And, never forget: what a company preaches and advertises is not the same with what the company is actually doing.
And, never forget: what a company preaches and advertises is not the same with what the company is actually doing.
Also, here is some more information about this breach: https://x.com/intcyberdigest/status/1973422846396473765
90% of the time, they are checking boxes. But if they are fishing, you have to be careful because they generally are bad at understanding anything, but good at manipulating the audit rules to frame things in such a way so they can “catch a big fish”.
Is it really OK? Not necessarily, but on the other hand you don't want to spend the rest of your life answering even more questions from other people the auditors might bring in to help them understand your helpful explanations.
I learned this the hard way, assuming auditors are logical and understand technology.
A person who is used to interviewing people will be able to tell right away.
Yes, it is highly adversarial and the best compromise I've seen is to have an internal audit team that is separate organizationally from IT, but has to withstand peer review if they claim anything is a real problem.
Your boss is bad apple and so are you if you adopt their ways.