Hacker News new | ask | show | jobs
by yankeehue 2814 days ago
Government's move slowly. Security best practices are evolving quickly.

My team is working through FedRAMP/NIST compliance right now. We have sadly adopted the saying, "Security or compliance, choose one." We have literally rolled back a more secure implementation in order to be compliant. Regulations can't keep up.

I'm not ideologically against regulating the software industry, but I have doubts it can be done successfully.