|
|
|
|
|
by michaelt
7 days ago
|
|
> SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Even with an external audit - think of how many projects and repositories and servers and libraries and legacy systems Apple, a 50-year-old company with 166,000 employees, could have. Then think about how much inspection is involved in a $50,000 audit. I doubt you get more than one inspector working full time for a year. In which case they've got 45 seconds of to audit each employee's entire work output. And places like EY will bill some people out at $700/hour, so it could be an order of magnitude less than that. So this isn't some fine-toothed-comb forensic investigation or adversarial penetration test. |
|