July 11, 2023, 1:49 p.m. | /u/foxtrot90210

cybersecurity www.reddit.com

My company has a SOC 2, customer is asking if we have "complementary user entity controls" in our report. To be honest I never heard of that term nor do I see it in my SOC 2. Is this required? How bad does it look if I tell the customer that I don't see any.

However, I did find a line item that says "`complementary user entity controls and complementary subservice organization controls how those controls interact with related controls …

asking bad controls customer cybersecurity don report soc soc 2 soc2

Senior Security Engineer - Detection and Response

@ Fastly, Inc. | US (Remote)

Application Security Engineer

@ Solidigm | Zapopan, Mexico

Defensive Cyber Operations Engineer-Mid

@ ISYS Technologies | Aurora, CO, United States

Manager, Information Security GRC

@ OneTrust | Atlanta, Georgia

Senior Information Security Analyst | IAM

@ EBANX | Curitiba or São Paulo

Senior Information Security Engineer, Cloud Vulnerability Research

@ Google | New York City, USA; New York, USA