3 ms·
I have personally been a part of security audits that have found critical vulnerabilities in some of the best-known tech companies on the globe. Just because t
by mahemm 8y ago
I have personally been a part of security audits that have found critical vulnerabilities in some of the best-known tech companies on the globe.
Just because there exists a world of auditors who function as rubber stamps does not mean we all do.
- cptskippy 8y agoI've been part to numerous audits during my career and there's always an initial findings report with the opportunity to explain away findings such that they never show up on the final report.
- mahemm 8y agoIf that's the case then you haven't been working with good auditors. That said, the opportunity to do this (scrub reports) is a driving decision behind many companies' choice to work with more permissive firms. If you want a rubber stamp, you can certainly get it, but if you want a true partner who will find and exploit issues you can get that too.
- Leace 8y ago> if you want a true partner who will find and exploit issues you can get that too. Could you name such a company? This is a perfect opportunity to get to know a good auditor, actually I can't imagine how would one look for a good auditor otherwise.