Hacker News new | ask | show | jobs
by watt 2182 days ago
There are certain practices that a company does, and various auditors have different opinions on it. For example, in PCI there are ways of interpreting certain requirements: and when you choose an auditor, you want one that agrees with your approach, and don't want the one that insists on different approach.