Replies: 2 comments 2 replies
-
We follow SOC 2 internally, if someone wants to monitor this they can, but SOC 2 is rather more complete and externally audited. |
Beta Was this translation helpful? Give feedback.
2 replies
-
The intention with the initial question is partly answered with soc 2. Think I am not seeing all software supply chain things like openchain ISO/IEC 5230 so that would be a nice addition, but I have used another standard that SOC 2 so not that read up on this standard. Case closed from my side. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Have there been ideas to adding openssf scorecard to see what things would be good to secure up?
Beta Was this translation helpful? Give feedback.
All reactions