3 ms·
> They are looking for their interests (minimize security breaches) No. This comes from the sales people. They want to provide a "SOC 2 Audited" certificate to
by illud_tempus 5y ago
> They are looking for their interests (minimize security breaches)
No. This comes from the sales people. They want to provide a "SOC 2 Audited" certificate to their potential customers. They don't give a rats ass about actual security.
The upper management does care about security. But I don't think this particular requirement offer much of that.
- zby 5y agoI googled "SOC 2 Audited" - and I've got: """ A SOC 2 audit is a company-wide certification that evaluates an organization's standards regarding its core data security infrastructure, information handling practices, consumer privacy, and confidentiality. For this purpose, an SOC 2 auditor needs to evaluate various aspects of a company's systems and processes """ So it is about security. I guess your point is that it is just a security theatre and not related to the real thing - but that is a different discussion. It would be a discussion about https://slatestarcodex.com/2014/07/30/meditations-on-moloch/ https://slatestarcodex.com/2014/07/30/meditations-on-moloch/ and https://www.amazon.com/Moral-Mazes-World-Corporate-Managers/dp/0199729883 https://www.amazon.com/Moral-Mazes-World-Corporate-Managers/... and etc