The Tech Herald

NCSAM: Compliance vs. Security – Tell us where you stand

by Steve Ragan - Oct 5 2010, 20:40

When it comes to protecting your organization’s assets, such as Intellectual Property, data (customer or employee), and the actual equipment that houses all of it, which is the focus, compliance or security? Should you keep them equal or separate? Does one not equal the other?

This National Cyber Security Awareness Month topic is aimed at starting a discussion. Please leave your thoughts below, or email security@thetechherald.com to share your opinions.

According to the Verizon Payment Card Industry Compliance Report, investigators found that breached organizations are 50 percent less likely to be PCI compliant and that only 22 percent of organizations were PCI compliant at the time of their initial examination.

In short, Verizon says that these findings indicate that PCI compliance can help prevent data breaches.

Our Take:

PCI, or any given compliance measure for that matter, including all of the steps needed to obtain it, are only the building blocks to a solid security program. Just because an organization can obtain compliance for a given regulation does not mean they are secure. Compliance today cannot equal security tomorrow. Things change entirely too fast for that to happen.

In truth, compliance and security should be equal, and when plans are developed for them, they need to be a critical part of the organization’s business and growth strategy. Also, when considering compliance and security, a measure of risk assessment is mandatory. If you don’t know what it is you need to protect first and foremost, then there is no need to bother with either.

Often compliance and security come from the same department, so equality should be a given. Sadly, as is the case with many business plans, security and compliance come after the fact, and are implemented based on regulatory fear or cost alone.

For the record, we agree with the conclusions and recommendations from the Verizon report, as seen on page 25 in this PDF, and our stance on compliance vs. security aligns with them on many points.

What we’d like to know is if you agree with our thoughts, as well as those from Verizon, and read your opinions on them.

Are security and compliance things to be kept separate? If so, is this because they are simply different, or because it depends on the organization? Are they equal? If you think so, why?

Around the Web

Comment on this Story

comments powered by Disqus

From Autosaur.com

Asian Market Gets McLaren 625C

Sportscar maker McLaren have announced they will release a special model just for the Asian ...

Mercedes-AMG C63 Pictures

We have added some great pictures of the new Mercedes-AMG C63. With a 4.0 liter engine ...

Mercedes-AMG C63 Details

Mercedes have released details of their new Mercedes-AMG C63. This top end of the C-Class li...

Volkswagen Beetle Classic Model Prices

Volkswagen has announced prices for the new limited edition Beetle Classic model. The new Cl...

Chevy Colorado And GMC Canyon Ship To Dealers

General Motors have started shipping their new 2015 Chevy Colorado and 2015 GMC Canyon to de...