Hacker News new | ask | show | jobs
by grumpyinfosec 840 days ago
GRC non-sense like this is really the cornerstone of cybersecurity. It seems like dumb boxchecking but these domains are the tools that we use to define, measure and most importantly sell security to management / main IT / users. The technical side is more sexy but then you discover that wack-a-moling the hot sploit of the week didn't really build your posture beyond the low hanging fruit.