|
|
|
|
|
by discodave
2151 days ago
|
|
The audits check that controls are in place, not that the controls are technically bulletproof or people-proof. Source: Worked at AWS for several years including working on systems that had audit requirements for [secret project where I could not know the name of the customer because I don't have TOP SECRET security clearance]. |
|
And there are lots of things that many folks at the big cloud providers don't know about their internal threat management and monitoring. Source: Audited most of them for that customer you weren't allowed to know the name of. :)