Hacker News new | ask | show | jobs
by raverbashing 1980 days ago
No, I'm saying their audit process focus more in box checking than actually seeing "you left the key under the mat"
3 comments

The "boxes" to be checked are actually asking open-ended questions about that, and asking you to provide copious written documentation backing up what you are claiming. This process takes weeks or months and is quite expensive.
The relevant box here is "Are all accesses to production systems logged in an indelible manner?" and "Is the principal of least privilege followed when accessing production systems?"

These questions aren't perfect, since they don't actually prevent security issues and merely document them extensively, but answering no to them will fail the audit.

Are you talking about HIPAA or SOC2?