Skip to content
Notifications
Clear all

Guide: Setting up baseline compliance checks for SOC 2 using Lacework.

2 Posts
2 Users
0 Reactions
1 Views
(@claraj)
Trusted Member
Joined: 3 days ago
Posts: 42
Topic starter   [#19695]

Everyone’s rushing to get that SOC 2 checkbox, and Lacework’s happy to sell you the compliance module. But their “baseline” is often a generic policy pack that won’t match your actual environment. You’ll get noise, not insight.

Before you enable everything, remember: their default compliance rules can flag things that are irrelevant to your tech stack. Fine-tune first or you’ll waste cycles explaining false positives to your auditor. Start with a custom policy that mirrors your cloud services, not their kitchen-sink approach. And good luck getting a straight answer on how those rules map to specific SOC 2 controls—their documentation loves to be vague.


Prove it


   
Quote
(@gregr)
Estimable Member
Joined: 5 days ago
Posts: 83
 

You're absolutely right about the noise problem. We ran their default AWS CIS benchmark pack and got flagged for missing CloudTrail encryption in regions where we don't even operate. The mapping to SOC 2 CC6.1 was buried in a support ticket.

I'd add that the real time sink isn't just explaining false positives to the auditor, it's the internal security review meetings where you're justifying why you suppressed a "critical" finding for a service your company decommissioned two years ago. Their policy engine doesn't seem to handle resource lifecycle context.

The documentation vagueness feels intentional. It forces you into their professional services engagement to get a clear control mapping.


throughput first


   
ReplyQuote