Earlier quoted context omitted.
Reminds me when I was doing PCI compliance. A PCI question asks if all outbound traffic is explicitly authorized. I took that to mean getting a list of all the IPs for the APIs of services we hit, and even constructed that entire list except for one, the payment processor itself. The payment processor did not have any stable IPs, and could not give me a list. Their official solution was to have our policy be that we…
> If such an option is allowed by PCI, what is even the point of making it a requirement? The point of all those certifications (I took companies through the processes required for PCI, SOC2, and ISO27001 ) is security theater, a path in the back for the execs, the ability to have "I'm not to blame, I have this cert" in case of some shit happening, and the ability for sales to throw TLAs to prospects to show how Seri…
The problem isn't these low bars, but rather the market for services to "help" people clear them, and the widespread perception that the bars are higher than they actually are.