3 ms·
I'm curious, can you tell us what the negative impacts you've seen are? Are there any audits that you can say are a positive indicator for security?
by wadadadad 2y ago
I'm curious, can you tell us what the negative impacts you've seen are?
Are there any audits that you can say are a positive indicator for security?
- agartner 2y agoSpending all their security time/budget on box checking rather than actual security. I'd rather see open ended red team pentest reports.
- ensignavenger 2y agoThis is my complaint with "cyber insurance". Companies spending money on insurance premiums and checklists for the insurance company rather than spending money on security.
- phil21 2y agoYep. My experience as well. Once a place starts doing useless box checking stuff like SOC2 it’s time to find a new job or switch vendors. Positive indicators would be talking to employees and getting an idea of organizational clue level. There are no shortcuts here I’ve ever found beyond doing this sort of old fashioned “know your vendor” style work.