April 2, 2024, 4:51 p.m. | /u/87390989

cybersecurity www.reddit.com

I am being audited for SOC. One of the controls is regarding signed job descriptions. One of the employees did NOT sign their job description. At this point, we are outside the audit period. We are still going to have the employee sign it.

My question is, do I tell the auditor that it wasnt done in the audit period ***OR*** do I just hand over the newly signed job description and leave it up to them to noticed it …

audit auditor controls cybersecurity descriptions employee employees job period point question sign soc

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Application Security Engineer - Remote Friendly

@ Unit21 | San Francisco,CA; New York City; Remote USA;

Cloud Security Specialist

@ AppsFlyer | Herzliya

Malware Analysis Engineer - Canberra, Australia

@ Apple | Canberra, Australian Capital Territory, Australia

Product CISO

@ Fortinet | Sunnyvale, CA, United States

Manager, Security Engineering

@ Thrive | United States - Remote