The Rook
Send us Fan Mail [https://www.buzzsprout.com/2611183/fan_mail/new] A clean audit doesn't tell you whether your company is secure. It tells you something much narrower, and the gap between what the audit answers and what executives read into it is where most companies are quietly carrying real risk. In this episode, David Shaw walks through what compliance audits actually evaluate, the three places where compliance and real security pull apart inside companies (access management, detection, out-of-scope creep), what someone running a real security practice will tell the board, and the two questions every board should be putting on the agenda at the meeting after the next audit closes. In this episode: * What an audit actually answers, and what it doesn't * Why the gap between the report and reality isn't a failure of the audit * The three places compliance and real security pull apart: access, detection, scope * What a real security practice looks like, versus a compliance program * What someone running a real program will tell the board * The two questions to put on the agenda after the next audit closes Resources mentioned: * SOC 2, ISO 27001, PCI, NIST, HIPAA frameworks Connect with David Shaw: * Website: corvus-cyber.com * LinkedIn: linkedin.com/in/djshaw * Email: david@corvus-cyber.com [david@corvus-cyber.com] The Rook · Corvus Cybersecurity · corvus-cyber.com · David Shaw, CISSP, GLEG
2 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de The Rook!