I don't really care much about cerifications of any sort so I can't be sure I'm describing the right one, but I remember when working at a small ISP/datacenter we wanted to get SOC II (??) compliance to please some customer and the process was like this:
Me: what are the requirements?
🤖 We have to document all our processes and procedures
Me: and then what?
🤖: an auditor will verify (by quizzing you in front of a computer screen they don't understand) to prove you're following the documented processes and procedures
Me: okay, but like what do we have to do? How long do we have to retain customer backups, for example?
🤖: there is no requirement. How long are you retaining customer backups?
Me: well we had that failure so right now we only have 6 months
🤖: so document 6 months
Me: can we just say one month? And then we exceed our documented retention by a good margin?
🤖: yes
Me: this is a scam isn't it?



)
🇨🇦Samuel Proulx🇨🇦
in reply to jbz • • •