← Back to context

Comment by horsawlarway

6 hours ago

None of those are what OP proposed. Frankly, we also cover many of these practices just fine. What do you think SOC 2 type 2 and ISO 27001 are?

It seems like your issue is that we don't hold all companies to those standards. But I'm personally ok with that. In the same way I don't think residential homes should be following commercial construction standards.

> None of those are what OP proposed.

That doesn't worry me overly much.

> What do you think SOC 2 type 2 and ISO 27001 are?

They're compliance frameworks that have little to no consequences when they're violated, except for some nebulous "loss of trust" or maybe in extreme cases some financial penalties. The problem is the expectation value of the violation penalty isn't sufficient to change behavior. Companies still ship code which violates these things all the time.

> It seems like your issue is that we don't hold all companies to those standards.

Yes, and my issue is that we don't hold engineers personally liable for negligent work.

> I don't think residential homes should be following commercial construction standards.

Sure, there are different gradations of safety standards, but often residential construction plans require sign-off by a professional engineer. In the case when an engineer negligently signs off on an unsafe plan, that engineer is liable. Should be exactly the same situation in software.