June 14, 2024, 4:23 p.m. | /u/87390989

cybersecurity www.reddit.com

From my understanding, its possible for a company to have a SOC2 for a particular product and not necessarily one at the organization level.

* Regarding TPRM, if a company does not have a SOC2 for a product but they do have it in another area, would that be ok for you in terms of risk? I mean, some controls do span across the organization.
* I dont know much about ISO 27001, but does the same rules apply?


Wondering …

area cybersecurity organization product soc2 the company tprm understanding

Information Technology Specialist I, LACERA: Information Security Engineer

@ Los Angeles County Employees Retirement Association (LACERA) | Pasadena, CA

Tier 1 Network Operations & Security Center (NOSC) Analyst

@ ManTech | 201CK - 2250 Corp Park Dr, Herndon, VA

Tier 1 Network Operations & Security Center (NOSC) Analyst

@ ManTech | 852L - 1233S SpectrumBlvd,Chandler,AZ

Systems Engineer II - Simulation and Training (Onsite)

@ RTX | HVA34: Sterling, VA 22640 Davis Dr , Sterling, VA, 20164-7104 USA

Senior Software Engineer

@ Boliden | IN KA BANGALORE Home Office Building 10

Principal Audit Manager

@ Deutsche Bank | Pune - Business Bay