home.social

#qsa — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #qsa, aggregated by home.social.

  1. Why doesn’t the PCI Security Standards Council crack down on #QSA firms that create worthless junk certificates? Important question @jbhall56 asks of the @PCISSC. #PCI #SSC admits it’s a problem, but won’t step up to the plate & is doing zero to stop it. pciguru.wordpress.com/2025/12/

  2. @bernie I can't speak to your local regulations, but there are certain types of audits and reports (e.g. #SOC attestations) that have to be done by a #CPA. Other types of audits may also have specific credentialing requirements, too, such as a #qsa for #pcidss.

    This post explains a bit about the CPA requirement for SOC reports. It's written more accessibly than the official AICPA information, IMHO.

    linfordco.com/blog/who-can-per

    You don't need to be a CPA or QSA for every type of auditing role, and there are certainly ways that other technical and security experts can be involved in auditing. Maybe you need to look for internal audit roles that aren't related to financial systems, but that's just an educated guess.

    Good luck in your job search!