Blaze Blog /

O guia completo do comprador para testes de penetração SOC 2

Guides
Jan 30, 2023
13min read
Imagem de uma bússola antiga
Loading the Elevenlabs Text to Speech AudioNative Player...

Aprenda tudo sobre pentest de conformidade com nosso guia do comprador para testes de intrusão SOC 2 e tome decisões mais bem fundamentadas na sua próxima avaliação.

Organizações de serviços que lidam com dados confidenciais estão frequentemente sujeitas a requisitos rigorosos de conformidade, sendo o SOC 2 um deles. Para alcançar e manter a conformidade SOC 2, as organizações devem passar por um processo de preparação rigoroso e, por vezes, demorado, além de uma auditoria de terceiros sobre seus procedimentos de segurança.

Critérios de Serviços de Confiança do AICPA as seções CC 4.1 e CC 7.1 aconselham as organizações a considerar avaliações técnicas como parte do processo, tornando o pentest um componente importante dos controles de segurança do SOC 2.

A ideia de criar este guia surgiu da percepção de que muitas organizações que trabalharam conosco no passado se viram, em algum momento, na situação de precisar realizar testes de intrusão como parte de sua auditoria SOC 2, mas tiveram dificuldade em encontrar orientações informativas e precisas.

Este guia tenta responder às perguntas mais frequentes relacionadas ao SOC 2 e testes de intrusão que coletamos dessas interações, ajudando os compradores a tomar uma decisão mais informada ao contratar serviços e escolher uma empresa de cibersegurança para apoiar seus objetivos de conformidade.

Quem se beneficiará deste guia de testes de intrusão SOC 2?

Este guia destina-se a organizações e tomadores de decisão encarregados de contratar serviços de teste de intrusão como parte de sua conformidade SOC 2 e que precisam atender aos requisitos de clientes, parceiros e auditores em relação aos padrões de cibersegurança.

Criamos este guia para trazer informações relevantes sobre o tema de testes de intrusão para auditorias SOC 2 para líderes dos seguintes públicos:

  • Executivos responsáveis pela segurança de TI em uma organização (CISO, VP de segurança, CIO)
  • Alta gestão, como executivos de nível C (CEO, CTO, COO, CFO)
  • Membros seniores de uma equipe de auditoria e comitês de auditoria
  • Gerentes de conformidade
  • Engenheiros e analistas de cibersegurança (AppSec, SecOps, InfraSec, etc.)
  • Gerentes de engenharia e proprietários de produto

O que é a conformidade SOC 2 e por que ela é importante?

A conformidade SOC 2 refere-se aos padrões que as organizações devem cumprir para garantir controles adequados na proteção de dados confidenciais. A estrutura inclui cinco princípios:

  • Segurança
  • Disponibilidade
  • Confidencialidade
  • Privacidade
  • Integridade do processamento
SOC 2 criteria

As organizações devem implementar os controles adequados para atender a esses princípios e estarem em conformidade.

A estrutura SOC 2 foi desenvolvido pelo American Institute of Certified Public Accountants (AICPA), fornecendo um conjunto abrangente de diretrizes para empresas que lidam com informações confidenciais. Para estar em conformidade com a norma SOC 2, uma organização deve passar por um rigoroso processo de auditoria e demonstrar que possui controles adequados para proteger efetivamente os dados dos clientes e outras informações sensíveis que possa manipular.

A conformidade com a SOC 2 tornou-se cada vez mais importante nos últimos anos, à medida que as violações de dados continuam a aumentar. Muitas organizações agora exigem que seus prestadores de serviços estejam em conformidade com a SOC 2 para proteger os dados de seus clientes. Embora alcançar essa conformidade possa ser um desafio, é essencial para qualquer empresa que lide com informações confidenciais, especialmente para empresas de SaaS que operam na nuvem.

Ao atender aos mais altos padrões de segurança, integridade, privacidade e confidencialidade, as organizações em conformidade com a SOC 2 oferecem aos seus clientes a tranquilidade de saber que seus dados são tratados com segurança, respaldados por inúmeros procedimentos e pelas melhores práticas do setor.

O que é teste de penetração SOC 2?

Um teste de penetração, frequentemente chamado de pentest ou hacking ético, é um tipo de teste de segurança usado para avaliar a segurança de um sistema, aplicação, rede, nuvem ou de uma empresa inteira por meio da realização de um ataque simulado.

Uma avaliação de pentest pode ser conduzida usando diversas abordagens, cada uma levando em consideração um ponto de vista diferente:

  • Black-box: No teste black-box, o pentester não tem conhecimento prévio do sistema ou da aplicação em teste. As vulnerabilidades de segurança são identificadas do ponto de vista de um invasor externo completo.
  • Gray-box: Este tipo de teste é uma combinação dos testes black-box e white-box. No teste gray-box, o testador possui um conhecimento limitado do sistema ou da aplicação em teste. Isso pode incluir informações de alto nível sobre a arquitetura do sistema, fluxos de dados e credenciais de teste. Não é fornecido acesso ao código-fonte.
  • White-box: Nesta abordagem, o engenheiro de segurança tem acesso completo ao código-fonte, aos projetos e ao design do sistema em teste. Isso permite que o pentester identifique vulnerabilidades de segurança que podem não ser aparentes ao observar o comportamento do sistema a partir de uma perspectiva externa.

A maioria das empresas profissionais de pentesting desaconselha uma perspectiva puramente black-box. Às vezes, os sistemas são difíceis de invadir por fora, mas com acesso autenticado, mesmo em um nível básico de permissão, a segurança pode estar muito abaixo do ideal. Nossa experiência mostra que o teste gray-box é a abordagem preferida para a maioria das Testes de intrusão SOC 2 projetos.

Os testes de intrusão podem ser aprimorados com o uso de ferramentas automatizadas, mas profissionais qualificados vão além da automação e realizam testes manuais. Embora exijam mais esforço, eles frequentemente encontram vulnerabilidades de segurança ocultas que ferramentas automatizadas deixariam passar. A automação é adequada para tarefas rotineiras, como a varredura de portas abertas ou a busca por vulnerabilidades conhecidas. Ainda assim, o pentest automatizado ainda não está pronto para substituir um hacker ético experiente, devidamente treinado na identificação de vulnerabilidades e riscos.

O escopo de um teste de intrusão é geralmente definido pelo cliente. O cliente especificará quais sistemas ou aplicações devem ser avaliados e quais tipos de testes serão realizados.

É importante ressaltar que, no contexto da conformidade SOC 2, não existem diferenças significativas em relação ao pentest para outros fins ou requisitos de conformidade.

Testes de intrusão e varredura de vulnerabilidades são obrigatórios para a conformidade SOC 2?

A resposta é simples: o teste de intrusão não é obrigatório para obter a conformidade SOC 2. Incluí-lo ou não em sua avaliação é uma decisão que deve ser tomada com base nas necessidades específicas, no perfil de ameaças e no apetite ao risco da sua organização.

No entanto, as seções dos Critérios de Serviços de Confiança (Trust Services Criteria) CC 4.1 e CC 7.1 do AICPA recomendam que as empresas em processo de certificação SOC 2 considerem diversos tipos de avaliações de cibersegurança, como pentest e varredura de vulnerabilidades:

  • Princípio 16 do COSO: "A entidade seleciona, desenvolve e realiza avaliações contínuas e/ou separadas para verificar se os componentes do controle interno estão presentes e em funcionamento."
  • CC4.1 ponto de foco – "A gestão utiliza uma variedade de diferentes tipos de avaliações contínuas e separadas, incluindo testes de intrusão, certificações independentes feitas com base em especificações estabelecidas (por exemplo, certificações ISO) e avaliações de auditoria interna."
  • CC7.1: "Para atingir seus objetivos, a entidade utiliza procedimentos de detecção e monitoramento para identificar (1) alterações nas configurações que resultam na introdução de novas vulnerabilidades e (2) suscetibilidades a vulnerabilidades recém-descobertas"
  • Ponto de foco CC7.1: "Realiza Varreduras de Vulnerabilidade — A entidade realiza varreduras de vulnerabilidade projetadas para identificar potenciais vulnerabilidades ou configurações incorretas periodicamente e após qualquer mudança significativa no ambiente, e toma medidas para remediar as deficiências identificadas de forma oportuna"

Diversas organizações e auditores consideram que testes de intrusão e varreduras regulares de vulnerabilidade podem complementar a auditoria e atender às necessidades de conformidade, com o benefício adicional de um passo extra para aumentar suas defesas cibernéticas.

Se você decidir incluir testes de intrusão em sua avaliação SOC 2 tipo I ou tipo II, há algumas coisas a se ter em mente:

  1. Certifique-se de trabalhar com um provedor de cibersegurança respeitável e experiente.
  2. Crie um escopo apropriado para o tamanho e o perfil de risco da sua organização.
  3. Esteja preparado para tratar prontamente quaisquer fraquezas identificadas durante o processo de teste de segurança.

Escrevemos uma postagem extensa em nosso blog sobre o tópico de SOC 2 vulnerability scanning and penetration testing requirements if you are interested in reading more.

Penetration testing vs. vulnerability scanning in the context of SOC 2

Penetration testing and vulnerability scanning are essential tools for managing cybersecurity risk, as they can help identify security weaknesses in systems and networks. However, there are critical differences between the two approaches.

Vulnerability scanning is typically automated, while penetration testing is usually manual. Vulnerability scanners can be run frequently to look for new security weaknesses, while penetration tests are typically only conducted occasionally. Scanners identify potential security issues that follow a repeatable pattern, while pentesting involves exploiting vulnerabilities to gain access to systems or data.

In general, penetration testing is more comprehensive and sophisticated than vulnerability scanning. However, both techniques can help manage cybersecurity risk. Organizations should use a combination of penetration testing and automated scanning to get the best possible picture of their security posture.

It is essential to know that less reputable cybersecurity firms may offer automated vulnerability scanning disguised as penetration testing. You must understand the difference between the two and ensure you get the correct service to help with your compliance goals. A "too good to be true" pricing structure may hint at this practice.

What are the benefits of performing penetration testing for SOC 2 compliance?

Despite not being required for SOC 2, pentests can be helpful for various reasons beyond simply being compliant with a security framework.

A thorough pentest assessment can provide valuable insights into an organization's cybersecurity posture. A pentest can help identify weaknesses in an organization's defenses by simulating an attack. As a result, pentests can play an essential role in helping organizations to improve their cybersecurity, comply with regulatory compliance requirements and satisfy vendor risk assessments.

How to define the scope of a SOC 2 penetration test?

The scope of a pentest outlines the boundaries of the engagement, which often entails a list of assets the pentesting team is allowed to attack while excluding assets that are not supposed to be attacked.

Undoubtedly, defining the scope of a penetration test can be a tricky process. After all, the whole point of a pentest is to find vulnerabilities that an attacker could exploit. As such, it's vital to ensure that the scope of the test is broad enough to identify potential threats but not so broad that it becomes hard to manage or cost-prohibitive.

From our experience, organizations undergoing SOC 2 compliance usually have the following in mind for their pentest scope:

  • The company's flagship product, user-facing SaaS platform
  • APIs (REST, GraphQL) and microservices
  • Security testing of mobile apps, if applicable
  • Any administrative panel or back office behind the user-facing SaaS
  • Internet-facing server infrastructure (usually cloud-hosted)
  • The company's internal network, servers, key infrastructure such as Active Directory, Kubernetes clusters, etc.

Organizations frequently perform pentests in a staging environment to avoid any potential disruption to production a pentest might cause. As long as your staging environment is close to production, this is an acceptable and popular approach. Nevertheless, before engaging a pentest, it is advisable to ask your SOC 2 auditor if they feel this approach is acceptable.

What security testing methodologies suit a SOC 2 pentest?

The methodology used will depend on the specific goals of the test. With the added factor that SOC 2 does not define exact guidelines for penetration testing and the procedures that should be used, it is often left open to interpretation.

However, a few standard methodologies are often used in SOC 2 penetration testing. One of the most popular is the OWASP Top 10. This methodology focuses on the most common web, API, mobile, and even IoT security risks, making it a perfect choice for organizations looking to identify and address potential threats. Combining OWASP Top 10 with OWASP Testing Guide should satisfy nearly all pentest requirements for SOC 2 audits.

Pentest methodologies

Other popular methodologies include SANS 25, OSSTMM, and PTES, which go beyond application security but include network security too. Finally, the NIST 800-115 methodology can also be used in compliance pentests. This methodology focuses on identifying and assessing risk, making it a good choice for organizations that want a comprehensive view of their security posture.

How long does a SOC 2 penetration test assessment take?

The duration of an average SOC 2 pentest engagement is between 5 to 25 person days, depending on the scope of the assessment.

A pentest of a single website or web application might take a few days only. In contrast, a comprehensive pentest of an extensive network or a complex SaaS platform could take several weeks. Most pentests, especially for SaaS companies, can be completed within a little over a week or two but can exceed this estimate when a larger scope is defined.

Buyers should be suspicious of providers offering "express" pentests that only last one, two, or three days. These "pentests" are most likely performed almost exclusively using automated scanners, or at best, they blindly follow a basic pentest checklist without any adversarial mindset or creativity. In such situations, there's a good chance subtle vulnerabilities, especially those pertaining to an application's business logic, were missed.

A good rule of thumb is that any pentest for SOC 2 performed under 40 hours for a small to medium-sized scope means there was not enough time for a pentester to manually inspect your systems and turn over every stone as it should.

How much does SOC 2 penetration testing cost?

On average, the price of a penetration test assessment for SOC 2 performed by a reputable and accredited cybersecurity firm will fluctuate between $8,000 and $25,000. However, the cost of a SOC 2 penetration test can vary depending on the scope size and complexity.

In some cases, the cost may be even higher if the organization requires a more comprehensive assessment or lower for a small scope. Many reputable pentest providers start at a ballpark figure of $250 to $300 per hour – with niche and specialized work, such as product security assessments or reverse engineering, having a higher hourly price tag (but these are rarely in scope for SOC 2 pentests).

Buyers should be suspicious of providers charging dramatically low prices: most likely, they perform the bulk of the work using automated scanners, which often yield false positives and miss high-risk issues or have unqualified staff to deliver pentest assessments.

While these low-quality pentest reports may sometimes be sufficient to satisfy an auditor, they bring a false sense of security. They can leave your systems vulnerable to attacks, as the assessment probably only scratched the surface.

Pentest Provider Price

Ultimately, the cost of a penetration test is a small price to pay for the peace of mind that comes with knowing your systems are secure and achieving your SOC 2 compliance goals.

How to select a reputable penetration testing firm?

When it comes to ensuring the security of your organization's data and systems, there is no substitute for a thorough and adequately scoped pentest executed by experienced experts. But with so many pentesting vendors on the market, how can you be sure you're choosing a reputable one to fulfill your SOC 2 pentest audit requirements? We have written a detailed post on this topic with the top 10 tips for finding a good pentest provider, but below, you can find a summary.

Here are a few things to look for:

  • A reputable pentesting vendor should have a proven track record with experience pentesting similar organizations to yours.
  • Working with a provider specializing in cybersecurity services can be beneficial as they often provide superior pentest services.
  • Qualified penetration testing firms usually have a technical blog, Github, or other channels displaying their technical expertise and research.
  • Ensure the vendor has adequate liability insurance to cover damages if something goes wrong during the pentest.
  • The vendor's staff should be full-time employees rather than freelancers, and they should have robust security procedures protecting your data during the test.
Pentest Provider

By following the guidelines above, you can be confident that you're choosing the right penetration testing partner.

How often should I conduct a pentest for SOC 2 compliance?

Most organizations undergo SOC 2 audits annually, meaning the reports are valid for 12 months. If your organization follows this cycle of audit, penetration testing for SOC 2 should be conducted at least once a year to ensure a strong company's security posture and continuous compliance.

SOC 2 pentest frequency

However, there are service organizations that are audited every six months, and it is recommended that your pen test requirements should align with this shorter timeframe.

What to expect from a SOC 2 penetration test report?

A penetration test report is the main deliverable of a pentest assessment. The document usually contains elements such as the following:

  • A high-level summary of the findings
  • An executive summary explaining the risk and impact of each vulnerability for non-technical audiences
  • Scope, testing methodology, and duration of testing
  • Detailed information about the vulnerabilities discovered during testing
  • Recommendations for fixing each issue or mitigating their respective risk

A pentest report should provide a comprehensive analysis of the results of the findings encountered during the assessment, with a clear and concise explanation of the impact and likelihood of an attack.

We have written a separate blog post with more information about what to expect from a pentest report, and we encourage readers of this guide to read our article for more details.

How can Blaze help your organization with SOC 2 compliance and penetration testing?

Na Blaze Information Security, somos especialistas em cibersegurança ofensiva. Da alta liderança à equipe de consultoria de segurança, todos somos hackers éticos que acreditam na excelência técnica.

Nosso portfólio de serviços é composto quase exclusivamente por testes de intrusão e serviços de segurança de aplicações. A equipe da Blaze publica rotineiramente pesquisas originais em nossos Labs, e realizamos constantemente avaliações de testes de intrusão focadas em SOC 2 para diversos clientes na América do Norte, Europa e além. Além disso, firmamos parcerias com plataformas líderes em automação de conformidade para oferecer aos nossos clientes suporte total em sua jornada SOC 2.

Entre em contato conosco para suas necessidades de testes de intrusão SOC 2 ou demandas de conformidade automatizada.

Considerações finais

Ao seguir estas diretrizes, você garante que sua auditoria SOC 2 ocorra sem problemas e que sua organização permaneça em conformidade com as melhores estruturas de segurança do mercado.

Os testes de intrusão podem ajudar as organizações a melhorar sua postura de cibersegurança e alcançar a conformidade com os padrões de segurança mais recentes, incluindo o SOC 2.

Entre em contato conosco hoje mesmo para saber mais sobre como os serviços de teste de intrusão da Blaze podem ajudar sua organização a atingir seus objetivos de SOC 2 e aumentar a resiliência cibernética.

Perguntas frequentes

Qual deve ser a frequência de um teste de intrusão SOC 2?

O teste de intrusão para SOC 2 deve ser realizado pelo menos uma vez por ano para garantir a conformidade contínua.

Quanto custa um teste de intrusão para SOC 2?

Geralmente, uma empresa conceituada cobrará entre US$ 8.000 e US$ 25.000, dependendo do escopo.

Qual é o prazo de uma avaliação de teste de intrusão SOC 2?

Geralmente entre 5 a 25 dias úteis, dependendo do escopo do trabalho.

O teste de intrusão é um requisito para o SOC 2?

Não, não é um requisito, mas é frequentemente utilizado para atender aos critérios CC4.1 e CC7.1 do AICPA.

Do you have questions? Let's talk.

Get in touch with our cybersecurity experts

Read More