4 ms·
It also doesn't help that these frameworks are often dated and don't align with modern best practices. Shops have the choice to check the boxes and do things t
by fishpen0 5y ago
It also doesn't help that these frameworks are often dated and don't align with modern best practices. Shops have the choice to check the boxes and do things the dumb way or to fill out page after page after page of special exception documentation for their auditors. Most take the easy way.
And that doesn't even cover the part where PCI, SOCII, and SOX all have various bits that contradict or are not compatible with each other.
I've seen too many times where the head of security or IT or whatever picks a pre-made package off a shelf from one of the audit providers where they guarantee you will pass all of them. Then they follow it like it's law ultimately leading the swe/devop/sre groups to build out layers of shadow it/ops to actually get productive work done.
My work primarily is to jump into startups after they are acquired to make them "enterprise ready" for a bigger org and its always a unique shit show dealing with the preexisting war between their security/it orgs and their actual product development orgs.