|
|
|
|
|
by wil421
2688 days ago
|
|
The company I work at has many PCI compliant systems. I asked a security officer why they were still doing certain things the old way. He explained they very well know it’s the old way but in order to be compliant they must do it. |
|
The Compliance department has one job: passing audits. They never tell Security what to do; they document "compensating controls" and if that's not good enough for an Auditor the Compliance department will run whatever worthless compliance control themselves.
I'm not saying security compliance itself is a joke. It forces small businesses to at least try to get their shit together. But for big tech companies with real security programs, security compliance is a worthless tax.