4 ms·
the auditors that sign off on your security to meet your clients requirements usually know way less about your security posture than your clients do its all ju
by czk 1y ago
the auditors that sign off on your security to meet your clients requirements usually know way less about your security posture than your clients do
its all just surface-level box-checking. most companies required to get 'penetration tests' just get an overpriced Nessus scan sold as a pentest and that meets their reqs.
- JohnMakin 1y agowhile this is true it in no way diminishes the value that orgs like cve provide