Los Angeles, CA, USA (22 July 2009)—At ISACA’s International Conference in Los Angeles this morning, security professional John Pironti called for a sweeping change in how enterprises deal with information security. “Security by compliance is no longer working,” said Pironti, who is president of IP Architects and an ISACA volunteer. “The number and impact of security breaches have dramatically increased in the last couple of years, even though companies were in compliance with standards like PCI, GLBA, FFIEC, FISMA and others.” If organizations continue to focus on security by compliance, he argues, the adversaries will continue to win as their attacks become more effective and more damaging. “Compliance can be a good starting point for securing information infrastructure and data if an organization has not put anything in place previously, but it cannot be the end point of the conversation.”
- Published: 21 July 2009
- Written by NStinchcombe