this post was submitted on 12 May 2024
38 points (97.5% liked)

Asklemmy

43899 readers
992 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy ๐Ÿ”

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_[email protected]~

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 9 points 6 months ago* (last edited 6 months ago) (3 children)

I'm an IT auditor. "What the fuck?" is the main question, we ask it daily

[โ€“] [email protected] 5 points 6 months ago (2 children)

I do other audits, mostly safety and environmental, and my big question is usually "nobody made you write this, why would you write this down if you don't want to do it?"

[โ€“] [email protected] 1 points 6 months ago

Oh so so much of "dude you mande this rule up, you reviewd this document, why is this process nothing like this?!

[โ€“] [email protected] 0 points 6 months ago (1 children)

Can you explain? Are you referring to catching people doing stuff they shouldn't have been doing?

[โ€“] [email protected] 6 points 6 months ago

For most regulations, the laws and rules say something like "companies must ensure X doesn't happen", and the companies themselves have to come up with a way to do that.

Let's say the law says "companies that transport apples must be able to show which batch went where".

Company A says "to comply with the law, whenever we move a shipment, we store the shipping order on our computers"

Company B says "to comply with the law, the truckdriver will film the place they left, count the apples when leaving, then email the entire dashcam trip, and count the apples on arrival".

Neither process is wrong, they both follow the law. But when I go to Company B, I promise you they're going to fail the audit. They're (probably) not doing anything illegal, but they're going to fail their audit because no truckdriver is going to count a truck full of apples.

They made that rule, and they really didn't have to.

[โ€“] [email protected] 2 points 6 months ago

It'd be interesting to see that answered scientifically.

[โ€“] [email protected] 1 points 6 months ago (1 children)

I work in IT and haven't had to go through an audit yet knocks wood

Any war stories you can share?

[โ€“] [email protected] 1 points 6 months ago

Mostly cybersecurity strugles. If you invest millons in a castle with a gigantic lock and a pit full of piranas, would you leave the service entrance open and give everyone in town the key? Yeah, more commom than not.

But an IT audit is only necessary if your company goes public or is the owner wants it, maybe if you are a tech company.