|
|
|
|
|
by asynchronous
1075 days ago
|
|
I’ve really been of the opinion as of late that if we took just a small fraction of the time and manpower we waste on pedantic security framework adherence and put it towards training actual staff to and experts to be better cybersecurity professionals, we’d be better off. |
|
On the other side of the coin, if a vendor does not have paperwork and evidence to support their programs - how does one as a purchaser or security reviewer verify? Organizations only act truthful to an extent that benefits them. Quality of audits and supporting paperwork is a real mixed bag. Unless you’re an Amazon you’re not going to get the chance to audit your vendors and sub processors outside of reviewing this type of documentation.
The entire process is broken.