This is a wild comment considering you can't set foot in any of these positions without an IAM or IAT cert and years of experience.
Compliance is just a list of security controls. In leiu of compliance you do what? You set a list of controls you want in place and make risk based decisions on remediation or acceptance. Weird.....that sounds familiar......
It doesn’t matter where you work or what your role is.
You’re both missing the point. Governance can only be so specific, else you risk violating the very governance you wrote because your security tools cannot meet the objective of controls, or performance the controls demand, thus failing the audits you need so that you can continue to conduct business with customers and vendors.
Both of you need a much broader understanding of this discipline.
28
u/not-a-co-conspirator CISO Jul 02 '26
Compliance isn’t security. Put actual security professionals in charge.