Dec. 18, 2023, 3:35 p.m. | /u/80martinezl

cybersecurity www.reddit.com

I'm' interested in learning from those with experience in audits like ISO, SOC2, Fedramp, or similar. Have you ever faced a scenario where a control owner's evidence didn't match the policies or procedures shown to an auditor? In a SOC2 audit, this might lead to a 'qualified opinion' in the report. How should I bring this up with management and what are the potential repercussions? Specifically, during our internal audit, one of the control owners showed positive internal control testing …

audit auditor audits control cybersecurity experience fedramp iso opinion policies procedures report scenario soc2

Azure DevSecOps Cloud Engineer II

@ Prudent Technology | McLean, VA, USA

Security Engineer III - Python, AWS

@ JPMorgan Chase & Co. | Bengaluru, Karnataka, India

SOC Analyst (Threat Hunter)

@ NCS | Singapore, Singapore

Managed Services Information Security Manager

@ NTT DATA | Sydney, Australia

Senior Security Engineer (Remote)

@ Mattermost | United Kingdom

Penetration Tester (Part Time & Remote)

@ TestPros | United States - Remote