As it turns out, all of my current engagements are for AI companies. Basically SaaS companies that utilize AI for very specific business service delivery. One of these companies targets major global enterprises so I'm getting a first hand view of how these enterprises are looking at their risks. Suggestions: get your basic SOC2/ISO27x stuff in order. It answers a lot right out of the gate. Be prepared to explain, in detail how the clients data will be exposed to the LLM. Have a rock-solid one-two pager on that. Helps focus discussions. This is new stuff for some of these big enterprises so there is not a lot of similarity between their questions/tools yet. Everyone is learning about how AI is implemented in business tools. Expect lots of questions from lots of parties; IT, Cyber, legal, IP. Expect lots of duplicate questions. Keep you own tooling up to date with client questions/questionnaires about AI controls and your answers for repeatability. One client has asked about ISO42001, and we have it backlogged and I'm starting to cost out the program. We are pretty sure having it will help speed procurement with other large prospects. Happy to answer any specific questions.
I have not opened a support ticket for this issue. I was working with the vendor first. We've learned that the standard Google Workplace connector in Vanta won't work with HIPAA Vault due to the Org wide access required by Vanta. Should I still open this ticket?
Does anyone have any tips for connecting Vanta to HIPAA Vault for GCP monitoring? I'm being told by their support team that I can't use the Vanta process to connect to GCP because: "...the Vanta scanner too invasive with their defaults. As a Google Cloud Partner, our organization supports many client projects. Vanta demands org level permissions by default which we cannot provide because of our sub clients. However, there may be a way to configure this within a single project, but it makes the set up more complex. As a Google Cloud Partner we have the premium version of the Security Command Center (SCC). SCC provides the compliance checks that Vanta provides. However, we understand that Vanta may be a tool used by your org to aggregate information.... Any suggestions/solutions to this dilemma is appreciated.

.png)
