Compliance begins with laws and regulations
No company says, “I love compliance because it makes my company more secure.” Compliance is seen as a pain. Many people see it as something that slows your company down from what they need and want to be doing. As a CISO, compliance can be your ally. You can use it to bolster your security program. Maybe you want to segment your network to ensure it’s not flat. In addition, you want to segment critical assets from the main network. Your company may not see segmentation as a priority. As the CISO, you can tie the risk of a flat network into your risk register. You can review the compliance standards for your company and use a standard or framework to give your idea more weight. As an example, if your company is using the National Institute of Science and Technology (NIST) Cybersecurity Framework (CSF) as their framework, then you could leverage control PR.AC-5: Network integrity is protected, which specifically calls out...