Hacker News new | ask | show | jobs
by ergocoder 33 days ago
> do you have documented procedures for revoking employee access

The answer should be "yes". And here you just drafted one.

That's the point of going through SOC2. You make policies that you don't have and execute the policies for some amount of time to pass SOC2.