Why Compliance does not equal security?

Why Compliance does not equal security?

Being compliant is a wonderful thing to do, and in many cases, you will have no choice but to comply to be able to run your business. However, there is a common misconception floating between people is that security is achieved when you achieve Compliance. Being fully compliant does not mean you are fully secure.

By definition, Compliance means your organization meets the minimum security requirements for specific regulations at a given moment. However, security means your organization remain free from danger while operating your fully "compliant" infrastructure.

A good real-life example of Compliance is like driving a car while having the basic security settings such as seat belts, airbags, Collision avoidance system, Electronic stability control, lane departure warning system, blind-spot detection turned on. Those controls make the vehicle compliant with specific standards; however, they will not save you if you are driving recklessly or not following driving best practices.

Compliance is a practice of satisfying a set of requirements for a 3rd party to facilitate business operations. This initiative is over when the external body is satisfied.

On the other side, security is practiced for its own sake and not to satisfy anyone. Security is never done. It should be continuously maintained and improved.

 Security is a journey; being compliant is just the beginning.

----------------------------------------------------------------------------------

Would you like more interesting articles?

#Obscurity #Secrecy #Security #cybersecurity #informationsecurity #cloudsecurity #securitymanagement #infosec #incidentmanagement #cyber #cyberattack #threats #cyberdefense #privacy #cyberwarfare #computersecurity #coronaravirus #cyber #cloudsecurity #covid19 #investment #ciso #ROI #costoptimization #costsavings #CFO #cfoinsights #ssl #ciso #compliance

Yasser Elshishiny

Cyber Security Consultant | IT Solutions, Network Security

4 年

Very well said ,

回复
Peter Hansen

Information Security Manager - Northern Europe

4 年

"Being fully compliant does not mean you are fully secure.", agree. "Being secure doesn't mean you're compliant", also true "Being secure should also mean you're compliant", how it should be

回复
Ambaji N Rao

General Manager- IT

4 年

Yes, compliance is Non negotiable

Fábio Ferr?o Ribeiro, MBA

Cyber Security Manager at Getnet Brasil | A PagoNxt Company

4 年

Very interesting text!

Sylvain Cortes

VP of Strategy @ Hackuity ?? Speaker ?? Follow me on Linkedin to be updated on ?????????????????????????? and ?????? news ??

4 年

So true !!!

要查看或添加评论,请登录

Youssef Elmalty的更多文章

  • Security by Reassurance

    Security by Reassurance

    With the current wide access to information, many of us are able to acquire and analyze information that can be used in…

    26 条评论
  • Place your bet, Security or Compliance?

    Place your bet, Security or Compliance?

    Many believes that security is binary game that will lead you to win or lose. Well, this is not true.

    27 条评论
  • How to specialize in cybersecurity?

    How to specialize in cybersecurity?

    I have received several inquiries from computer science students and fresh graduates about which specialization they…

    6 条评论
  • The art of Hunting - Exposed!

    The art of Hunting - Exposed!

    Oftentimes, people presume that cyber threat hunting is a process that is highly dependent on tooling. While tooling is…

  • If you are not hunting, you will be hunted!

    If you are not hunting, you will be hunted!

    We are good. We have checked all our detection and monitoring tools, nothing abnormal.

  • You can only fight the way you practice

    You can only fight the way you practice

    In cybersecurity, many tend to believe that having incident response plan hanging around waiting for the response team…

  • Security is a journey not a destination!

    Security is a journey not a destination!

    Security is a state of being free from any predefined threats. The reason I choose the word "predefined" because…

    5 条评论
  • Are you looking for a new home?

    Are you looking for a new home?

    Yes, I am talking about homes today, but there is a catch at the end. Below are some fundamental measures that you…

    3 条评论
  • Should you invest in cybersecurity?

    Should you invest in cybersecurity?

    I get it, the cost associated with security investments is high, but I can guarantee you that the cost of doing nothing…

    2 条评论
  • What is your cyber condition?

    What is your cyber condition?

    Organizations should operate with the impression that they "are" and "will" always be under attack. If the bad guys are…