Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Youre required to have a policy. That policy may be throwing bananas at the wall, but if it's documented and you follow it, you're compliant with policy.


That's a good way to kill off motivated employees.

"We don't know why we're doing it - it's just mandatory".


Only if you write a bad policy, so don't do that.

The better way is that for each policy you look at what do you actually want to do and how you want to do it, and then write that down as the policy. Now the policy makes sense because it's how you wanted to do it anyway.

I've set up policies and processes from the ground up for SOC2 audits in startups, that's how I do it.


Great, so stepping into any organization green where the subvert command is to be unwilling to update policy will enable this.


Smart employees totally understand: "we do it because it makes it easier to explain to auditors, customers, new employees, non technical managers".


No, cogs understand that. Smart employees want to update policies to be an effective mandate versus lip service to the C-suites asshole


The policy can be changed.


Unless you’re every company I’ve worked st over the past 20 years.


When the audit happens, the auditors also consider if the policy meets the control objectives. If it doesn’t, you’re going to fail.


"Write what you do. And then do what you wrote."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: