Quantcast
Channel: THWACK: Message List
Viewing all articles
Browse latest Browse all 20490

Re: LEM Thoughts of the Week: Does Compliance Actually Make you More Secure?

$
0
0

This question started me thinking… “more” implies that you have an additional amount of security than you did before you were compliant.  So while compliance does imply a minimum level of security, it might not “make you more” secure. That will depend on where the organization started and where it ended up.

 

In the case of most small businesses that I have worked with over the years, yes they would be more secure if they could even afford to become complaint in the first place. But in reality many will just ignore the compliance issues and if something happened they would be forced to close. In that case it will not make them more anything, except maybe stressed.

 

As some of the others have mentioned, with the medium and large businesses often the compliance initiative drives IT spend which allows for the organization to become more secure. Therefore yes they are more secure.

 

In the enterprises that I have worked for compliance audits have exposed some glossed over issues and allowed them to be patched. Sometimes we received additional budgets to code to in support of the project. It also helped create process to prevent future misses. So yes, enterprise class businesses are often more secure due to compliance.

 

Though a friend of mine in a different enterprise always brags to me that they complete all of their audits with no issues found. So I guess there are a few cases that would answer no. For them, compliance is just busy work that slows down the real work they do. But how many companies is that really? (Now that I think about it…maybe he is just yanking my chain…hummm)


Viewing all articles
Browse latest Browse all 20490

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>