Comment by tptacek

3 hours ago

You get that the technical controls in SOC2 are also extremely weak, right?

Sure, yes. The way I understand SOC2 relies on the auditors to set the effective standard. So it really depends who audited you

  • SOC2 auditors are accountants. A SOC2 auditor verifies only that you're doing what you say what you're doing.

    • And the way they verify you are doing what you say you are doing is by asking you to provide evidence, which is usually pretty easy to demonstrate that a policy was followed once or twice, a lot harder for them to pick up consistency issues or exceptions.