KPMG asked me once: "Can you show it's actually encrypted?"
Do you have any programming skills? ... No? Then no. Then they started blabbing about what the data could be and it basically came down on them not understanding what random is and they then just checked it off and went on. Since then I do not believe any audit which come from those paper farms.
Yes, we ensure that the data is only available via TLS foo.bar with encryption algorithm baz, which is on the approved list. We have monitoring and logging that ensure that we receive an alert if the port the app is on is not encrypted, and if you'd like we can dump the traffic to show you that there is no clear text available.
Further, only users on the approved admin list can make a change or deploy to production, or login to the server as root. Moreover, we do a background check on employment for all users who have admin access, and all deployments and code changes require at least one other employee to approve them, and we log who they were, and what the change was.
Do you have any programming skills? ... No? Then no. Then they started blabbing about what the data could be and it basically came down on them not understanding what random is and they then just checked it off and went on. Since then I do not believe any audit which come from those paper farms.