We Make Sure

David Pahlman - Compliance As Code

10 min · 10. maalis 2026
jakson David Pahlman - Compliance As Code kansikuva

Kuvaus

Compliance as Code vs Real Compliance | HIPAA, ISO 27001, and NIST 800-53 Explained Everyone is talking about Compliance as Code—automating controls, enforcing policies in CI/CD, and letting tools monitor security posture in real time. But can automation really handle the full scope of compliance frameworks like HIPAA, ISO 27001, and NIST 800-53? In this episode of the We Make Sure Podcast, David Pahlman breaks down where Compliance as Code works incredibly well—and where it falls short. You’ll learn why automation can enforce technical controls, but frameworks like HIPAA and ISO demand something deeper: governance, leadership involvement, risk-based decisions, and documented intent. If you're a CISO, security leader, compliance professional, or executive, this episode will help you understand how to balance automation with real-world compliance strategy. In this episode we discuss: • What Compliance as Code actually is • Where automation strengthens security programs • Why HIPAA compliance is mostly administrative • Why ISO 27001 requires intentional governance • The limits of automation in NIST 800-53 • The difference between proving a control exists and proving why it exists Compliance as Code is powerful—but real compliance still requires people, judgment, and leadership. Subscribe for more conversations on: Cybersecurity • Governance • Risk Management • Compliance • Leadership About the We Make Sure Podcast The We Make Sure Podcast explores the intersection of cybersecurity, governance, risk management, and leadership. Each episode breaks down complex security and compliance topics into practical insights that executives and security professionals can actually use. If you work in security, compliance, healthcare technology, or executive leadership, this channel is built for you. #CyberSecurity #Compliance #ISO27001 #HIPAA #NIST #GRC #DevSecOps #InformationSecurity #WeMakeSure

Kommentit

0

Ole ensimmäinen kommentoija

Rekisteröidy nyt ja liity We Make Sure-yhteisöön!

Aloita maksutta

14 vrk ilmainen kokeilu

Kokeilun jälkeen 7,99 € / kuukausi. · Peru milloin tahansa.

  • Podimon podcastit
  • 20 kuunteluaikaa / kuukausi
  • Lataa offline-käyttöön

Kaikki jaksot

3 jaksot

jakson David Pahlman - Compliance As Code kansikuva

David Pahlman - Compliance As Code

Compliance as Code vs Real Compliance | HIPAA, ISO 27001, and NIST 800-53 Explained Everyone is talking about Compliance as Code—automating controls, enforcing policies in CI/CD, and letting tools monitor security posture in real time. But can automation really handle the full scope of compliance frameworks like HIPAA, ISO 27001, and NIST 800-53? In this episode of the We Make Sure Podcast, David Pahlman breaks down where Compliance as Code works incredibly well—and where it falls short. You’ll learn why automation can enforce technical controls, but frameworks like HIPAA and ISO demand something deeper: governance, leadership involvement, risk-based decisions, and documented intent. If you're a CISO, security leader, compliance professional, or executive, this episode will help you understand how to balance automation with real-world compliance strategy. In this episode we discuss: • What Compliance as Code actually is • Where automation strengthens security programs • Why HIPAA compliance is mostly administrative • Why ISO 27001 requires intentional governance • The limits of automation in NIST 800-53 • The difference between proving a control exists and proving why it exists Compliance as Code is powerful—but real compliance still requires people, judgment, and leadership. Subscribe for more conversations on: Cybersecurity • Governance • Risk Management • Compliance • Leadership About the We Make Sure Podcast The We Make Sure Podcast explores the intersection of cybersecurity, governance, risk management, and leadership. Each episode breaks down complex security and compliance topics into practical insights that executives and security professionals can actually use. If you work in security, compliance, healthcare technology, or executive leadership, this channel is built for you. #CyberSecurity #Compliance #ISO27001 #HIPAA #NIST #GRC #DevSecOps #InformationSecurity #WeMakeSure

10. maalis 202610 min