IT bosses: Get budgets for better security by rating threats on a scale of zero to Yahoo!
What do you reckon US government regulations on computer security look like? If you selected outdated, contradictory and avoidable, congrats, you're an industry veteran – or you were paying attention to a talk this morning at the BSidesSF 2017 infosec conference.
In a presentation titled "Swimming upstream: regulation vs security," Robert Wood, head of security and compliance teams at healthcare IT firm Nuna, laid out the state of red tape in heavily regulated industries, and how it affects building secure networks and systems.
For instance, he said his company has to operate within eight different government frameworks for data handling and information security, and they can be more harm than good. “Most regulations were brought into being with the best of intentions,” he told his audience in San Francisco. "They were there to make things better and give us some instructions. But they do mean you end up handling crazy things.”