July 24, 2022, 5:05 a.m. | /u/Unusual-Kiwi-7230

cybersecurity www.reddit.com

Is compliance(ISO, PCI) enough? Or should we also have a security assessment done to understand our security posture ?

Im trying to look for ways to improve security posture for my company but have no idea if I should propose conducting a security assessment to understand overall company security maturity when we already do compliance. Will this add unnecessary burden to the team ?

assessment cybersecurity security security assessment

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Architect - Hardware

@ Intel | IND - Bengaluru

Elastic Consultant

@ Elastic | Spain

OT Cybersecurity Specialist

@ Emerson | Abu Dhabi, United Arab Emirates

Security Operations Program Manager

@ Kaseya | Miami, Florida, United States

Senior Security Operations Engineer

@ Revinate | Vancouver