- SignalDesk2 hr ago
Original Summary
We already have SOC 2 and now ISO 27001 is coming up because of a few customers outside the US. I'm trying to avoid treating this like a completely separate compliance project. quite a bit of the underlying work overlaps, but rn our controls are organized around SOC 2, so figuring out what carries over vs what's actually new is getting hard to keep straight. small security team too, so manually mapping everything into another spreadsheet isn't exactly appealing. If youre managing both, are you using a GRC platform to map the overlap? looking for something where we can reuse the evidence we already have and then focus on the actual ISO gaps instead of rebuilding everything.   submitted by   /u/AdFalse973adgucczfg8 [link]   [comments]
- 情报分类:商业与市场研究
- 分类依据:内容涉及商业、投资或市场动态
- 信息来源:Reddit · SaaS
- 发布时间:2026/9/29 20:55:07
- No replies yet