Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ah, OK. Makes more sense now. Still, requiring ISO compliance from a small business sounds like madness. An audit ought to be enough.


Again, makes total sense from the perspective of an American legal department. They're falling back on the tools they know to de-risk vendors, which is formal certifications and accreditations. ISO, SOC, etc. The lawyers are going to be extra twitchy because of how vague and hand-wave-y GDPR is.

An actual compliance audit from an accredited auditor, paid for by the SaaS offering of course, is not going to be cheap or easy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: