Comply Oh My
Barak Engel · 2023
This chapter looks at the security compliance realm. It provides a primer to the nuances of different compliance standards and programs, and then shows how a compliance focus leads to worse, and sometimes plainly negative, security outcomes. It ends with a guest essay by Steve Levinson, a global expert in security compliance. The second edition chapter (5.2—Voluntary Self-Immolation) delves deeply into the world of voluntary compliance (e.g. SOC2, ISO27001), and how compliance automation vendors have taken many companies hostage to an extreme version of the failing security management process described in the original chapter. It then provides key insights for enterprises seeking to deal with TPRM in the exploding world of cloud-based software solutions.