Hacker News new | ask | show | jobs
by RankingMember 180 days ago
This is 100% it- the auditor is confirming the system is configured to a set of requirements, and those requirements are rarely in lockstep with actual best practices.