|
|
|
|
|
by tptacek
365 days ago
|
|
Cosign all of this wholeheartedly. Push back! The ratcheting back system scope thing is super good advice I always forget to give, too. You can get your entire software security program wrapped up in your SOC2 --- but why would you ever want to do that. The security of your software is very relevant to your customers, but it is not and should not be relevant to SOC2. |
|