2 ms·
Is this how every auditor does though or just you/Deloitte? SOC 2 is a set of guidelines, not mandates, there is one size fits all and every org may design thei
by devy 2mo ago
Is this how every auditor does though or just you/Deloitte? SOC 2 is a set of guidelines, not mandates, there is one size fits all and every org may design their own security controls based on their unique systems. Is that the same philosophy on the auditing side as well?
- yylyyl 2mo agoThe method is mine. How I test, what evidence I accept, how I call a deviation. Every firm has their own methodology but none of them publish it.