compliance is not security
expressiongovernance & risksecurity
The audit-season reminder that passing a checklist proves documentation, not protection.
Frameworks set floors and attackers read the same checklists everyone else does. Breached organizations with clean audits are an industry constant. The mature stance keeps both books: compliance as the reporting layer, security as the engineering it is supposed to describe.
A framework specifies a floor, assessed at a point in time, against controls written to be assessable across many different organizations. Security is whether a specific attacker can achieve a specific objective against your specific environment today. The two overlap and are not the same, and the gap runs in both directions.
Compliant and insecure is the famous direction, and there is no shortage of breached organizations holding current certifications. Controls that are auditable tend to be controls that generate evidence, which is not the same as controls that work, and a framework's requirements will always lag the techniques currently in use.
Secure and non-compliant is the less discussed direction and is equally real. An organization may have addressed a risk through a mechanism the framework does not recognize, and will fail an assessment for it. That produces the pathology where teams implement a weaker control that maps cleanly to a requirement instead of a stronger one that does not. The useful posture is to treat compliance as a floor worth clearing and an appalling ceiling, and to keep the question of what an attacker would actually do as a separate exercise that nobody is grading.