Hacker News new | ask | show | jobs
by vasco 1136 days ago
Yes same issue in all my jobs. I've found that security and compliance standards for technology companies are created and maintained by accountants, not engineers. In a way this is good because if the engineers fix "the real issues" and the accountants focus on the "generic list that doesn't matter", you still end up catching some different things. Problem is the amount of fake work, as well as slowdowns created in exchange for no extra security.