| ▲ | tfrancisl 4 hours ago | |||||||
Maybe no one wakes up wanting to deal with compliance, but it you found a company that has legal or moral obligations to be compliant with these standards, you sure have signed yourself up for it. Passing the responsibility off to some other company is, quite simply, irresponsible. | ||||||||
| ▲ | egorfine 4 hours ago | parent | next [-] | |||||||
> Passing the responsibility off to some other company is, quite simply, irresponsible. Then do not pass the responsibility. But here's the trick: the regulator would like to see an audit done by a firm and purchasing audit services is exactly that: passing responsibility. So legally you can't be compliant unless you passed responsibility. | ||||||||
| ||||||||
| ▲ | egorfine 4 hours ago | parent | prev [-] | |||||||
Problem is, compliance is often detrimental to the cause. You want to encrypt users' data at rest? Illegal. You must store users data in a way prescribed by the law and it is extremely cumbersome, outdated and insecure. | ||||||||