Hacker News new | ask | show | jobs
by RandomTisk 2383 days ago
They would be very wise to hire their own auditors, not necessarily to go into their client's businesses but to review the assessments most of them are already getting periodically, to make sure that evidence presented actually made sense and earned them a pass. It's been my experience that IT auditors are often book smart, but IT-experience poor. Some are simply not savvy or experienced enough to interpret their own framework the same way a week or a month later.