Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SOC2 is absolutely an infosec certification; it's just one that's premised around the idea that that the service organization should have its own mechanisms for achieving security goals and then demonstrate compliance with them.

This is different from PCI-DSS which is single-domain-specific and highly prescriptive at a technical level as a result.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: