Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> You might be able to justify non-compliance with a compensating control, but I've never heard of anyone who tried it.

I just did similarly within a SOC2 audit. I sent the auditors a list of 50+ articles and references i've been maintaining for years saying that password changing is a bad idea (this article is on the list) from many different sources. I never heard back and the item was marked approved by them.



Can you please pop this list of articles into pastebin and paste it here? tyvm


This hasn't been updated in a while but there's plenty of references:

https://gist.github.com/technion/65c652194fb1427e6828ea23ff4...



Would you consider sharing it? Might be useful for others in the same boat.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: