4 ms·
> SOC2 is the best-known infosec certification, and the only one routinely demanded by customers Maybe in the US. For the rest of the world, ISO27001 is arguab
by mopoke 4y ago
> SOC2 is the best-known infosec certification, and the only one routinely demanded by customers
Maybe in the US. For the rest of the world, ISO27001 is arguably better known.
- OrvalWintermute 4y agoSOC2 is also one of the weakest. >Developed by the American Institute of CPAs I don't know when CPAs became infosec experts. >Each company designs its own controls to comply with its Trust Services Criteria. Because it depends on self-assertion, SOC2 is generally a weak organizational certification.
- tptacek 4y agoThey're not infosec experts, and don't claim to be.
- bflesch 4y agoSOC2 signals much higher maturity than ISO27001, also in Europe.