3 ms·
Often this only comes after IPO e.g. with SOX/... compliance.
by _Codemonkeyism 9y ago
Often this only comes after IPO e.g. with SOX/... compliance.
- yeukhon 9y agoSOX compliance is unfortunately bureaucratic in the sense as long as you can prove control is in place no one cares if you can read customer's data. A business owner can approve thr request in some ticketing system (change ticket) then the auditor would be okay because it is not the auditor's interest to judge whether some business decision is good or bad. You can keep your private keys in a Git repo encrypted as long as you can prove control and audit logs are available because the underlying security is not an audit concern. Another example is as long as you keep data and logs for seven years, auditors would be okay; they don't care if you are keeping a yearly archive for seven rars, monthly backup for seven years, you pick. Data and security governance is often a miss item.
- _Codemonkeyism 9y agoYes.