Tag
SOC 2
3 articles tagged “SOC 2”.
-
The Compensating Controls Register Auditors Accept
You deferred a control and promised a compensating one. Here is the register entry that PCI, SOC 2, and NIST assessors sign off on instead of flagging.
-
Risk-Based Patching: How to Defend It to an Auditor
You skipped a Critical CVSS because EPSS said low-risk. Here is the evidence trail that keeps a PCI, SOC 2, or SOX auditor satisfied.
-
SOC 2 Change Management Controls and Real Audit Questions
SOC 2 change management under CC8.1, CC7.1, and CC6: what auditors actually ask, what evidence to keep, and where automation falls short.