compliance

term

governance & risk

Demonstrating that an organisation meets an external requirement - which is a different objective from being secure.

The two overlap and are not the same, and pretending otherwise wastes money in both directions. A control can satisfy a requirement and stop nothing, and a genuine improvement can be invisible to the framework. The useful stance is to treat the requirement as a floor and a forcing function - it obtains budget and attention that a risk argument could not - while measuring the programme against whether an attacker would actually be stopped.

Also known as: conformity

All glossary entries