Hacker News new | ask | show | jobs
by ah88 1883 days ago
One way is to isolate the applications that actually need SOX compliance and have separation of duties for those. The ones that don't need to follow SOX compliance don't need those controls.