It is frustrating to see the amount of budget allocated to compliance when you consider that most of the money goes to documenting security controls, not improving defenses. One of the biggest reasons is that risk management, a carry-over from the bigger world of business, does not work in IT security.
http://www.networkworld.com/article/2160724/tech-primers/why-risk-management-fails-in-it.html
Laisser un commentaire