logoalt Hacker News

dgellowtoday at 2:55 PM1 replyview on HN

I guess we had different experiences. The ones I interacted with were ok and wouldn’t have accepted a simple nmap here


Replies

tptacektoday at 3:09 PM

I'm not being snarky when I say that not getting your automated vulnerability scan, whatever it might have been, past your SOC2 auditors is a skills issue. SOC2 audits are not technical and the vulnerability scan control in SOC2 is categorically not meaningful. Cloudflare wrote a whole post about this.

show 1 reply