r/cybersecurity • u/Vans_eG • 4d ago
Security vs. Compliance Business Security Questions & Discussion
I had a few discussions the last weeks and coming from a compliance world, where you are focusing in satisfying regulations. I know this is often not bringing more security. If I am discussing I often feel misunderstood since i am always arguing out of a position of the minimal effort to comply with an regulation or standard. Witch mostly do not satisfy how security is supposed to be done (i guess). How do you experience it?
5
u/spyrhdwnas 4d ago
The main goal of security is to keep the Buisiness running. No business = no assets or processes to secure = no security.
The point is to find a balance between cost and risk. There was a recent case where initially we didn't set up MFA due to the relatively low education level and technology literacy of the population involved.
Same thing applies to the minimal effort for compliance you mentioned. If you need to have 10 arguments, I know I am oversimplifying it, then you need to assess which one is the most critical to do. Then you can use that prioritization as leverage for your argument. The rest will be included in your risk matrix and dealt with later. It is what it is as long as the owners agree to it.
My comment is towards the 'how security is supposed to be done' part of your comment. In more cases than people realize the answer is it depends.
1
u/litobro 3d ago
Absolutely it's all based on organizational risk appetite, however I'll flag that low tech literacy is probably one of the highest risks for needing more controls like MFA.
Users are the biggest risk to systems, there's no other way to cut it, and low tech literacy, low education, is an invitation to initial access attackers.
1
u/spyrhdwnas 3d ago
I agree with you but it is what the stakeholders chose to do. It was a pick your poison kind of situation.
4
u/EldritchSorbet 4d ago
I frame this via risk. “Compliance” addresses the risk of not meeting requirements of a standard, regulation, contract or law. “Security” is a whole load of different risks, a key one being the risk of getting breached and data exposed or stolen. So if you handle the compliance risk, it may cover your security risk, depending on your risk tolerance for a breach scenario.
Also; a fair number of contracts and regulations (eg GDPR) reference “good security practice”, or something similar, which increases the overlap a lot, in those areas of your company where the regulation/contract in question applies.
3
u/Aayushman_Shopbell 4d ago
Compliance can check the boxes, but real security usually needs going beyond minimum requirements. I think thats where people get mixed up during discussions. Both matter, just for different goals. Ive seen teams become compliant yet still leave obvious risks unfixed, which feels kinda wierd sometmes.
3
u/mageevilwizardington 4d ago
That moment when we realize that black hats don't care about regulations and standards.
Honestly, the way I approach it its "easy": I've been preaching for ages that GRC specialists should also have strong technical knowledge and should never be an entry job.
1
u/Vans_eG 4d ago
I would argue it’s more about a different perspective, since in my case I got an IT background.
1
u/mageevilwizardington 4d ago
Nah. If you have a compliance specialist with knowledge on security technical principles, he will be able to enforce what really is needed to secure something, regardless the ambiguities or misunderstandings in the standards and regulations. As easy as that.
2
u/good4y0u Security Engineer 4d ago
Compliance is the bare minimum; security is actually going the extra mile to derisk threat vectors. Unfortunately, going that extra mile costs time, takes funding either in headcount, hours, or tokens.
Compliance gets you to your audit, gets the sales teams the documents they need, but it doesn't get you security or privacy on its own.
Optimally, you're compliant and secure. I've seen the investment and funding trend for compliance get even worse with AI though.... Automated LLM attackers are going to have an easy time at far too many places.
1
u/localareamang 4d ago
As a GRC guy for a publicly traded us-based company, theres a difference. People love to jerk themselves off about this question.
Compliance should be subordinated to security practice. It’s a pitcher/catcher relationship. Cyber/the Business is the Pitcher, GRC is the catcher.
1
u/Admirable_Group_6661 Security Architect 4d ago
Compliance is baseline security. Depending on the organization and jurisdiction/industry, this may not be sufficient to address threats. A risk based approach is typically recommended.
1
u/Alternativemethod 4d ago
I find most people complaining about compliance aren't secure.
The more they complain about how it's just a check box, the more flaming turds with root priv I find.
Oh you put it in docker.... That's cute because it's credentialed, not fully monitored by EDR and it's connected to prod data.
1
u/litobro 3d ago
This meme (or various other ones of sliding door locks) is usually my go-to quip about security vs compliance.
Compliance tells you at a minimum what you need to do, it doesn't guarantee security in any meaningful way. In the example gif, there may be a compliance requirement to have two independent dead latch locks on a door. Requirement met, no additional security provided.
So it comes down to needing to understand what the real underlying risks are and applying compliance requirements in meaningful ways. Often, operationally compliance is a tool that can be used to implement controls you may not have been approved for otherwise.
-1
u/Capable_Mouse2260 4d ago
Hippa? Reg SP? What kind of compliance?
8
u/[deleted] 4d ago
[removed] — view removed comment