New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Compliance does not equal security

New York Tech Editorial Team by New York Tech Editorial Team
October 19, 2021
in Cybersecurity
0
Compliance does not equal security
Share on FacebookShare on Twitter

Buy these widgets. Write these policies. Be compliant. Be secure.

While certain industry bodies set specific cybersecurity standards and requirements, following them is not enough to protect your organization from cyber attacks and to achieve resilience.

compliance does not equal security

Security started with compliance

Compliance was the primary driver for many businesses to build a cyber security program. Starting with frameworks like The Health Insurance Portability and Accountability Act (HIPAA) and Visa’s Cardholder Information Security Program (CISP) – which later evolved into the Payment Card Industry Data Security Standards, or PCI DSS – failure to meet compliance requirements was met with strict penalties that included hefty fines or the inability to process payments.

While these regulations made forming security teams necessary, they were often made up of employees that oversaw network and infrastructure. With little to no security experience, these early teams looked at the compliance framework as a definitive roadmap to being secure. The boards of these regulatory bodies noticed companies doing only what was mandated, so they evolved frameworks to encompass more controls. This inevitably led to the cost of being compliant eating the entire security budget.

Auditing or assessing

When cyber attacks were still in their infancy, the penalties enforced by regulatory agencies were often the biggest motivator behind implementing security. To ensure controls were implemented, regulatory bodies required varying levels of audit. Larger audits required third-party verification, and the subjective nature of control vs. intent created factions of assessors and auditors.

While auditing is looking at the words of specific control and “checking the boxes”, assessing looks at the intent behind the control and whether the capabilities implemented fulfill that intent. Assessing goes one step further to not only ensure the control is in place, but also verify that it is improving the security posture of the organization.

With few long-term cyber experts to assess the intent of the control, earlier evaluations were primarily audits and created a pandemic of organizations that were compliant, but not secure, often procuring security hardware and software just to check the box (without ever implementing them).

Keeping compliance relevant

Typically, the degradation in security-return of compliance comes from outdated controls with no explanation of intent.

PCI DSS debuted in 2004 with v.1.0, and 17 years later we anxiously await the arrival of v4.0. While tweaks and amendments can bring a framework closer to the current threat landscape, the evolutionary cycle of attacker tactics, techniques, and procedures (TTPs) make even a yearly re-release seem like a flirtation with irrelevance.

Further exacerbating the point is the highly prescriptive nature of the outdated controls, acting more as a tactical directive than a strategic objective. Referencing the above conversation about assessor vs. auditor, if organizations are audited on the presence of outdated technology that no longer applies to attacker TTPs rather than the ability to fulfill the intent of the control with more capable technology, compliance not only hinders the evolution of security, but is also counterproductive.

Current compliance mindset

With the increased publicity of today’s cyber attacks and the increased damage they’re inflicting, the cost of insecurity is surpassing the cost of non-compliance and garnering much more attention from the board and C-suite. However, the tidal wave of compliance requirements covering everything from PII to critical infrastructure continues to pull resources required for implementing and administering security.

Regulatory frameworks should define expected security outcomes and the penalties for failure to meet those outcomes – not dictate the means to achieve the outcomes. Today’s cybersecurity professionals are far more adept than those of the past who were pulled from other departments to meet a requirement.

With the career of most CISOs rooted in security, it’s time for regulatory bodies to trust the experts to achieve the expected outcomes of compliance, while protecting the organization’s brand and reputation in a way that enables business.

Credit: Source link

Previous Post

SASE emerges as the edge becomes an enterprise focal point

Next Post

This Raspberry Pi add-on lets you control Lego robots

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
This Raspberry Pi add-on lets you control Lego robots

This Raspberry Pi add-on lets you control Lego robots

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

March 19, 2025
Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Global Funeral Traditions Meet Technology

Global Funeral Traditions Meet Technology

March 9, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025

Recommended

The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

March 19, 2025
Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up startupnation Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media