logoalt Hacker News

michaeltyesterday at 10:46 PM1 replyview on HN

> SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1).

Even with an external audit - think of how many projects and repositories and servers and libraries and legacy systems Apple, a 50-year-old company with 166,000 employees, could have.

Then think about how much inspection is involved in a $50,000 audit. I doubt you get more than one inspector working full time for a year. In which case they've got 45 seconds of to audit each employee's entire work output. And places like EY will bill some people out at $700/hour, so it could be an order of magnitude less than that.

So this isn't some fine-toothed-comb forensic investigation or adversarial penetration test.


Replies

tptacekyesterday at 10:52 PM

A $50k audit is going to be team of 2 CPAs collecting evidence for 2 weeks.