Hacker News new | ask | show | jobs
by deepsun 6 days ago
It's not auditors, it's the compliance requirements and controls. You should not even reach to an auditor before fixing the controls (most of them, the ones you lack auditor must flag, as sometimes it's not feasible to fix most of the controls). I'd say going through an audit is easy, but preparing for the audit is hard.

PS: regarding "most of them" -- if you're one-person shop, you'll likely fail a control that requires your board of directors to be independent of company management (i.e. having directors that do not work for the company). That's OK, but will be reported on your SOC2 report.

1 comments

Security and compliance are totally different functions and one has little to do with the other.
I mean, if you don’t think about it that’s true.