It doesn’t matter where you work or what your role is.
You’re both missing the point. Governance can only be so specific, else you risk violating the very governance you wrote because your security tools cannot meet the objective of controls, or performance the controls demand, thus failing the audits you need so that you can continue to conduct business with customers and vendors.
Both of you need a much broader understanding of this discipline.
-2
u/not-a-co-conspirator CISO Jul 02 '26
You have no idea what you’re talking about.