Tag: GRC

Why GRC Automation Tools Didn’t Fix Compliance

Why GRC Automation Tools Didn’t Fix Compliance

SERIES: “The Death of Compliance Theater” — Part 2 of 3 Part 1 of this series made the case that a passing audit and a secure environment are two different things, answering two different questions. This post is about a specific, well-intentioned attempt to close that gap  and why it mostly automated the wrong half

Read More
Compliant and Breached: Why Passing an Audit Doesn’t Mean You’re Secure

Compliant and Breached: Why Passing an Audit Doesn’t Mean You’re Secure

SERIES: “The Death of Compliance Theater” — Part 1 of 3 In 2013, Target passed its PCI-DSS assessment. The retailer was, on paper, compliant with the payment card industry’s security standard, the same standard designed specifically to prevent exactly the kind of attack that hit it a few months later, when attackers used stolen vendor

Read More

Categories

Seceon Inc