April 2, 2024, 4:51 p.m. | /u/87390989

cybersecurity www.reddit.com

I am being audited for SOC. One of the controls is regarding signed job descriptions. One of the employees did NOT sign their job description. At this point, we are outside the audit period. We are still going to have the employee sign it.

My question is, do I tell the auditor that it wasnt done in the audit period ***OR*** do I just hand over the newly signed job description and leave it up to them to noticed it …

audit auditor controls cybersecurity descriptions employee employees job period point question sign soc

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Sr. Staff Firmware Engineer – Networking & Firewall

@ Axiado | Bengaluru, India

Compliance Architect / Product Security Sr. Engineer/Expert (f/m/d)

@ SAP | Walldorf, DE, 69190

SAP Security Administrator

@ FARO Technologies | EMEA-Portugal