logoalt Hacker News

tptacekyesterday at 3:26 PM2 repliesview on HN

SOC2 auditors are accountants. A SOC2 auditor verifies only that you're doing what you say what you're doing.


Replies

kevin_nisbetyesterday at 5:06 PM

And the way they verify you are doing what you say you are doing is by asking you to provide evidence, which is usually pretty easy to demonstrate that a policy was followed once or twice, a lot harder for them to pick up consistency issues or exceptions.

show 1 reply
dgellowyesterday at 3:28 PM

Obviously, yes

show 1 reply