Does Malicious Compliance Define Your Organization's Security Program?

Even with the best intentions, no law or regulation can address every possible security threat. Every organization has unique challenges, and new threats arise daily. Organizations who base security programs around only compliance are missing many security best practices and are at risk of a breach. We call this malicious compliance, and it is a constantly growing threat.

What exactly is malicious compliance? Malicious compliance comes as a result of an organization building a security program, or adhering to a set of security practices, solely around being compliant to a specific law or regulation as opposed to security best practices.

Is malicious compliance happening in my organization? Simply put, your organization may concede to this mindset if there is a belief that compliance equals security, which any good security professional knows is not the case.

How does my organization avoid the problem? While the answer is simple, the solution is complex; begin building an enterprise security program with effective management, operational and technical controls. The absence of any one of these components results in an ineffective security program. The absence of an effective security program most likely will result in a lack of compliance with industry regulations or, at the very least, a security program built around malicious compliance.

A  simple example follows, regarding a much more complex problem as to how these controls can come together to help maintain an effective compliance program.

Let’s start with management controls. When we discuss management controls, we have to begin with organizational structure. A good security program uses a top-down approach. That means an effective security program is supported by upper management and filters down through mid-level managers all the way down to hourly associates.

This is, in a sense, the only way to properly execute an effective security program. This approach is not industry specific, as Fortune 100 banks to mom-and-pop dry cleaning chains all should use the same approach.

At the end of the day, if upper management isn’t concerned with security, then why would an hourly associate care? In an organization where this approach is not executed, the only ones who care about security is the person who will lose their job in the event of a breach. Most times these people aren’t the ones with decision making power. In this type of organization, an individual or department unfairly holds most of the risk for the organization.

There is no right way to properly structure an organization, as all organizations are different. Typically in a banking environment, there will be dedicated security, risk management, and internal audit departments. In an organization such as this, all of these departments have to work together effectively and act as a check and balance system. In a smaller organization it probably isn’t necessary to split departments in this manner. The only things that remain consistent are that security should be supported from the top down, and that there is an effective way to identify and manage risk.

Second is operations. These employees perform the day to day activities including anything from monitoring to access control maintenance. The ways in which these actions are performed are dictated by operational policies and procedures.

Both policies and procedures set the tone for how the organization is to operate. They comprise the law of the land, if you will. Without these, there is no good way to communicate marching orders from upper management.

Policies and procedures cannot just be stagnant documents sitting on the company intranet of which no one knows the location. These important documents need to be constantly updated to reflect technological changes, as well as communicated to associates. Any unapproved action by the end user to circumvent these policies and procedures needs to be met by management with disciplinary action against the end user. All approved exceptions to standard policies and procedures need to go through formal change management and be documented as such.

One last note: policies and procedures shouldn’t be based solely on compliance requirements, but should also include industry best practices. Typically compliance requirements are a step behind industry best practices, and most times compliance requirements are updated to reflect industry best practices. This approach ensures that your organization remains ahead of the curve from a compliance standpoint.

Finally, there are technical controls. These are implemented to enforce information security best practices as well as corporate policies and procedures. These controls encompass everything from a corporate firewall to ensuring that USB ports are disabled on end user systems.

The level of technical controls implemented on systems in an organization typically depends on the risk associated with that specific system. For many regulations such as GLBA, HIPAA, and FISMA, a formal risk assessment must be performed before technical control requirements are implemented. The results of this assessment determine the level of controls needed to protect the specific system/network infrastructure. Although one of the most effective ways to enforce policy, typically, this area is where most organizations want to do the minimum amount required by compliance regulations. Not only do technical controls have a high association with increased cost, but many also impact the way business is done and therefore are not typically supported by upper management or line of business owners.

Let’s consider an example of how all of these components come together and how doing so can help to maintain an effective compliance program. Once again, let’s start with people. Whether or not security is supported from the top down or not, senior executives do have a vested interest in ensuring that their organization is compliant with whatever regulation to which the organization may have to adhere.

The difference between a top down approach and a “we just need to be compliant” approach is the “effectiveness” part. The latter of the two approaches pushes the organization into a program of malicious compliance. Other than the obvious issues around malicious compliance, it’s very hard to maintain compliance as such. For example, PCI requires only 7-character passwords. Let’s assume the organization simply wants to meet this minimum, but industry best practices suggest a minimum of 12.

If the standard were to change, then that organization would have to meet that requirement. Although this may seem like a relatively arbitrary task, I can ensure you that it isn’t that easy. In addition to the sometimes difficult logical changes that will need to be made, policies and procedures will need to be updated and communicated to end users as well.

However, if executive management would have actually been concerned about security and not just compliance to begin with (in a top down approach), policies and procedures would already have been created based on industry best practices to meet this new compliance requirement. In addition, the technical controls would already have been implemented to ensure that policies and procedures around this requirement were properly being enforced.

Compliance with various regulatory standards becomes much easier to manage if an organization is already aligning with industry best practices. In order to become compliant with industry best practices, all of the safeguards discussed need to be addressed.

This not only makes sense from a compliance perspective but just from an overall “doing good business” perspective. Organizations can use security frameworks such as NIST or ISO:27001-2 as good references for security best practices. Organizations can even become certified to such frameworks. Organizations that have certification and accreditation to such frameworks have no difficulty meeting the demands of either somewhat subjective compliance requirements such as GLBA and HIPAA or more black-and-white standards such as PCI.

In conclusion, much of the information provided above is fairly easy to understand -- Security 101 type stuff. The issue is not with understanding, but with articulating to organizations, that the long term reduction in the cost of compliance quickly will outweigh the short term investment needed to ensure their environment is implemented in accordance with security best practices. Unless security is made a top priority in your organization and is implemented using a top-down approach, the preceding advice will fall on deaf ears and malicious compliance will continue to plague your organization.


 

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • Busy South Africa Building Integrates Custom Access Control System

    Nicol Corner, based in Bedfordview, Johannesburg, South Africa, is home to a six-star fitness club, prime office space, and an award-winning rooftop restaurant. This is the first building in South Africa to have its glass façade fully incorporate fritted glazing, saving 35% on energy consumption. Nicol Corner (Pty) LTD has developed a landmark with sophisticated design and unique architecture by collaborating with industry-leading partners and specifying world-class equipment throughout the project. This includes installing a high-spec, bespoke security and access control system. Read Now

  • Only 13 Percent of Research Institutions Are Prepared for AI

    A new survey commissioned by SHI International and Dell Technologies underscores the transformative potential of artificial intelligence (AI) while exposing significant gaps in preparedness at many research institutions. Read Now

  • Survey: 70 Percent of Organizations Have Established Dedicated SaaS Security Teams

    Seventy percent of organizations have prioritized investment in SaaS security, establishing dedicated SaaS security teams, despite economic uncertainty and workforce reductions. This was a key finding in the fourth Annual SaaS Security Survey Report: 2025 CISO Plans and Priorities released today by the Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment. Read Now

Featured Cybersecurity

Webinars

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3