New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Compliance does not equal security

New York Tech Editorial Team by New York Tech Editorial Team
October 19, 2021
in Cybersecurity
0
Compliance does not equal security
Share on FacebookShare on Twitter

Buy these widgets. Write these policies. Be compliant. Be secure.

While certain industry bodies set specific cybersecurity standards and requirements, following them is not enough to protect your organization from cyber attacks and to achieve resilience.

compliance does not equal security

Security started with compliance

Compliance was the primary driver for many businesses to build a cyber security program. Starting with frameworks like The Health Insurance Portability and Accountability Act (HIPAA) and Visa’s Cardholder Information Security Program (CISP) – which later evolved into the Payment Card Industry Data Security Standards, or PCI DSS – failure to meet compliance requirements was met with strict penalties that included hefty fines or the inability to process payments.

While these regulations made forming security teams necessary, they were often made up of employees that oversaw network and infrastructure. With little to no security experience, these early teams looked at the compliance framework as a definitive roadmap to being secure. The boards of these regulatory bodies noticed companies doing only what was mandated, so they evolved frameworks to encompass more controls. This inevitably led to the cost of being compliant eating the entire security budget.

Auditing or assessing

When cyber attacks were still in their infancy, the penalties enforced by regulatory agencies were often the biggest motivator behind implementing security. To ensure controls were implemented, regulatory bodies required varying levels of audit. Larger audits required third-party verification, and the subjective nature of control vs. intent created factions of assessors and auditors.

While auditing is looking at the words of specific control and “checking the boxes”, assessing looks at the intent behind the control and whether the capabilities implemented fulfill that intent. Assessing goes one step further to not only ensure the control is in place, but also verify that it is improving the security posture of the organization.

With few long-term cyber experts to assess the intent of the control, earlier evaluations were primarily audits and created a pandemic of organizations that were compliant, but not secure, often procuring security hardware and software just to check the box (without ever implementing them).

Keeping compliance relevant

Typically, the degradation in security-return of compliance comes from outdated controls with no explanation of intent.

PCI DSS debuted in 2004 with v.1.0, and 17 years later we anxiously await the arrival of v4.0. While tweaks and amendments can bring a framework closer to the current threat landscape, the evolutionary cycle of attacker tactics, techniques, and procedures (TTPs) make even a yearly re-release seem like a flirtation with irrelevance.

Further exacerbating the point is the highly prescriptive nature of the outdated controls, acting more as a tactical directive than a strategic objective. Referencing the above conversation about assessor vs. auditor, if organizations are audited on the presence of outdated technology that no longer applies to attacker TTPs rather than the ability to fulfill the intent of the control with more capable technology, compliance not only hinders the evolution of security, but is also counterproductive.

Current compliance mindset

With the increased publicity of today’s cyber attacks and the increased damage they’re inflicting, the cost of insecurity is surpassing the cost of non-compliance and garnering much more attention from the board and C-suite. However, the tidal wave of compliance requirements covering everything from PII to critical infrastructure continues to pull resources required for implementing and administering security.

Regulatory frameworks should define expected security outcomes and the penalties for failure to meet those outcomes – not dictate the means to achieve the outcomes. Today’s cybersecurity professionals are far more adept than those of the past who were pulled from other departments to meet a requirement.

With the career of most CISOs rooted in security, it’s time for regulatory bodies to trust the experts to achieve the expected outcomes of compliance, while protecting the organization’s brand and reputation in a way that enables business.

Credit: Source link

Previous Post

SASE emerges as the edge becomes an enterprise focal point

Next Post

This Raspberry Pi add-on lets you control Lego robots

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
This Raspberry Pi add-on lets you control Lego robots

This Raspberry Pi add-on lets you control Lego robots

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026
Employee Time Tracking

What is an Employee Time Tracking Solution? A Definite Guide for 2026

March 31, 2026
Voltify founders

Voltify Raises $30 Million Seed Round as It Challenges $1 Trillion Rail Electrification Model

March 31, 2026

Recommended

laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit Israel israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media