“We Think the Security Control Is Working” Is No Longer Good Enough

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

Security, risk, and control assessments are typically done for the sake of compliance: tools deployed, audits passed, workflows completed, boxes checked. That’s no longer enough for boards, customers, and regulators, who all want an answer to a harder question: ‘can you prove your controls are working right now?’

I often ask CISOs a version of that question, and the honest answer is usually some form of “we think so.” It’s not because they’re careless. Most control checks still happen the way a dentist visit does. When your dentist asks whether you brush and floss every day, you could fib and say yes, but one look at your x-ray tells the real story.

Security works the same way. An annual audit captures what you told the auditor, or what looked true on the day someone checked. But it may not be the ground truth.

There’s a gap between what we believe...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more