Preview Mode Links will not work in preview mode

Defense in Depth


Feb 9, 2023

All links and images for this episode can be found on CISO Series

Why do strongly supported security frameworks have such severe limitations when building a security program?

Check out this post for the discussions that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest Stas Bojoukha, CEO, Compyl.

Thanks to our podcast sponsor, Compyl

GRC solutions often cause process roadblocks within organizations. They are either antiquated and lack the functionality needed or so stripped down they can’t fix the problems you set to solve. That's why the team over at Compyl created the all-in-one security and compliance automation platform. Compyl quickly integrates with the tools you use, and automates 85% of the day-to-day tasks, all while providing complete transparency and comprehensive reporting along the way. Start your free trial with Compyl today and see all the efficiency gains you can expect from a leading solution. Learn about Compyl today at www.compyl.com/getstarted.

In this episode:

  • Why do strongly supported security frameworks have such severe limitations when building a security program?
  • Is it because the product security landscape updates with such speed and ferocity that these frameworks can't keep up?
  • Are most regulatory and third-party compliance "programs" simply non-prescriptive?
  • Is the intention to achieve compliance with every single control?