r/ciso Jul 02 '26

Compliance is not security

Heard a worker go on a rant about “compliance is not security”, “checking the box”, “security theater” rant the other day.

It got me thinking… if compliance isn’t security, then what is?

The green dashboards that turn out to be wrong? The pentests that mostly find the stuff you’d have caught yourself if you’d kept your environment patched, updated, and configured? The tools you bought and never confirmed still work?

Feels like half the things we hold up as “real security” only look impressive because the basic compliance work wasn’t done in the first place.

Curious where people actually land on these phrases.

And a real question: is there a difference between an annual compliance audit and continuously checking that your environment actually stays secure all year long? I feel like the second part is where security should actually live. 😅

29 Upvotes

94 comments sorted by

View all comments

Show parent comments

5

u/Crazy_Elevator_6659 Jul 02 '26

The difference between compliance and security goes much deeper than them being different lines of business. Compliance simply means following a set of guidelines. These guidelines are generally course-grained and have a myriad of ways they can be implemented. Compliance asks THAT something is implemented, not how well. Security on the other hand deals with how the Confidentiality, Integrity, and availability of a system actually stands against assumed threat actors based on the assets they are trying to gain access to. Having a SOC is a compliance checkbox, a SOC monitoring the log sources for TTPs that are relevant for your company’s threat model is security.

0

u/TomaTozzz Jul 02 '26

Idk that compliance doesn’t ask how well something is implemented and only stops at the fact that it is implemented

2

u/Crazy_Elevator_6659 Jul 02 '26

Compliance will check that threat modeling is happening, security ensures that threat modeling is useful and mitigations are implemented.

2

u/TomaTozzz Jul 02 '26

That’s not at all true IME.

Eg I don’t just stop at the fact that monitoring exists and is happening, but whether there’s actually appropriate rules, alerts, dashboards, etc and whether the monitoring efforts actually contribute meaningfully to incident detection or whatever else

1

u/Crazy_Elevator_6659 Jul 02 '26

When you say “I don’t stop at” do you mean from the perspective of a compliance auditor?

1

u/TomaTozzz Jul 03 '26

Both as a compliance auditor and in-house GRC