| ▲ | dgellow 4 hours ago | |||||||
I know, that’s already established. I already acknowledged we had different experiences. I have no idea what you’re pushing for at that point | ||||||||
| ▲ | tptacek 3 hours ago | parent | next [-] | |||||||
Just to clarify, this is a bugbear of mine. It's nothing personal with you, but I've spent the last 6 years or so evangelizing the idea that people should minimize their SOC2s and not get pushed around by auditors or evidence collection platforms like Vanta, because that drives a lot of terrible security engineering, and the hypercompetent best-staffed security orgs in the industry all push their SOC2 auditors around. Compliance and security are entirely different practices in a well-run firm. Security can inform compliance. Compliance should not inform security engineering. If you search my name and "SOC2" in the search bar below, I've expanded on this quite a bit. | ||||||||
| ||||||||
| ▲ | john_strinlai 3 hours ago | parent | prev [-] | |||||||
tptacek just hates soc. its probably not personal. | ||||||||
| ||||||||