The vast majority of the security "industry" is about useless compliance, rather than actual security. The chimps have put their fears into large enterprise compliance documents. This teaches the junior security people at enterprise companies that these useless fears are necessary, and they pass them along to their friends. Why? Not just because of chimps and fear, but also $$. There is a ton of money to be made off…
Compliance is useful, just not for security. * You get a cool industry certification that you can put on your website to justify the vague "we take your security seriously" platitudes we spew. * It lets you stop putting money and effort into security once you've renewed your certs this year. * You don't need to hire a dedicated security person, any sysadmin can check boxes. * You can say you followed industry best pr…
There is compliance everywhere and compliance is often complying with larger industry "requirements" or considered best practice controls.
If you start a business from scratch, I don't know any company that has developed their own controls library from scratch without complying with some sort of framework or baseline controls set.
The frameworks and control sets that you often comply exist and are there for a reason, but your mileage may vary if you choose to use them.