EP003: Compliance Is Not Control
In EP003 of The InfoSec Control Room, Taher Amine ELHOUARI explores the uncomfortable gap between being compliant and actually being in control.
An organization can have approved policies, completed audits, risk registers, procedures, evidence, management reviews, and even certifications on the wall; while still struggling to answer very simple questions:
- Can we actually restore our critical systems?
- Who really owns this risk?
- Are our controls operating consistently?
- Does our evidence reflect reality, or was it prepared because an audit was coming?
This episode is not an argument against compliance. Quite the opposite.
Compliance, standards, audits, certification, and structured management systems can create tremendous value when they support real governance, risk management, accountability, and continuous improvement.
The problem starts when the objective quietly changes from:
“Are we improving security?”
to:
“Will we pass the audit?”
Taher discusses what he calls audit-season security, why a policy is not automatically a control, why evidence should be produced by normal operations rather than reconstructed before an audit, and why certification should be understood as part of a living management system rather than the finish line.
The episode also explores the practical relationship between compliance, audit, GRC, SecOps, management, and technical teams; and why all of them need to work from the same operational reality.
Topics include:
• Compliance versus control
• Conformity versus operating effectiveness
• Audit-season security
• Why documentation alone does not create maturity
• Evidence by design
• Control ownership and risk ownership
• Internal audit as a tool for improvement
• Repeated findings and root-cause thinking
• Making management reviews actually produce decisions
• Connecting GRC with SOC, CSIRT, and operational security
• Why compliance percentages can create false comfort
• Turning certification into continuous assurance
• Moving from requirements to control, evidence, assurance, and resilience
The key question of the episode is simple:
Compliance can tell you what should happen. Control tells you what happens.
So the next time someone says, “We are compliant,” ask one more question:
“How do we know we are actually in control?”
