3 ms·
Thought the way you presented your source is a bit odd. For SOC2 you write the controls & policies. The audit is backwards looking to confirm you're adhering t
by ckdarby 2y ago
Thought the way you presented your source is a bit odd.
For SOC2 you write the controls & policies. The audit is backwards looking to confirm you're adhering to what your company has said is policy.
- kstrauser 2y agoSure, but they also want to see that those policies you wrote and conform to meet a whole lot of bullet points.