3 ms·
I work with financial software and you'd be surprised how much of all this "regulation" is based on self assessments. Auditors are looking for liability shifts,
by superzamp 7y ago
I work with financial software and you'd be surprised how much of all this "regulation" is based on self assessments. Auditors are looking for liability shifts, not real security.
- greedo 7y agoAnd auditors don't really have access to passwords etc. They can run an assessment tool to see that there's an account named "admin," but typically don't get access to /etc/shadow or passwords within applications. Now a pentester? If they don't spot this during an assessment, they suck. But pentesting isn't always performed on a rigorous schedule.
- davismwfl 7y agoI was dumbfounded by this when I was consulting prior and worked with some banks on mortgage compliance. Almost everything about banking is self assessments and reporting. It is similar to the idea of Boeing doing self testing for the FAA and reporting all is fine. Regulation doesn't bring safety or security, it brings reporting that rarely gets analyzed and even if it is there is no way it will show anything but the most blatant of fraud etc. It is akin to closing the barn doors after the horses have all left, at least the banks can say hey 10 horses left, but nothing was done to prevent it and they won't get in trouble cause they reported on it. At least that was kinda my takeaway from those jobs. I could just have a skewed version based on the stuff I worked on.