Artwork

Innhold levert av Adopting Zero Trust. Alt podcastinnhold, inkludert episoder, grafikk og podcastbeskrivelser, lastes opp og leveres direkte av Adopting Zero Trust eller deres podcastplattformpartner. Hvis du tror at noen bruker det opphavsrettsbeskyttede verket ditt uten din tillatelse, kan du følge prosessen skissert her https://no.player.fm/legal.
Player FM - Podcast-app
Gå frakoblet med Player FM -appen!

Podcast Preview: GRC Uncensored and the commoditization of compliance

41:30
 
Del
 

Manage episode 444512599 series 3462572
Innhold levert av Adopting Zero Trust. Alt podcastinnhold, inkludert episoder, grafikk og podcastbeskrivelser, lastes opp og leveres direkte av Adopting Zero Trust eller deres podcastplattformpartner. Hvis du tror at noen bruker det opphavsrettsbeskyttede verket ditt uten din tillatelse, kan du følge prosessen skissert her https://no.player.fm/legal.

We are interrupting our regularly scheduled podcast series to introduce you to a new series we developed: GRC Uncensored.

This pilot season will elevate conversations about GRC that are often buried under millions of dollars in marketing spend. No boring talks about controls or frameworks, just unfiltered discussions with auditors and practitioners in the GRC space. We'll be back to our regular AZT episodes in a couple of weeks.

-----

In the first episode of 'GRC Uncensored,' hosts Troy Fine, dubbed the 'GRC Meme King,' and Elliot Volkman, alongside guest Kendra Cooley dive into the complexities of Governance, Risk, and Compliance (GRC) in cybersecurity. The discussion unravels the 'love-hate' relationship many security professionals have with compliance frameworks like SOC 2, exploring how they have become commoditized and possibly devalued over time.

The conversation touches upon the challenges security practitioners face in conveying the true value of GRC to businesses, the potential pitfalls of 'SOC in a box' offerings, and the broader implications of compliance becoming a 'check the box' exercise. Moreover, the episode delves into the broader regulatory landscape and the ongoing debates about the role of government regulations in cybersecurity compliance. This candid dialogue sets the stage for future episodes that promise further to dissect the nuances of cybersecurity audits and standards.

00:00 Welcome to GRC Uncensored

01:34 Introducing Kendra Cooley

02:05 Love-Hate Relationship with GRC

03:16 The SOC 2 Debate

04:33 Challenges with SOC 2 Audits

09:10 The Value of SOC 2 in the Industry

12:04 The Evolution of Compliance Frameworks

20:39 False Sense of Security in Compliance

24:46 The Buzz Around AI and Quantum

25:10 Staying Updated as a Security Professional

26:45 Challenges in Penetration Testing and Vendor Assessments

27:37 Compliance and Its Impact on Security

30:10 Government Regulations and Their Effectiveness

32:23 The Complexity of Privacy Laws

38:29 The Role of GRC Teams in Risk Management

42:30 Concluding Thoughts and Future Episodes

  continue reading

50 episoder

Artwork
iconDel
 
Manage episode 444512599 series 3462572
Innhold levert av Adopting Zero Trust. Alt podcastinnhold, inkludert episoder, grafikk og podcastbeskrivelser, lastes opp og leveres direkte av Adopting Zero Trust eller deres podcastplattformpartner. Hvis du tror at noen bruker det opphavsrettsbeskyttede verket ditt uten din tillatelse, kan du følge prosessen skissert her https://no.player.fm/legal.

We are interrupting our regularly scheduled podcast series to introduce you to a new series we developed: GRC Uncensored.

This pilot season will elevate conversations about GRC that are often buried under millions of dollars in marketing spend. No boring talks about controls or frameworks, just unfiltered discussions with auditors and practitioners in the GRC space. We'll be back to our regular AZT episodes in a couple of weeks.

-----

In the first episode of 'GRC Uncensored,' hosts Troy Fine, dubbed the 'GRC Meme King,' and Elliot Volkman, alongside guest Kendra Cooley dive into the complexities of Governance, Risk, and Compliance (GRC) in cybersecurity. The discussion unravels the 'love-hate' relationship many security professionals have with compliance frameworks like SOC 2, exploring how they have become commoditized and possibly devalued over time.

The conversation touches upon the challenges security practitioners face in conveying the true value of GRC to businesses, the potential pitfalls of 'SOC in a box' offerings, and the broader implications of compliance becoming a 'check the box' exercise. Moreover, the episode delves into the broader regulatory landscape and the ongoing debates about the role of government regulations in cybersecurity compliance. This candid dialogue sets the stage for future episodes that promise further to dissect the nuances of cybersecurity audits and standards.

00:00 Welcome to GRC Uncensored

01:34 Introducing Kendra Cooley

02:05 Love-Hate Relationship with GRC

03:16 The SOC 2 Debate

04:33 Challenges with SOC 2 Audits

09:10 The Value of SOC 2 in the Industry

12:04 The Evolution of Compliance Frameworks

20:39 False Sense of Security in Compliance

24:46 The Buzz Around AI and Quantum

25:10 Staying Updated as a Security Professional

26:45 Challenges in Penetration Testing and Vendor Assessments

27:37 Compliance and Its Impact on Security

30:10 Government Regulations and Their Effectiveness

32:23 The Complexity of Privacy Laws

38:29 The Role of GRC Teams in Risk Management

42:30 Concluding Thoughts and Future Episodes

  continue reading

50 episoder

Alle afleveringen

×
 
Loading …

Velkommen til Player FM!

Player FM scanner netter for høykvalitets podcaster som du kan nyte nå. Det er den beste podcastappen og fungerer på Android, iPhone og internett. Registrer deg for å synkronisere abonnement på flere enheter.

 

Hurtigreferanseguide

Copyright 2024 | Sitemap | Personvern | Vilkår for bruk | | opphavsrett