Regulations Are Just a Security Distraction
Full compliance should never be confused with robust security. One does not beget the other and, at times, changes called for by compliance rules can have a detrimental effect on an enterprise's overall security posture.
Most conversations on compliance eventually come around to the same point: Full compliance should never be confused with robust security. One does not beget the next and, at times, changes called for by compliance rules can have a detrimental effect on an enterprise's overall security posture.
Security practitioners take the job of defending their enterprises from known and unknown threats very seriously. CIOs and CFOs alike now need to recognize which compliance activities distract attention and resources away from managing the overall risk posture of an enterprise.
Better to be a little less compliant, and a little more secure.
Jack Phillips is a cofounder and managing partner at IANS, a Boston-based research company that focuses exclusively on the fields of information security, regulatory compliance and IT Risk Management. In this position, he oversees the Information Security Forum and Accelerator Services businesses.
regulation



