Evaluate scope of: compliant financial infrastructure. #207
Replies: 4 comments 4 replies
-
Concur that we need more input and perspectives from the community on this topic. My opinion is that we should set a scope saying that a service approval accelerator should at minimum cover a baseline standard such as NIST, CIS, or PCI-DSS. (Edited to include PCI-DSS in my examples.) |
Beta Was this translation helpful? Give feedback.
-
This is an upstream compliance project that Red Hat and others contribute to, is this something you are aware of? |
Beta Was this translation helpful? Give feedback.
-
Hi everyone, I had a question or two, and this looks like the right place to land. I led the audit team with the US GSA to audit GCP for federal IT compliance, as well as other audit work in Sarbanes Oxley, NIST/FISMA, and (what was ) SSAE 16 IT engagements. I'm reading into this discussion that you have a desire to a) come to agreement on appropriate regulatory controls for Internal Controls over Financial Reporting (ICFR) and b) inculcate those controls as IaC. |
Beta Was this translation helpful? Give feedback.
-
This conversation can be closed out as it has been resolved by #250. If additional changes to documentation are needed for clarity, please provide suggestions on #250. |
Beta Was this translation helpful? Give feedback.
-
Current state:
Problem:
Beta Was this translation helpful? Give feedback.
All reactions