logoalt Hacker News

sam_lowry_today at 8:54 AM2 repliesview on HN

Reminds me of the famous "Our security auditor is an idiot. How do I give him the information he wants? [1]

[1] https://serverfault.com/questions/293217/our-security-audito...


Replies

zvqcMMV6Zcrtoday at 10:06 AM

That is crazier than any old dailywtf stories, and that site felt like everyone tried to one-up each other.

rcxdudetoday at 9:52 AM

Is there some part of PCI auditing requirements that is getting misinterpreted by some auditors to demand this? Though in my experience with standards like this what auditors want to see and what the standards say often have only loose overlap anyhow.