• remotelove@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 day ago

    Compliance audits are usually handled by a third party and I am only familiar with SOC2, SOX, PCI and ISO27001. GDPR is a beast, from what understand. I do suspect it’s also ran by a third party during an audit period.

    Most of the above compliance programs require network architecture reviews and checks to ensure that their policies actually match how their internal processes and software actually works. This typically includes compliance enforcement mechanisms, such as what we were discussing.