1 Comment
User's avatar
Jeff Hall's avatar

I think the only piece you are missing here (and what a LOT of people miss) is that a risk-based approach to security gives you the compliance side of the equation as long as your program covers all of the domains of all of the compliance programs your organization needs to cover.

Expand full comment