From books

A certificate says that, on the audit date, a sample of evidence matched the requirements; it says nothing about the next day.

Bruce Schneier · The Process of Security · 2000 · Bruce Schneier, «The Process of Security», revista Information Security, aprilie 2000 — paragraful de deschidere2 minutes read
Security is a process, not a product. Products provide some protection, but the only way to effectively do business in an insecure world is to put processes in place that recognize the inherent insecurity in the products.Bruce Schneier · The Process of Security · 2000 · Bruce Schneier, «The Process of Security», revista Information Security, aprilie 2000 — paragraful de deschidere

The certificate is a photograph, and security is the film it was cut from.

Schneier's sentence is a quarter of a century old and still the best objection to compliance treated as a destination. A certificate says that, on the audit days, a sample of evidence matched the requirements. The system that produced that evidence can be abandoned the next morning and the certificate stays valid until the next surveillance visit. The certificate is a photograph; security is the film it was cut from. Hence the practical test for any compliance programme: if a control only works when an audit approaches, the control does not exist, only audit preparation does. The signs are easy to spot: a year of access reviews all performed in the same week; logs collected retroactively; training completed by everyone in three days. ISO/IEC 27001 is built against exactly this pattern, because it requires measurement (9.1), internal audit (9.2), management review (9.3) and corrective action (10.2). That is cadence, not an event.

Why it mattersThe surveillance auditor looks for traces of rhythm, and evidence crammed into the final week tells its own story.

The photograph —the certificateThe film — thesystem producing
The audit measures one second; real compliance shows in the cadence.

Back to the feed