Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm in Information Security at a large enterprise. We look for this kind certification, but it isn't required. Not having it though will lead to further scrutiny (lots more questions to answer). I would recommend getting it if you can, particularly if you are offering a service that is hosting the customer's data and/or is managing some part of their IT operations.

Bolstering the recommendation is the fact that the proliferation of supply chain attacks recently is adding pressure for companies to perform more thorough diligence on their vendors. The certification helps check all the boxes.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: