Feb. 23, 2023, 4:35 p.m. | /u/87390989

cybersecurity www.reddit.com

I am struggling to understand this better. When a organization wants to get SOC2, what "things" get certified? I believe their product does ***not*** get SOC2, its the company's environment correct?

For example, you are certifying that your policies/processes/procedures (from HR to cloud development) are documented, etc and those are getting certified.

If the above is true, can anything else get SOC2 certified? Is it possible to only certify a part of your organization or does it have to be …

certified cloud cybersecurity development environment etc organization policies procedures processes product soc soc 2 soc2 the company things understand

Financial Crimes Compliance - Senior - Consulting - Location Open

@ EY | New York City, US, 10001-8604

Software Engineer - Cloud Security

@ Neo4j | Malmö

Security Consultant

@ LRQA | Singapore, Singapore, SG, 119963

Identity Governance Consultant

@ Allianz | Sydney, NSW, AU, 2000

Educator, Cybersecurity

@ Brain Station | Toronto

Principal Security Engineer

@ Hippocratic AI | Palo Alto