Can Compliance Be A Piece Of Cake?

  |  Compiler Team   安全防护

Compiler • • Can Compliance Be A Piece Of Cake? | Compiler

Can Compliance Be A Piece Of Cake? | Compiler

About the episode

It’s tempting to treat compliance as a simple checklist. But treating it as an afterthought can be dangerous, and can damage customer trust.

Prioritizing both compliance and security in your infrastructure lifecycle from the start is essential—especially as threats become more sophisticated. Rhiannon Hawley, cybersecurity department chair at Fayetteville Technical Community College, joins the show to emphasize why human critical thinking remains irreplaceable.

Compiler team Red Hat original show

订阅

Subscribe here:

Listen on Apple Podcasts Listen on Spotify Subscribe via RSS Feed

脚本

So if you're following that checklist and you miss one item, it's kind of like you're making a cake and you're missing an ingredient. And I can tell you from experience, that makes a bad cake. Oh yeah, exactly. Gross. This is Compiler, an original podcast from Red Hat. I'm Emily Bock. And Jennifer Scalf. On this show, we go beyond the buzzwords and jargon and simplify tech topics. This season, we're covering the fundamentals of IT infrastructure. This episode, we're talking about security and compliance. Okay. True or false. If your infrastructure is compliant, it means your infrastructure is secure. No, no, no. Why is that? The security of your infrastructure is what you've done to it to secure it from whatever threat that you think might be coming at you. Yeah. It's literally the physical activities. It's the setting up of the firewalls. It's the air gapping. It's if you have it on the public internet, if you have it on your internal internet, access controls, that's your security. It's what you've actually physically done to prevent threats. Compliance is a checklist of if you've done those things or not to meet some regulations and recommendations and requirements from whatever industry you're in. I think that's probably the quickest summary of that. What do you think, Emily? Yeah, no, I think that makes sense to me because I kind of think of compliance as, in a lot of cases when it comes to security, the baseline, like must be this tall to ride. So you got to check off the check marks to feel like you're even covered as you need to be. Does that make sense? Oh, I love that analogy so much because first of all, I love rollercoaster. You need to know that about me. But also it goes along with, so depending on which rollercoaster you're riding, you have to be a different height for your baseline. Exactly. Our analogies and metaphors are beautiful. So if you're in the federal government, they have FedRAMP. We hear a lot about NIST. There's a lot of different compliance certifications, things like that. So you've met these. And I said checklist right off the bat, and some folks think that's kind of a negative way to think about it, but it's easy for my brain. Here are the basic requirements, you've met those requirements. Yeah. And I say checklist not as like a just check the box and don't actually care about it, but more of like a surgeon would do. You have to go through the checklist to make sure you did not forget anything. Perfect. Much better use of checklist and rollercoasters. And then the security is what they did to strap you in, what kind of seatbelt, what you physically put into the rollercoaster. Yeah. I'm just going to keep going with rollercoasters this episode. No, I think that makes a lot of sense. And there's a lot of compliance standards around security, but there's also compliance standards for other things like accessibility of websites or areas or, I don't know, those are the ones that come to mind. But I think they overlap a lot, but they're not necessarily synonyms. I agree. Here to expand on this idea is Rhiannon Holley. She's the department chair of cybersecurity at Fayetteville Technical Community College in Fayetteville, North Carolina. And she helps students understand the relationship security and compliance has to the rest of IT infrastructure. We tell them that the most valuable way to approach security is to understand the underlying fundamentals and then see security as the layer of frosting on top because you can't secure what you don't know. There's so much emphasis on the technical hands-on and application of how do we secure the systems that really once we start talking about policy and compliance, it's a matter of, "Oh, well, that's an afterthought." So what we're trying to do is put more emphasis and focus on starting with the compliance and policy with the understanding that compliance is not security. I always like a cake frosting metaphor. Right. It's a sweet analogy. Exactly. And halfway through that, I switched analogies in my head. I like the cake one, but I like what she said about starting with compliance and policy because it's really easy to fall into the trap of thinking of that compliance checklist kind of concept as grading how well you've done already. But it's an open book test. If you build it around the actual requirements, that's a lot easier. Wait for it, Emily. If you bake it in. If you bake it in, yes. All right. Full circle. Very nice. Dessert aside, I also want to know the consequences of this gap we're seeing. Well, frankly, it's trust. Trust on the part of the customer. And I mean a company can look compliant on paper, but if a breach occurs because they treated security like an item on a checklist, that trust is gone. Let's just face it, most individuals, especially outside of technology, don't know what that means. They know trust. They know what that means. So if I as a customer, I as a client cannot trust you to properly manage and secure my data, then well, there goes your business. Although it may seem like the smallest part or the smallest consequence, if you will, that has lasting impact, negative impact to a business. Yeah. So if you're following that checklist and you miss one item, it's kind of like you're making a cake and you're missing an ingredient. And I can tell you from experience, that makes a bad cake. Oh yeah, exactly. Gross. Yeah. Well, and I like what she said about trust there as well, because not only is there maybe a real tangible effect of missing something in that kind of security compliance checklist, but you also damage trust on the part of the customer because that compliance badge makes them think that, "Yep, I've got all my stuff together. Everything's cool. You can trust me." And that feels like a betrayal of that. Yeah. And it's a lot of work, a lot of time and money to repair it afterwards. I can think of a few big ones over the last 10 years. I'm not going to name them. It's not a name and shame kind of situation, but folks can think of them where they had to do so much work afterwards. It's so much easier to just go ahead, and I'm going to keep going back to that checklist because it's just to make sure that you've done the things that you're promising. You're trying to build that trust, you're trying to build that security. And if you break that trust and security, the amount of time and money that comes after to repair that relationship. Fortunately, I have seen some... I got to stick to the positive a little bit. There have been organizations that have been able to rebuild that, but it's so much easier to do it ahead of time. Very much so. Much easier to break down trust than build it back up again. And so I think it boils down a lot to what an organization does after an incident, which can be just as important as what they did before. Exactly. And the stakes here are so high because we're talking about literally, in many cases, extremely sensitive data. Even companies that think... Again, I don't want to name any, but they're thinking, it's a kind of a frivolous website they're running, but there is still usernames, passwords, social interactions, even the most frivolous still. There is a security element that if they go through and they get certain certifications, and they don't have to go the whole federal government level certifications, but there are some open source ones out there now that they can walk through that's very easy. Yeah. Well, and speaking of compliance, one of those checklists, so to speak, is the GDPR- Oh, great example. ... around personally identifying information. And there's real tangible harm that can come from missing on some of those things, I think. Not just to the vendor who's providing the security in this hypothetical, but also to the company paying them and the customers using that company's product. So there's a lot more stakeholders in play than you might think. So earlier you talked about compliance as a thing we have to do. So how much of the operational parts of compliance are up to a company's choices? I would actually reframe it just a little bit from choices to more the industry they're in. A lot of the folks that I work with are very much focused on what would their security team or what would industry standards or what would their customers knowing what the compliance certifications and things that are needed? Mmh-hmm. I keep kind of going back in my head to this notion of a checklist. I love how you reframed it earlier to something positive. No, we're going through a checklist to literally make sure we hit all of these things. Because I'll be honest, day-to-day, it becomes a little bit of a slog sometimes, especially if you're in the know and you're like, "Oh, why am I doing this again?" Yeah, no, definitely firsthand experience there. Right? So it is a positive. We are trying to help folks. The reasons these exist are to help folks make sure that they are meeting the baseline security based off of their industry. But the choices internally to the company, how do they enforce those? How do they monitor that they're actually making the changes with their security policies internally? All of that is really going to matter a lot on that, I mean I'll go right to it, the culture of the company. Yeah. So it's a little bit like we were talking about before, which is there's a big difference between going through the checklist at the end as you're releasing something to see how you did versus building your security around addressing compliance standards. Those are very different perspectives that will have big implications for how you implement things. Yeah. And then it goes to the life cycle of whatever it is you're releasing internally, externally, however. If you bring in your security team or your compliance folks early on, now I'm putting my architect hat back on, don't wait until you get to wherever in your lifecycle. Every company uses a different process to figure out the life cycle of their software. We've talked about CDCI pipelines. We've talked about all these various ways of handling that, but just don't wait is the best, especially if you know you're in a sensitive industry. Yeah. It's the difference between studying a little every day and cramming right before the test. Yes. Great analogy. I still want to figure out how to get a rollercoaster analogy back in there, but I've lost it. It's gone. Bake it in though. We'll go with the cakes. I like the cake. Bake it in. I do like the cakes, but I will say the last thing you want on a rollercoaster you're riding is to know that they'd only checked the safety standards at the very end. Oh, good point. Yes, definitely. I think they all stand. They all hold weight, frosting. I don't know. I've gotten them confused. I love it. Okay. Coming up, we're going to discuss how the operational methods around compliance are changing. And yes, it's a segment about AI, but emerging tech isn't just changing how we work. It's also changing how we think. More on this after the break. Before the break, we were shifting the conversation to operational realities. Jennifer, why do audited compliance systems still fail? The reality? Human nature. People tend to set it, forget it, especially if you have these longstanding massive environments where it's very easy for something to just stay in place. It's not broken, don't fix it. Yeah. "I checked the box once. Isn't it good forever?" Exactly. And that's how regulations can bump up against each other. If they were set long ago one way and the regulations changed, and now we have to go back and review those systems. Oh my goodness. Being in the Linux community, the whole situation with California in terms of quote, unquote, "banning Linux" because it cannot manage users' age. So there was and still currently is a discussion around California in regards to Windows verifying age. Linux doesn't have that capability. Therein lies everyone saying that, "Well, it's going to be banned." That's introducing even more questions when it comes to things like privacy or access control, and that's going to introduce a new situation where standards start to overlap. Yeah, that's a lot of operational complexity there. Yeah. And another thing, now this is going to be a bit controversial, but let's talk about. Yes. Please. Live for controversy. I know, right? Hot take. Modern humans love convenience. And I'll also throw in there my deepest sympathy for the people that are maintaining all of these massive infrastructure complexities because they're craving the convenience to be able to manage in those incredibly complex environments. Yes. So when I hear, oh yes, in such and such state, such and such geo, such and such country, there are these regulations now or those. Sometimes they sound completely out there, but it's people trying their best to make sense of extreme complexity and dangers. They feel like actual danger around some security situations and privacy. And in this situation, I believe she was referring to some of the trying to protect kids. So we can't look at it as like, "Oh no, it's just kind of nuts. They're out there trying to make our lives more difficult." No, these are folks who have their hearts in the right place, but how on the backend do we- Yeah, how do you manage that? Yeah. How do you manage this and when it changes so quickly? So I have a lot of sympathy. And in our day-to-day lives, we're using systems that have gotten seemingly simpler over time. Our cell phones, our laptops, the interfaces have gotten more simple. We're not writing assembly language code anymore. We're not writing any code anymore. We're clicking on buttons in WYSIWYG. That's something I talk about with the engineers a lot is that concept of you don't actually simplify things, you just hide the complexity somewhere else. Yes. I was going to say, do the kids use the word WYSIWYG anymore? I don't even know. I still do, and now I don't know if people know what I'm talking about. Anyway, so that's a breadcrumb. Go look into that. If you don't know what it is, WYSIWYG is what you see is what you get. So it's like a UI on top of things. You see it a lot in website building tools. So I can completely understand why folks would want to simplify a lot of this. However, another thing that I have to throw in there, if you guys want to talk about that later, is in the 3D printing world, people are trying to put in a lot of very well-meaning regulations right now. Yeah. I'm not going to go any further. That's another breadcrumb if people want to go look into it more. You can really go down a lot of trails with this. That's what I was going to say is that it's not just your infrastructure and then they have to meet this set of regulations. It's that there's lots of sets of regulations and compliance standards and you have to meet in some capacity all of them. And there's lots of overlap, and in some cases conflicting requirements. Exactly. And it is a mess to keep track of. It really is. Anyway, my heart is with them. So we've got some different options. Yeah. Well, and I think part of that comes with tooling. We're talking about convenience, and there's more and more and new, better tools to help with some of these compliance things. And I think it's very easy to fall into just trusting the convenience. Not seeing what's happening underneath, behind. Kind of brings you back to the, "Oh, I checked the box. I used the tool. It said it was fine." And you really have to be diligent and disciplined about double checking. Yeah. And I really need to put a more positive spin on that box checking. Well, it takes you back from that operation room. Did we check off everything on the list? Did we remember everything? It brings you back to the, "Oh, I checked the box. Who cares?" Exactly. And I think Rhiannon would agree with all of this. I believe that they see it from, "Oh, well, I've set this once and I can leave that there." But especially when you're taking that approach and trying to correlate that to say enterprise security, you can't configure it and leave it. Technology changes, but more than that, users get added, applications get added, updates get pushed. I think we were prescient in some of the things we were saying before because things change and tools alone aren't a silver bullet, but those tools are meant to amplify human practices and not replace them. And ignoring that creates the exact scenarios attackers look for. The attackers, threat actors, bad actors, whatever you would like to label, they're not wasting time and their systems are not wasting time trying to break down a barricaded door. These attacks are coming from simple oversights. And so I think that misconfigurations, whether it's professional or educational environment, oftentimes it's either out of sight, out of mind, a lack of visibility into the infrastructure, or just simply being human. Both security and compliance are meant to be hands-on and not hands-off, which kind of brings us to the inevitable topic, AI. So she just mentioned, and in the past it is true that usually it was the lowest hanging fruit that attackers were going after. There was the zero-day and the long available exploits. You guys, there's been exploits out for a mind-bogglingly long time in my world that because folks hadn't updated, they were still vulnerable too. And that is very true. But with AI now, we've got, I hate to say it, the double-edged sword. So we've got the tools that we can use to combat some of those, the low-lying fruit, as I'll call it, the easier, how would she say it? The things that are the most easiest to exploit. But now we've also got both. We've got folks using AI to find and chain together. And this is right now when we're recording this, a lot is coming out. And Emily, I know you're in the middle of it too. We're kind of overwhelmed with the number. Oh, yeah. It'll actually be interesting to see what's going on when this actually airs because it moves so fast. Because they're chained together using AI tools. And so now we're not just using the tools to protect ourselves. It's just it's constant cycle. Exactly. And I do think there's a little bit of hype. Don't get me wrong, I'm not totally bought in. Okay. But it's a very powerful technology that can be used for good. And just like the best people say, with great power comes great responsibility. I do think there is a fear of over-reliance on the tools also that we're going to break down some of our own human critical thinking. I've already kind of felt that a little bit. What about you? You think so? Oh, I feel it happening for sure. And I know Rhiannon has some thoughts on this too. She read an article about it before we spoke with her. And in this article, they discussed something called thought atrophy. For example, we're trusting AI now over our own thinking. In AI, we trust is almost what it seems like. And with that, I think comes the implication in regards to security. I think that's exactly what we're talking about is that breakdown of critical thinking skills. And I don't want to over hype it like I don't think it's literally destroying our brains or anything, but I will say I like the phrase thought atrophy because I think that kind of captures it. So I think of it kind of like if you've ever learned another language. So for example, in high school I learned Spanish. In college, I learned Japanese. And it has been an undisclosed amount of time since that happened, and now I speak neither. So it's that you have to practice and exercise things to keep the skill strong. I love it. And it's really easy to just let AI do the hard part for you. I love that we're all thinking the same on this topic. That was amazing. Yeah, that's exactly where I was going, though atrophy and on all sides of it. So we have to keep our critical thinking skills up to be able to continue to produce tooling that can combat some of this extremely complicated and long-term, I mean we're going back decades now that these AI-powered, let's call it maybe penetration testing. I mean, I'm going to use the word pen testing. I think people know what that is. But these tools are doing it in such a way that, and I can't stress enough that they're chaining things together. I'm trying to make things. This is terrifying for people that are in the security community, but we also get it and we know that that's what they're doing. So that's good. That gives a little bit more trust. It's like next level pattern recognition. Yeah. And so there's a place for your critical thinking skills, folks, that are listening to this right now. What you've developed in your lifetime throughout your human experiences, there's a place for that. We need that, continue doing that. Don't let that atrophy. And I keep saying because it's just like I want to put so many different ideas together into one. I want to chain them together like our AI systems can. No, I think that's exactly right though, is that it's a very powerful tool, but like AI itself, it's not evil. It is not destroying your brain, but you do still need to use human thought. And I do want to go back just for a second. I love that you learned a number of languages many years ago. So did most of us, and then we lose that as time goes by. And now I'm going back and I'm not going to subject the folks listening to my incredibly bad Spanish that I've been trying to relearn. But I say this with all love in my heart. It also has helped my brain to not atrophy by thinking about things differently. Learning a new language is a great example for fun, for friends. It's a great example. However, I do now pronounce English words different because I'm trying to learn. So American English versus. And so I've got some friends that might be listening to this right now who I have subjected to my incredibly bad limited Spanish with a thick American accent. So I want to apologize, but also bring that up as another example that we can't let our brains atrophy. That's critical thinking that I will continue to use. So just good luck everybody. That's actually what made me think of it earlier because I was trying to string together a sentence in Spanish and it was a mess. I was throwing Japanese words in there. I forgot all the grammar. I don't know how to conjugate things anymore. It comes back if you practice it. [foreign language 00:23:56]. That's all I'll say. Well, it's kind of like using AI in that perspective would be using Google Translate versus learning the language. And you can decide which one you want to do for which situations. Exactly. We have the tools. Use them where they should be used and keep your skills sharp within yourself to continue to also be able to chain these together yourself. Yes. Well, and to help come up with solutions for those new creative ways to, I don't know, ruin things. Oh my goodness. I love it. So I think ultimately if a sysadmin uses AI to generate complex configurations without understanding the underlying mechanisms that make it work, you see that chain, but you don't understand why the environment is vulnerable and therefore how to prevent it. And we've done this, for those of us who have been in the industry a long time, this is not the first time something has come along that seems to obfuscate. And so there are lots of things over the years that have made the underlying parts of IT infrastructure hidden. And the people that continue to understand how those pieces work continue to build and grow. And those of us who just move on up, I have not done any assembly language coding in 20 some years, but it's back there somewhere. The data structures are back there. But if you can continue to build and grow on top of that, there's a place for that. But those of us who have to keep everything secure, meet these compliance, let's go back to the compliance and regulations, you still need to know how all that works. You still need to know why. Oh, and it's so hard these days when you can just hit a button and it writes all the code for you. Oh yeah, it's so tempting. But go back and read it. Yes. Because you don't know what that is doing anymore. And if your job is to know what that is doing and to make sure you're compliant, you have to keep backing up and doing it. You have to give your space and time to do that. And it's very hard right now. I want to sympathize again with everybody who's involved. Yeah, and we're talking about human nature and the inherent temptation of convenience. And I think we can't put it on individuals to do it right, go back, read your code that it generated, et cetera, et cetera. I think we need to be building into processes and regulations and things making that happen, because otherwise we go back to the checklist and, "I checked it off. Isn't it fine?" Yes, exactly. Oh my goodness. Such a terrifying idea of who regulates the regulators. But anyway, let's not go all the way down into that right now. Yeah. Point is it can't be individual responsibility to make sure that these things are working right. Exactly. Oh, it's so complicated. But anyway, going all the way back. We can't let ourselves atrophy though. Exactly. And speaking of going back, we talked about a lot of things, and I want to make sure I remember. We started off talking about compliance and security, how they're different. They're not exactly the same thing, but there's a lot of overlap. We talked about how difficult it can be to manage the interplay between those two, given the complexity and sprawl of infrastructure, and also the number and differences between regulatory bodies or compliance checklists that you have to be looking at. There's interactions between all of them. Enter tools. Tools can be really helpful to help manage that interplay between security, compliance, keeping all of your infrastructure good, but you can't let it replace entirely the human aspect of it despite the fact that it can be super convenient to do so. Yes. Oh, you got it. I think that was kind of the highlights that we touched on there. I always enjoy how you summarize these. This is amazing. I'm like, yes, we said so much. We made so many analogies. There was a rollercoaster in there, remember? Exactly. There were cakes, all kinds of stuff. Oh, baked in cakes. And so I got a summarize or I won't remember. The real crux of it is, can't leave an episode without talking about AI, AI is an excellent tool for efficiency, but it only provides an answer, not the answer. So keep your human brain involved. And true security and compliance still relies entirely on human curiosity, innovation, understanding the why. Attackers are constantly pushing the envelope and experimenting. The good guys need to do the same. Exactly. So you've heard us talk a lot already. Now it is your turn. Hit us up on social media at Red Hat and use the hashtag Compiler Podcast. And that does it for this episode of Compiler. This episode was written by Kim Huang. Thank you to our guests, Rhiannon Holley. Compiler is produced by the team at Red Hat with technical support from Molly Brock. If you liked today's episode, follow and review our show on your platform of choice. See you next time.

About the show

Compiler

Do you want to stay on top of tech, but find you’re short on time? Compiler presents perspectives, topics, and insights from the industry—free from jargon and judgment. We want to discover where technology is headed beyond the headlines, and create a place for new IT professionals to learn, grow, and thrive. If you are enjoying the show, let us know, and use #CompilerPodcast to share our episodes.