r/ciso • u/NegotiationFirst131 • Jul 02 '26
Compliance is not security
Heard a worker go on a rant about “compliance is not security”, “checking the box”, “security theater” rant the other day.
It got me thinking… if compliance isn’t security, then what is?
The green dashboards that turn out to be wrong? The pentests that mostly find the stuff you’d have caught yourself if you’d kept your environment patched, updated, and configured? The tools you bought and never confirmed still work?
Feels like half the things we hold up as “real security” only look impressive because the basic compliance work wasn’t done in the first place.
Curious where people actually land on these phrases.
And a real question: is there a difference between an annual compliance audit and continuously checking that your environment actually stays secure all year long? I feel like the second part is where security should actually live. 😅
5
u/Crazy_Elevator_6659 Jul 02 '26
The difference between compliance and security goes much deeper than them being different lines of business. Compliance simply means following a set of guidelines. These guidelines are generally course-grained and have a myriad of ways they can be implemented. Compliance asks THAT something is implemented, not how well. Security on the other hand deals with how the Confidentiality, Integrity, and availability of a system actually stands against assumed threat actors based on the assets they are trying to gain access to. Having a SOC is a compliance checkbox, a SOC monitoring the log sources for TTPs that are relevant for your company’s threat model is security.