logoalt Hacker News

SAI_Peregrinusyesterday at 7:20 PM1 replyview on HN

SOC2 requires a company to write policies in a large number of areas, and to demonstrate that they're complying with the policies they wrote. AFAIK SOC2 does not require anything meaningful about the actual contents of the policies, nor does it require the policies to remain constant.


Replies

briHasstoday at 2:43 AM

This is true. They (the auditors) usually have guidance or areas they need to see policy address, but not specific implementation details.

Using common, overbearing MDM or endpoint tools make providing evidence of adherence to policies easier, however.

show 1 reply