Skip to content
All lessons
Objective 5.4Governance & Risk· 3 min read

Security Compliance

Summarize elements of effective security compliance

What you will learn

  • Separate compliance from security, and know why neither implies the other.
  • Name the four consequences of non-compliance and see that the fine is sometimes the least of them.
  • Explain privacy as an obligation rather than a feature.
  • Know the difference between automated monitoring and manual attestation in evidencing compliance.

The most important sentence in this objective: compliance is not security. A fully compliant organisation can be breached tomorrow, because a standard is a written minimum from years ago, not a description of today's threats. And a genuinely secure organisation can breach a regulation because it never documented what it does. The relationship is an overlap, not containment.

Compliance vs security

ComplianceSecurity
The measureConformance to a written standardActual risk reduced
TimeA snapshot at audit timeA continuous state
The driverExternal: a regulator or a contractInternal: what actually threatens you
If you stop thereYou pass the audit and get breachedYou hold up, and may be fined for not documenting it

Consequences of non-compliance

FinesFinancial penalties, sometimes calculated as a share of annual revenue.
SanctionsRegulatory sanctions: restricting the activity or withdrawing a licence. Harsher than a fine, because they stop the business.
Reputational damageLoss of customer trust. Hard to measure, and can outweigh everything above.
Loss of licenceIn licensed sectors — finance, healthcare — it can mean the end of the business, not a cost to it.
Contractual impactsLosing contracts whose customers require a specific compliance certification.

Privacy

Right to be forgottenAn individual's right to request deletion of their data. It requires knowing where all of it is — which is what exposes weak data inventory.
Data subjectThe person the data is about.
Data inventoryAn inventory of what data you hold and where. A practical precondition for any privacy obligation.
ConsentThe data subject's agreement to the processing; its limits are the limits of what you may do.

"We passed the audit, so we're secure"

Passing an audit means you matched a standard at a moment, within a scope. The standard is a minimum, the scope may exclude specific systems, and the moment has passed. If a question says a compliant organisation was breached, there is no contradiction — and it is usually asking about exactly that gap.

Real-world example: audit scope

A retailer passes a card-processing compliance audit whose scope was the payment environment alone. Three months later it is breached through a marketing server outside that scope, from which the attacker moves into the internal network. There is no contradiction: the audit said the payment environment conformed; it never said the company was secure. The failure is that the company read the certificate as a verdict on its whole security, and that the out-of-scope server carried no controls because nobody was asking about it.

What matters on the exam

  • Compliance and security overlap; neither contains the other. Any option equating them is wrong.
  • A sanction or licence withdrawal can outweigh a fine. Read the sector named in the question.
  • The right to be forgotten presumes a complete data inventory. If the question asks what blocks it, the answer is knowing where the data is.
  • Automated monitoring gives continuous evidence; attestation gives a signed snapshot. The question may ask which fits.

Quick check

Answer in your head first, then reveal.

  1. Can an organisation be compliant and insecure? Explain.Reveal the answer

    Yes. A standard is a previously written minimum, and an audit is a snapshot within a defined scope. Anything outside the scope, emerging after the audit, or not covered by the standard stays exposed despite full compliance.

  2. Which consequence of non-compliance can be harsher than a fine?Reveal the answer

    Licence withdrawal, or a sanction that stops the activity, especially in licensed sectors. A fine is a cost; stopping the business is an ending.

  3. What is the practical precondition for honouring the right to be forgotten?Reveal the answer

    A complete data inventory: knowing every place that person's data lives — databases, backups, logs and third-party systems. You cannot delete what you cannot locate.

Sign in to track your progress on this topic.

Your next step

Read the lesson, then mark it complete

Sources

Used to verify the facts. The writing is original to Passuit.