> SOC2 is the best-known infosec certification, and the only one routinely demanded by customers
Maybe in the US. For the rest of the world, ISO27001 is arguably better known.
Maybe in the US. For the rest of the world, ISO27001 is arguably better known.
>Developed by the American Institute of CPAs
I don't know when CPAs became infosec experts.
>Each company designs its own controls to comply with its Trust Services Criteria.
Because it depends on self-assertion, SOC2 is generally a weak organizational certification.