4 ms·
CIO in financial services here. Most security activity is/will be driven be external forces. Auditors, regulators, etc. This tends to drive organizations towar
by dstroot 6y ago
CIO in financial services here. Most security activity is/will be driven be external forces. Auditors, regulators, etc. This tends to drive organizations towards “checklist” security. Real security professionals know that it’s not really about “can we check the MFA box” it’s about HOW we implement MFA. Unfortunately, that discussion gets squeezed in favor of “we have to close this finding by the next risk committee meeting...”.
- ImaCake 6y ago> This tends to drive organizations towards “checklist” security. I have seen the pharmaceutical manufacturing equivalent of this. No one actually cares about microbiological surveillance of drugs for animals, they are just forced to pretend to because otherwise they get in a lot of trouble.