What is the difference between Security Assurance and Security Compliance?

Anyone who has spent any time in Information security will have heard the phrases “security assurance” and “security compliance”. You will definitely hear about them if you attend our Security Assurance vs Security Compliance talk at this year’s Leeds Digital Festival. 

These two terms will often be used within the same context, since both deal with the security posture of organisations. There are, however, some important, but subtle differences  

In this blog, we’ll give a brief introduction to both terms before providing a quick rundown of the differences between the two. 

 

What is Security Compliance? 

Let’s start with security compliance. Security compliance is the term we use to describe how much a business is operating in accordance with security standards. These standards may be organisationally produced or external and relate to many areas of security including physical, technical and procedural.  

Some organisations have a legal, regulatory responsibility to operate in accordance with specific information security and privacy standards, such as GDPR and the Data Protection Act.

In addition to legal and regulatory requirements for compliance, contractual relationships with clients might require that an organisation is certified as compliant with one or more information security standards. Examples would be 27001, PCIDSS and SoC. 

 

What is Security Assurance? 

Security assurance is a little different. Security compliance refers to an organisation’s ability to demonstrate conformance with a well specified set of security requirements. Security assurance is a broader term which refers to the confidence an organisation, its customers and partners have in the overall security posture of the organisation.  

For example, an organisation may not be compliant with a particular security control defined within a standard. However, because of other controls in place, the organisations data, and that of its customers, is adequately protected.  

 

Chris Bell one of CSP’s directors, presents this explanation at his event: 

“Meeting a level of security compliance does not guarantee that an organisation is secure, though it can be a good indicator. However, non-compliance does NOT mean that the organisation is insecure.” 

 

A high degree of Security assurance demonstrates that an organisation has robust processes, and mechanisms in place to secure its services and data, including that belonging to clients. 

 

What’s the difference between Security Compliance and Security Assurance? 

As you’ll have seen from our two definitions, both security compliance and security assurance relate to the ability to identify and demonstrate an organisation’s information security posture. Both approaches are about ensuring that organisations can operate securely in the digital world. But there is a key difference. Compliance is about achieving conformance with standards. 

Assurance is about going beyond those standards. It’s about providing a level of confidence that you and your business are doing everything you can, to protect customers and employees from threats of cybercrime and illegal activity. This confidence is provided by maintaining a constant state of awareness regarding information security threats facing your organisation, developing and maintaining mitigations against those threats and fixing vulnerabilities in the mitigations as they are identified.  

 

So, what next? 

As an organisation you must always aim to be compliant with relevant standards. Compliance should be taken as the minimum baseline that an organisation needs to meet. However, you should aim for an “appropriate” level of security assurance. The organisation needs to decide what is the most appropriate level of information security, it is not always a one size fits all approach. Also, frameworks such as the NIST CSF can be a great help when formulating security assurance approaches. 

 

To discover more about assurance vs compliance and engage in the debate, join us in person at our free event as part of the Leeds Digital Festival on September the 27th – book your free tickets here. 

For other insights and reports on other cybersecurity topics, visit our news page here. 

Leave a Reply

Your email address will not be published. Required fields are marked *