Dec. 18, 2023, 3:35 p.m. | /u/80martinezl

cybersecurity www.reddit.com

I'm' interested in learning from those with experience in audits like ISO, SOC2, Fedramp, or similar. Have you ever faced a scenario where a control owner's evidence didn't match the policies or procedures shown to an auditor? In a SOC2 audit, this might lead to a 'qualified opinion' in the report. How should I bring this up with management and what are the potential repercussions? Specifically, during our internal audit, one of the control owners showed positive internal control testing …

audit auditor audits control cybersecurity experience fedramp iso opinion policies procedures report scenario soc2

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior - Penetration Tester

@ Deloitte | Madrid, España

Associate Cyber Incident Responder

@ Highmark Health | PA, Working at Home - Pennsylvania

Senior Insider Threat Analyst

@ IT Concepts Inc. | Woodlawn, Maryland, United States