Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What's actual security? Looking for zero days? Malware research? Continuous red team?

I think at the end of the day, SOC 2 aims to instill a basic level of organizational security so the company doesn't shoot itself in the foot. If a company can't genuinely follow a basic set of SOC 2 controls, can I trust them to do actual security?

Also, badly written checklists might be bad, but not all checklist are bad. Pilots use them. Doctors use them. Mechanics use them. In fact, most fields that involve critical life or death operations use them. Why? Because humans have a limited memory and tends to miss critical tasks all the time.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: