Is "Compliance Doesn't Equal Security" a Pointless Argument?
Feb 1, 2024
auto_awesome
Derek Fisher, Executive director of product security at JPMorgan, discusses the significance of compliance in a security program and the need to go beyond minimum standards. The podcast explores the difference between compliance and security, emphasizing compliance as the minimum viable security. It also highlights the importance of compliance in the banking industry and the collaboration within the security industry. The episode concludes with a mention of sponsor Reveal Security and a discussion about the benefits of LinkedIn.
Compliance serves as a benchmark for security and provides a starting point for organizations to improve their security programs.
Compliance and security should complement each other, with compliance acting as a guide for organizations to enhance their security efforts and build a more secure environment.
Deep dives
Compliance establishes a benchmark for security
Compliance is based on well-established standards and serves as a benchmark for security. While compliance is the minimum requirement, it provides a solid beginning for organizations to improve their security programs. Adhering to compliance standards helps organizations toe a collective line and forces them to do better. Compliance ensures that organizations meet minimum security standards and can be a stepping stone towards building a strong security program.
Compliance and security go hand in hand
Compliance and security are not mutually exclusive. They are intertwined and equally relevant. Achieving compliance means following industry-defined frameworks and establishing a mature control environment, lowering inherent risks and leaving organizations with manageable residual risks. Compliance can act as a guide for organizations to improve their security outcomes and embrace necessary changes. Compliance and security should complement each other, and organizations should see compliance as a means to enhance security efforts and build a more secure environment.
Compliance as a starting point for security
Compliance, although the minimum requirement, serves as a starting point for organizations to improve their security programs. It acts as a North Star, guiding organizations towards stronger security measures. Compliance regulations establish a baseline of security practices, while organizations can build upon those to create a robust security program. By implementing compliance requirements, organizations begin to see the importance of security and are prompted to invest in developing a more secure environment.
The relationship between compliance and security budgets
Compliance and security budgets often intersect, causing some tension between meeting compliance requirements and investing in additional security measures. Compliance ensures that organizations manage liability, while security focuses on managing risks. Budget constraints can lead organizations to prioritize compliance over security, potentially leading to insufficient security measures. However, compliance should not be seen as the endpoint for security investment. Organizations should aim to go beyond compliance, considering a risk-based approach and prioritizing security as the cost of doing business.
A security program shouldn't stop at compliance, but that doesn't mean we should undervalue it, right?
Why are we so quick to dismiss compliance as simple check boxes?
Why is compliance important and why is it often getting a bad name these days?
What are the elements that make a great solution?
Thanks to our podcast sponsor, RevealSecurity!
Reveal Security ITDR detects identity threats - post authentication - in and across SaaS applications and cloud services. Powered by unsupervised machine learning, it continuously monitors and validates the behavior of trusted human users, APIs and other entities, accurately detecting anomalies that signal an in-progress identity threat. Visit reveal.security
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode