Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SOC2 is also one of the weakest.

>Developed by the American Institute of CPAs

I don't know when CPAs became infosec experts.

>Each company designs its own controls to comply with its Trust Services Criteria.

Because it depends on self-assertion, SOC2 is generally a weak organizational certification.



They're not infosec experts, and don't claim to be.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: