|
|
|
|
|
by bane
1075 days ago
|
|
> Being compliant within any of those frameworks does not make an organization secure. I've gotten into breathless arguments with "cyber experts" who really don't understand this simple point. I've met people in industry who literally think that "filling out the paperwork and having a risk committee accept risks or prioritize a schedule to get into compliance" equals "our systems are now secure". It's a massive self-serving industry incentivized to enrich itself and not secure systems. If they were successful at designing, deploying, and maintaining secure systems, there wouldn't be an industry. |
|