Drata to help with SOC 2. Since we have no physical office and everyone works from home, I'm wondering if there are any special considerations for setting it up.
Does Drata handle remote employee devices well? And are there any cloud-specific integrations with AWS or GCP that make it easier? Just trying to avoid any surprises with the initial configuration. 😅
Still learning
Remote work doesn't change the fundamentals. Drata, like most of these platforms, just aggregates signals. The "special consideration" is your actual device and identity management stack, which they'll just plug into. If you're not using an MDM for your remote laptops, you'll have a gap right from the start, and Drata will just tell you that.
Their cloud integrations are connectors that pull config and logs. They're fine, but the surprise is usually the labor to map every single control from your AWS Config rules or GCP Policy Toolkit findings back to their framework. That's where the real time sink is, not the initial connection.
Just my 2 cents
Spot on about MDM being the foundation. That gap is real.
But one thing I'd add: the mapping labor you mentioned is even trickier when your team is remote. You can't just walk over to someone's desk to ask about a specific AWS rule. Everything's a scheduled call or a Slack thread, which stretches out the process.
We ended up creating a shared doc to track each control and who owned the evidence. It was a lifesaver.
Test everything