Good Security Policy Names Names
TL;DR I wrote the security policies and procedures for a company against NIST CSF and NIST 800-53, and these days I ghostwrite books for the security leaders who live this
Compliance proves you met a standard on the day someone checked. It does not prove you are secure the other 364 days. These articles cover the gap between passing an audit and actually being protected, and why the certificate on the wall is a receipt, not a shield.
TL;DR I wrote the security policies and procedures for a company against NIST CSF and NIST 800-53, and these days I ghostwrite books for the security leaders who live this
TL;DR I led cybersecurity at a major national retailer for twenty years. Once PCI DSS applied, we passed every audit we faced. Now I ghostwrite books for the security leaders
If this sparked something, let's talk about turning your expertise into a finished book.