Comment by paulryanrogers
9 days ago
IME compliance tools will take a doc and or a link. What's acceptable is up to the auditor. IMO both a link and doc are best.
Links alone can be tempting as you've to reference the same docs or policies over and over for various controls.
No comments yet
Contribute on Hacker News ↗