4 ms·
> It's theatre, so it won't help actual security. I disagree with this sentiment. As a small firm who has undergone multiple security audits/certifications, I
by a13n 5y ago
> It's theatre, so it won't help actual security.
I disagree with this sentiment. As a small firm who has undergone multiple security audits/certifications, I have found that the controls we added were generally practical and did improve our security.
- leokennis 5y agoThis is also my experience with risk audits in IT: you get asked a lot of stupid questions and spend a lot of time engaging in extreme hypotheticals, but in the end there are always one or two “hmmm I hadn’t thought of that” moments which lead you to significantly increase your security.
- tptacek 5y agoI've seen the exact opposite thing happen: organizations that went into security engineering deficit because of stupid things they were led by an unguided audit process to believe they needed to do. Compliance is a byproduct of security, not the other way around. Never go into a compliance process without an already-clear idea of what your security practice goals are.
- irundebian 5y agoLooks that you don't have any idea of ISO/IEC 27001. ISO/IEC 27001 is actually a standard which forces you to think about your security practices and goals.