Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

the auditors that sign off on your security to meet your clients requirements usually know way less about your security posture than your clients do

its all just surface-level box-checking. most companies required to get 'penetration tests' just get an overpriced Nessus scan sold as a pentest and that meets their reqs.



while this is true it in no way diminishes the value that orgs like cve provide




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: