Tag Archives: SDLC

More Snake Oil

In Standard (Snake) Oil, I complained about  companies that don’t audit according to standards because some treat control owner statements as pure gold, don’t insist evidence be tied back to actual systems, and don’t ask all the appropriate questions.

Here’s a few more questionable practices that I’ve challenged all too recently.

Continue reading

Leave a comment

Filed under Audit