this post was submitted on 12 May 2024
229 points (99.1% liked)
Asklemmy
43757 readers
1293 users here now
A loosely moderated place to ask open-ended questions
Search asklemmy ๐
If your post meets the following criteria, it's welcome here!
- Open-ended question
- Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
- Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
- Not ad nauseam inducing: please make sure it is a question that would be new to most members
- An actual topic of discussion
Looking for support?
Looking for a community?
- Lemmyverse: community search
- sub.rehab: maps old subreddits to fediverse options, marks official as such
- !lemmy411@lemmy.ca: a community for finding communities
~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
there are 2 types of rules, or controls as we call it: Legal requirements and internal policies. The first one is clear there are legal requirements in place and you have to be in compliance with. The second one is where I get the most wtfs. Internal policies are rules the company itself crated and said had to be followed. For example let's say you are the IT manager of your company and you discover that everyones password to you system is 1234. You go out and look for market best practices and create a policy saying "All passwords must contain 6 numbers and 2 letters". For this to be official you write it down and "publish" it internally.
Now, me as an auditor go there, look at the rule you created and check if it's really in place or if you just wrote because. A lot of times it's not. The company creates the rule but forgets or just postpone implementing it