Started By
Message

re: Job with Ernst and Young

Posted on 5/20/23 at 9:33 pm to
Posted by LemmyLives
Texas
Member since Mar 2019
6568 posts
Posted on 5/20/23 at 9:33 pm to
quote:

The problem I run into is the audit checklist morons who say they are "infosec experts" that have no ability to comprehend or process compensating controls.


Preaching to the choir. People don't understand nearly all auditors (or ex-auditors that work in 3rd party risk management, etc.) have an accounting degree and learned all they need to know about Windows Server security at a three day training in Cincinnati. I watched one consider the on prem mainframe as "out of scope" for a PCI DSS audit, because it was a mainframe. The quickest way to fool them is to bring up subnets and watch them pretend that being in two different class C subnets alone provides some sort of protection.
Posted by Centinel
Idaho
Member since Sep 2016
43440 posts
Posted on 5/20/23 at 9:35 pm to
quote:

I watched one consider the on prem mainframe as "out of scope" for a PCI DSS audit, because it was a mainframe.


Jesus

*laughs in AS/400*
first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram