Curious how others have handled marking dev/test resources as out of scope. We're going through our first SOC 2 audit at Helmet Security. Vanta is detecting several development instances we use for integration testing and applying the same controls as our production environments. The setup: one Azure account containing a test VM and a test Sentinel instance (Azure's equivalent of Splunk). No real workloads, no customer data: purely a test environment. Is there a clean way to scope these out so they're not held to the same standards, without raising an auditor's eyebrow?
hey Gary P.!
Thinking out loud here; Since you mentioned "one Azure account," quick clarifying question: Is that the only Azure account connected to Vanta, or do you also have a separate production Azure account integrated? i ask because if it is just entirely a test, toggling it off entirely (and then of course noting that context to the auditor) might be the best route. but not sure at this point if youre referencing one of two instances, or if it is just one Azure instance altogther. thoughts?
hey Jacob G. thanks for the response. We are a google and aws company. The only reason we have access to anything Azure is for testing. We test a LOT of integrations which are all picked up by JAMF and therefore reported to Vanta. It's exhausting keeping up with telling Vanta (vendors) that these are all just things we're building api integrations to and that WE don't use them at all in our daily life.
hey Gary P. my pleasure! and thanks for that context. totally hear you there on keeping up with all the vendors and how you're using integrations/how theyre scoped. 馃ケ 馃槄
given what youve shared, it sounds like the toggle off will work here, then making sure you just make that note for audit purposes to cover all your bases. I have a feeling this article will help you with that + give more context on next steps. Let me know what you think! ![]()
