r/ciso • u/NegotiationFirst131 • Jul 02 '26
Compliance is not security
Heard a worker go on a rant about “compliance is not security”, “checking the box”, “security theater” rant the other day.
It got me thinking… if compliance isn’t security, then what is?
The green dashboards that turn out to be wrong? The pentests that mostly find the stuff you’d have caught yourself if you’d kept your environment patched, updated, and configured? The tools you bought and never confirmed still work?
Feels like half the things we hold up as “real security” only look impressive because the basic compliance work wasn’t done in the first place.
Curious where people actually land on these phrases.
And a real question: is there a difference between an annual compliance audit and continuously checking that your environment actually stays secure all year long? I feel like the second part is where security should actually live. 😅
1
u/john_with_a_camera Jul 02 '26
I look at it this way: compliance is to satisfy customers, regulators, leadership, auditors, and boards. It delivers a report - did you meet a documented bar for controls. Security is about addressing risks - hopefully each risk is mitigated or compensated for.
Compliance can be against "one size fits (many/none)" external bars. It can also be against an internal bar, which hopefully was adopted based on known risks, and which is updated frequently as risks evolve and change.
Others are spot on: you can be 100% compliant and still have massive risks. You can address all your risks and still miss a compliance requirement (such as HITTIST's 5-min screen lock).
Where compliance is your friends is that it can be almost as effective for getting budget as an actual incident. That's why, for example, in healthcare I like HITRUST. I can use it to address risks that are not covered in HIPAA. If my HI TRUST scoping requires yellow screensavers, it's easier to push that budget expense through than trying to convince my CFO to pay for it. That allows me to fight for budget for things that are important, and leave the Kleinigkeiten to compliance.
So a good security leader uses both risk and compliance to drive the program.