4 ms·
> Good point. But the audit seems useless now. It's supposed to prevent the carelessness from causing... this thing that happened anyway. > Sure, maybe it prev
by sobkas 2y ago
> Good point. But the audit seems useless now. It's supposed to prevent the carelessness from causing... this thing that happened anyway.
> Sure, maybe it prevented even more events like this from happening. But still.
Because the point of audit is not to prevent hacks, it's to prove that you did your due diligence to not get hacked, so fact that hack happened is not your fault.
You can hide under umbrella of "sometimes hacks happen no matter what you do".
- lucianbr 2y agoCYA is the reason you do the audit. But the reason for the audit's existence and requirement is definitely so that hacks don't happen. Don't tell me regulatory agencies require things so that companies can hide behind them.
- bonoboTP 2y agoThe reason for the audit's existence is CYA one level above. The chain ends with a politician's CYA in front of the electorate.