Replies: 2 comments 2 replies
-
We follow SOC 2 internally, if someone wants to monitor this they can, but SOC 2 is rather more complete and externally audited. |
Beta Was this translation helpful? Give feedback.
2 replies
-
The intention with the initial question is partly answered with soc 2. Think I am not seeing all software supply chain things like openchain ISO/IEC 5230 so that would be a nice addition, but I have used another standard that SOC 2 so not that read up on this standard. Case closed from my side. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Have there been ideas to adding openssf scorecard to see what things would be good to secure up?
Beta Was this translation helpful? Give feedback.
All reactions