I was talking with someone recently who rolled out whole-disk encryption to meet a compliance need. Someone told them they needed to encrypt, so they encrypted.
They do, of course, automatically log in users so they don’t have to enter their passwords. I asked, “Isn’t password authentication, never mind strong authentication, also a compliance requirement?”
“Oh yeah, it is. They all get passwords, they just don’t have to type them in themselves. Someone went down the list for compliance and checked all the boxes, but if you open a PC and turn it on it boots right up and you don’t have to log in. There wasn’t a checkbox for that.”
Classic. Simply classic.
Reader interactions
3 Replies to “The Perfect Example Of Worthless Compliance”
Sad, guess it goes to show you, Security is only as strong as the person that sets it up.
Ever get asked to setup a security system, then show it to your boss, and youre told to disable the important aspects?
Happens all the time, Im told.
[…] The Perfect Example Of Worthless Compliance (sweet mercy) […]
Just an observation – in the last few years the company I was an employee of as well as all the companies i’‘ve audited since leaving that company have been doing away with “checklist” audits due to this very issue.