Compliance Unfiltered is TCT’s tell-it-like-it is podcast, dedicated to making compliance suck less. It’s a fresh, raw, uncut alternative for anyone who needs honest, reliable, compliance expertise with a sprinkling of personality.

Show Notes: Ready to Get Serious About Compliance?

Listen on Apple Podcasts
Listen on Google Podcasts

Quick Take

Compliance doesn’t have to be expensive, slow, or overwhelming. In this episode, Adam Goslin and Todd Coshow reveal the blueprint for building a successful compliance program from the ground up. Learn why the right people, documented processes, and purpose-built technology make all the difference, how to avoid costly mistakes that delay audits, and why proper scoping is critical to long-term success.

You’ll also discover practical strategies for simplifying evidence collection, improving audit readiness, and transforming compliance into a business advantage instead of a business burden.

Read The Transcript

So let’s face it, managing compliance sucks. It’s complicated, it’s hard to keep organized, and it requires a ton of expertise in order to survive the entire process.

Welcome to Compliance Unfiltered, a podcast dedicated to making compliance suck less. Now, here’s your host, Todd Coshow, with Adam Goslin.

Todd Coshow:
Welcome in to another edition of Compliance Unfiltered. I’m Todd Coshow, alongside the tea to your compliance crumpets, Mr. Adam Goslin. How the heck are you, sir?

Adam Goslin:
I am doing just fantabulous today, Todd. How about you?

Todd Coshow:
I’m doing quite well.

As always, we want to say thank you to all the folks that have taken the time to share some time with us and listen to this very podcast.

If you are so inclined, please feel free to reach out to us at [email protected]. Share your favorite ideas, your thoughts, your concerns, your opinions about the topics that we cover here, and ways that we can improve this very podcast.

Additionally, tell your compliance friends. If you’ve got somebody that you know that you think would appreciate spending some time with us, please let them know.

Finally, if you are enjoying this podcast, please feel free to give us a rating or review on your podcast app of choice. It helps in more ways than you know.

Adam, today we are ready to get serious. That’s right, we are ready to get serious about compliance.

If there’s anyone that I know that’s serious about compliance, it’s you, sir. Help set the stage on this one.

Adam Goslin:
For a lot of organizations, when they started going up against security and compliance, they didn’t have any clue when they started just how much of an investment it was going to end up being.

Maybe the organization was initially hoping they could do a check-the-box approach to compliance.

“Oh, if we just put all our crap there, everything magically happens,” or whatever the snake oil salesman was busy hawking your direction at the time.

But if you actually care about the security posture of your organization, then you know that approach isn’t going to make the grade.

You can rest assured your customers expect to see detailed proof that you are indeed taking security and compliance seriously.

More and more, it’s becoming the standard or the norm that organizations will validate and vet the organizations that they choose to trust with their data. Your organization’s going to be no different.

If your organization fits into this category and it’s time to take your compliance program to the next level, then it’s a major step forward for the organization.

You’re going to need to get strategic about making sure you’re covering all the bases and evaluating and addressing several parts: people resources, the processes that you undertake, as well as where your existing technological approach to compliance stands in the grand scheme of things.

All of those are going to come into play as you’re going through the process.

If you fall into that category, you landed on the right podcast.

Todd Coshow:
Indeed.

As part of an organization’s leveling up their compliance program, tell me more about the people they should be looking to have as part of their compliance strategy, and some of the pitfalls that organizations run into there.

Adam Goslin:
It’s all about having the right people.

One of the big mistakes that I’ll see organizations make time after time when they say, “Okay, we’re going to take compliance seriously,” is that, no offense to the assessors of the world, they just go hire an assessor out of the gate.

They think, “The assessor knows what they’re doing, and the assessor will be able to get the answers and help to get the company’s act together.”

But I wouldn’t recommend that be step one.

It doesn’t work well because the assessor, as weird as this sounds to articulate, isn’t responsible for sitting and guiding the company through a compliance engagement.

They may be happy to charge you a hell of a lot more to hold your hand and walk you through it. But effectively, the organizations that do that become the problem children to the assessors.

It’s like, “Oh my God, this is the never-ending engagement because these guys aren’t anywhere near ready to go.”

For many assessors, they’ll have a readiness notion because they’ve been burned so many times with this exact thing happening.

They’ll do an assessment up front of, “Is this organization actually ready to bring in an assessor or not?”

You’ll be having conversations about the things that you don’t have in place with the person who is charged with assessing your organization’s current state of compliance.

You end up revealing a whole ton of dirty laundry through the process.

It’s a much safer option to have those “Where do we stand?” dialogues and open conversations, not with the person responsible for doing the assessment process, but somebody who isn’t directly connected to it.

The recommendation is to bring in somebody to assist you with navigating the process.

That leads to the next point. You want to be able to have “internal conversations.”

In the arena of the notion of a compliance consultant, maybe your company is staring down compliance as a new initiative, or you’re finally stepping up to the plate because you managed to play dodgeball long enough.

What happens? The organization says to themselves, “I’m pretty sure somebody in project management or IT can handle it.”

I’ve made the joke often about how the person who ends up being the center of the compliance engagement at the organization was the last one to sit when the music stopped.

That’s pretty much the way it goes.

They nominate somebody either in project management or IT and say, “I’m pretty sure they can handle it.”

I will guarantee you eight ways from Sunday that whoever you’re thinking is probably going to be able to handle it is absolutely not going to be the right person to do it.

This is no offense. There are a lot of really freaking smart people at companies.

I’ve been doing this for a minute or three.

The breadth of knowledge that the person who sits at the center of your compliance engagement needs to have is effing gigantic.

You pick one person, a project manager who doesn’t have any idea about technology? Oh, hell no.

Even people in IT, sure, they know about the IT stuff. But if I’m in networking, it doesn’t mean I have any clue what the hell’s going on in development.

If I’m in development, I don’t have any clue what the hell’s going on in access control.

You’re picking a person who’s got a portion of the knowledge needed, and it’s going to be absolutely ineffective.

The effective compliance manager is somebody who will normally have all of the requisite background and experience.

That would be a person literally commanding hundreds of thousands of dollars a year, that type of a resource.

There are very few organizations that are big enough to handle that type of an experienced resource, dollar-wise.

Anybody who has less experience is just going to be in over their head.

You’re going to sit around wondering, “Why is the compliance program taking so long to come to fruition?”

You teed that poor person up to head down that rabbit hole.

The skills needed are deep and broad.

When you nominate somebody internally, they do not have the breadth of experience to run that compliance program.

That’s where a compliance consultant is literally one of the best damn things you could plausibly do.

You’re not asking your assessor dumb questions. You’re getting directional guidance from somebody who does have experience.

You’re not having to pay for a full-time resource and bleeding over that, but they can assist your organization.

They can answer questions. They can help with coordination. They can give you guidance for implementation. They can give you recommendations for good vendor or external third-party solutions to bring in.

If you have somebody you’ve hired who you can trust and who has that level of experience, they’ll actually be able to hold the program together and get you from where you are to where you want to be in a reasonable timeframe.

Todd Coshow:
That’s the critical piece, right?

Adam Goslin:
Yeah.

Here’s the biggest problem for organizations. That light bulb doesn’t go on until they’re far down the tracks and they’ve already made all of this wasted money, wasted effort, and wasted hours.

It’s sunk cost at that point in the game, and they screwed themselves, if you will.

They don’t figure it out until it’s too damn late.

That’s why, if you can get the light bulbs to fire in the beginning, then you’ve got a prayer of being able to go through this and make it a lot more sane for everybody involved.

When you look at who all needs to be involved in ramping up your security and compliance engagement, all of your existing people, contractors, and vendors may be playing a part in this process.

One of the advantages of having a consultant walking in with all this experience is their ability to evaluate your existing personnel, vendors, and contractors, and figure out the right mix to meet the standard.

Any compliance consultant who’s worth their salt is going to walk in and try to do their best by the organization they’re trying to help.

They shouldn’t be walking in and saying, “You want to know what you need to do? You need to lop out all of these existing people, and then you need to use these resources. Go over here and use this person, that person, this vendor, that person.”

They shouldn’t be walking in and trying to line you up with some very specific set of vendors so that you can supplant existing partners.

Some of these organizations are going to shroud it in all sorts of different bullshit, but the minute you’re seeing this unfolding in reality, there should be giant red warning lights, flags, and flares going off.

The consultant needs to be able to see that most of the resources your organization currently relies on are valuable partners.

These people have worked with your organization. They know you. There’s a trust relationship.

Whenever possible, you should be looking across your existing solutions, seeing how you can optimize them, figuring out what all can we get covered with the existing suite of folks that we have, and then looking for ways that we can fill in the remaining gaps where the current suite of folks can’t fulfill that particular element.

The consultant can also give you directional guidance on who needs to be on your internal compliance team.

That team is going to include key personnel from various areas of the organization.

There’s going to be people in there from IT, HR, legal, operations, and even more departments. They can help through all of that.

The other advantage, in terms of best practices and leveraging those, is bringing in a consultant with expertise. They ought to be walking into that party with a whole bunch of tricks up their sleeve.

As a starting point, they should be able to bring to the table starting-point policies for your organization, bringing to bear overall information security policies, acceptable-use policies, and response policies.

Anybody who has been in the compliance space for years has developed some type of proven tool set that they can use on their engagement.

It’ll be a hell of a lot easier for the organization going through it to take advantage of that.

They know that all of their policies are going to align with these particular target standards.

They’ve done it many times. They’ve already validated, reviewed, and vetted that documentation with a myriad of different assessors.

You’re not going to have to figure it out.

I’ve seen organizations where they’ll go to whatever—I’m just going to make this up; I don’t even know if the site exists—www.informationsecuritypolicies.com.

They’ll throw down X number of dollars and pull down templates.

Holy, what a fucking shit show.

Now I’ve got to figure out, within these policies, where’s the section that meets this particular requirement for PCI, ISO 27001, SOC 2, etc.?

Now you’re having to go and try to piece all that together.

It’s typically some de facto, off-the-shelf policy engine that’s probably going to spit a whole-ass ton of garbage out and just be a make-work exercise.

But if you go to your consultant to do that, you don’t need to figure all that crap out.

You don’t have to figure out how to put it together or where it needs to get attached.

They’re going to spoon-feed that over to you.

It ends up working out a hell of a lot better if you go down that route.

I can’t even begin to tell you the advantages that organizations will get when they decide to head down that route.

Todd Coshow:
I love it.

Let’s talk about leveraging the right compliance approach that fits the organization.

Adam Goslin:
It’s beyond people when you’re trying to elevate your compliance program.

You need to make sure you’ve got good processes.

Without the right processes, your people don’t have the roadmap that they need to succeed.

If you start with implementing best practices for a stronger compliance program, then you’re going to be in a much better situation.

What do you need to do right out of the gate?

The first thing is assessing your situation.

If you don’t know empirically, which most organizations starting into here don’t, what the current state is, you’re not going to know what it is you need to optimize.

Don’t make the mistake of bypassing a fresh evaluation of state.

I’ve seen very few companies that would assess their beginning point accurately.

If you’re going to take this seriously, then take these steps, period.

Start off identifying what certifications we’re subject to.

That list will come from a bunch of different sources.

Your customers will have requirements of your organization.

What requests or inquiries have we had around security and compliance standards that we need to adhere to?

In addition to the articulated stuff from the customers, keep in mind, for some organizations, let’s pretend my organization kicked off in 2008.

I’ve got from 2008 until right now worth of client agreements.

Which clients do I still have? What’s written into their agreements?

I go back to 2010, and legal was loosey-goosey. That was 847 versions of our standard agreements ago.

You have no idea what crap you’re going to unfold when you start going back and looking at it.

Way back in the day, the sales team, which consisted of two dudes, was handwriting alterations to the freaking contract language and signing off on the dotted line.

It’s all over the damn board. I’ve seen it all.

You’ll go back and review your existing agreements because it’s going to have in there that you need to adhere to this or adhere to that.

Look at the industry requirements that you’ve got.

If I’m in the medical industry, then I’ve probably got HIPAA that’s going to be applicable.

If I’m in the manufacturing arena, then I’m probably going to have ISO that’s going to be applicable.

If I’m in the financial arena, I probably have SOC requirements.

If I’m dealing with credit cards, I’ve got PCI.

Look at what you’re doing as an organization, what industry you’re in, and see what types of things are happening there.

Go consult your legal team.

Ask them, “What all things do we need to be compliant with?”

That’s another good source.

Finally, go to your competitors’ websites and see what all they’re being compliant with.

That would be another good source of making sure you didn’t forget something and making sure you’re not forgetting anything about the matrix of various security and compliance standards that you need.

Going through that exercise will clarify all of the to-dos for what we need to comply with, and it will assist with shaping the full scope of your compliance program.

The next part, from the processes perspective, is getting your policies and procedures together.

Get all those policies we already have.

Identify any policies or procedures that we’re still going to need to develop against the standards that you now know you need to do.

You’ve got the option to go with off-the-shelf policies, like I said.

But don’t try to use them as plug-and-play.

Every organization’s different. Your policies need to reflect the unique aspects of your organization.

Certainly, if you have a compliance consultant in hand, task them with getting you through that mess.

That will make the process unbelievably more efficient and more expertly done, if you will.

Then start looking into generating technical documentation.

There are four cornerstones of technical documentation that I would recommend organizations commence with when they’re starting to take this seriously.

You can work on the technical documents in parallel with your policies.

Since both of those sets are going to use different resources, you can save time by paralleling these activities.

First, your network diagram.

A diagram that’s showing where everything is on the network, where it’s physically and logically located, how they connect to one another, and things along those lines.

The data-flow diagram.

Make sure you know where information is coming from, where it is going, where we store things, how data and information are moved, and what these flows contain.

Make sure you’ve got all of the movement happening.

Keep in mind, as you’re doing the network diagram and the data-flow diagram, it’s not just your environment, but everything around it as well.

Do I have vendors that are connecting in or solution providers that we’ve got?

You need to make sure you’ve got this in its entirety for your third-party service providers, as well as your own organization.

Firewall rules.

You need to make sure that these get documented outside of the firewall.

You want to make sure that you’re documenting those offline so that if anything were to happen to the firewall, now I have a rock-solid repository of these are the rules, these are why they’re there, this is the business purpose they serve, that they’re locked down, and things along those lines.

Getting the documentation together for the firewall rules is another.

Finally, the fourth of those cornerstones is your hardware and software inventory.

Make sure that you have a list of every device and every piece of software applicable to the organization, even if it’s not currently in use.

If I’ve got some machines that are shut off, sitting in the corner, add them to the damn inventory.

That way, you know that they exist. You know where they’re currently stored or housed. You know that they’re disabled if they’re virtuals.

Get everything together in one big-ass hardware and software inventory.

Once you have those four things together technically, that gives you a real clear picture of the scope for your compliance program.

One thing that I hear from organizations is, “We’re only going to scope this portion to be the scoped portion of our environment.”

They only include their security- and compliance-scoped stuff in those various technical assets.

I would recommend the polar opposite approach.

Put freaking everything into your network diagram, data flows, firewall rules, and hardware and software inventory.

On those, put an indicator for which of those are falling into your scoped environment.

If you have a document that has it all, you can readily add a bit onto the technical documentation.

The vast majority of assessors are going to be totally fine.

As long as they understand it and it’s clearly documented—this is the in-scope stuff, this is not the in-scope stuff—then it’ll form a conversation piece for down the road.

Let’s talk about meetings.

Scheduling your status-update meetings.

Nobody likes status-update meetings, but in this case, those weekly pulse checks are critical for the success of the program.

They’re making sure nothing’s falling through the cracks as you’re getting closer and closer to that annual assessment with your assessor.

The last assessment experience that you want is to discover in front of the assessor that you don’t have all your ducks in a row.

You should be covering in the weekly status meetings who’s doing what, which tasks are outstanding, what roadblocks are getting in the way of us getting these things completed, what’s overdue, and who on the team needs a kick in the pants.

When you start using the technology arm, which will be the next discussion here, if you start using an automated compliance management system, you can quite literally get in and out of your status meetings in under 15 minutes.

It’s not that challenging.

There is a huge plus to the technology side.

Todd Coshow:
What technology should a serious company leverage, and what should they avoid?

Adam Goslin:
This is a fun arena, but you definitely want to make sure you’re adopting the right compliance technology.

If you take a look at compliance technology solutions that are already in place for your organization and for the compliance program, look for tech holes and look for a plan to cover those gaps.

The technology that you use when you’re running a successful compliance program is about keeping your operational costs as low as you can.

There are a lot of organizations that’ll make uninformed decisions about the right tools for managing compliance.

They’ll adopt tools based on upfront costs, but they don’t understand the downstream operational and personnel costs that come along with inefficient and insufficient compliance management software.

Let’s talk about an overview of some typical technology choices.

Number one, the most hated thing on my planet when it comes to compliance is manual spreadsheets.

There are so many companies that are like, “Let’s just use a spreadsheet. It doesn’t cost us anything. It’s easy to use. Everybody understands it.”

I’ll tell you what, there are lots of companies that decide to go down that rabbit hole, but I’ve never heard anybody saying, “It worked out perfectly,” or, “It was as optimized and efficient as humanly possible.”

It’s cheap and familiar, and other than that, there’s no reason to use them on a compliance engagement.

Spreadsheets are a giant pain to use. They aren’t secure. People are overriding each other’s updates.

You end up with multiple spreadsheets that get tracked.

There are multiple people trying to make simultaneous updates and data-entry errors.

“Oops, accidentally blasted these three columns on the spreadsheet.”

“Oh gosh, I deleted the wrong spreadsheet.”

What we were talking about on the last pod was the fact that most of the time, organizations will go through a whole series of astronomically painful experiences with spreadsheets.

Their final solution, finger air quotes, is to say, “You know what? We’re just going to need all these people to get out of the effing spreadsheet. We’re going to have one person make all the updates to the spreadsheet.”

Well, guess what? That’s inefficient as hell.

Honestly, if you’re a fan of lighting a match to money, then use a spreadsheet, because that’s exactly what you’re doing when you go there.

The next step that I’ve seen organizations give a whirl is that they’ve hit their head on the spreadsheet thing for a year, two, or three.

“Our compliance program is finally starting to stabilize. Let’s just go build a system that’ll be able to do this. We’ve got developers. We can make our own.”

They go down that path.

The problem is that in-house development avoids purchasing costs, and the automation does help with making the work more efficient.

But now you’re also picking up ongoing support for your homegrown compliance tool.

You’re also going to need to update that system every time the compliance standard changes.

You’re going to have bug fixes. You’re going to have the operational team seeking additional features and functionality that they want to put into it, and they’re going to need technical support.

What happens when the compliance team’s issues going to the developers internally are causing impediments for the core business operations?

“Oh my gosh, we’ve got everybody in development, heads down working on this big-ass project, and we don’t have time to go make your updates to your compliance tool that’s currently broken.”

Compliance technology keeps getting pushed to the back burner.

It’s not long before the in-house system is more of a hindrance than a help.

The compliance team is begging for resources.

In many cases, I’ve seen them say, “Fuck it,” bail from the homegrown solution, and go back to the damn spreadsheet.

It’s almost worse, but not really, because at least their fate’s in their own hands at that point and not dependent on this other department that can’t take care of them.

I’ve seen a lot of organizations take the approach where their assessor will say, “You’re going to need to put all of your stuff into our proprietary compliance management system.”

They’ll make it available to you at little to no cost.

But organizations need to be aware of the drawbacks.

If your information is in their proprietary system, number one, you don’t have control over your own data, and it’s under their jurisdiction.

Switching vendors starts to become challenging.

Let’s say the person you were using at the assessor site, your key person who you’ve used for the last two or three years, turns over.

The person who’s picking up the engagement now sucks, and you hate them.

You want to move assessors.

Guess what? Now you just lost your repository for your data.

You can’t easily port the information that you used the prior time over to the new assessor.

You end up having to go through this janky process of ditching the existing assessor’s system.

Oftentimes, the company will pick up the new assessor and use the new assessor’s system.

You’ve got the same damn problem.

I don’t have my own data.

Unless I keep all of the copies of the information on my own systems, which is a nightmare in and of itself, I don’t have a copy of everything that we used on this particular compliance engagement.

That part sucks.

Todd Coshow:
What’s the better solution?

Adam Goslin:
We built the TCT Portal based on the backs of experience with going through compliance ourselves, doing compliance consulting with a multitude of companies across a multitude of compliance standards and certifications, and doing so with a multitude of assessors.

The TCT Portal was built to be a cost-effective tool to keep everybody on track and give you all of the tools that you need to standardize and simplify your entire compliance process.

What companies find when they use the TCT Portal for the technology element is that they’re able to reduce their compliance management time by as much as 65%.

They’re able to recover tens of thousands of dollars in wasted operational costs.

They’re able to eliminate and streamline bottlenecks and painful manual processes.

They can increase the effectiveness of their overall program.

They can keep the poor person who was the central choke point from jumping off any ledges.

It also enables organizations to walk into their annual assessment with confidence.

It was probably one of the biggest game changers that I would see in clients as they’re walking into their onsites, because everything’s in one spot.

All your data and information is saved there.

You own it, the organization going through compliance, not your assessor.

That means that you retain your compliance repository year over year.

If you choose to switch assessors, it’s not painful.

You can dial down the one assessor, dial up the next assessor, and you retain your repository.

We price the portal so that it would be an absolute no-brainer for companies to leverage, because I like helping people, and that’s why we got into this arena.

Todd Coshow:
Parting shots and thoughts for the folks this week, Adam?

Adam Goslin:
If you’re ready to get serious about your company’s compliance program, then you’re going to need to address the people, the processes, and the technology.

All three of those are really critical for building a successful security and compliance program.

It is a ton of work to take it all on your own, but you don’t have to.

We’re here to help. We’d be glad to give you some assistance.

I can’t tell you how many brain cells it saves organizations when they don’t have to go in and try to figure it out themselves.

There’s nothing I hate more than companies that don’t walk in informed and don’t realize until they’ve already got an inordinate sunk cost in their compliance program that, “Oh geez, I guess we should’ve gone this other direction.”

Trying to save people from that hell as well.

Todd Coshow:
And that right there, that’s the good stuff.

That’s all the time we have for this episode of Compliance Unfiltered. I’m Todd Coshow.

Adam Goslin:
And I’m Adam Goslin.

Todd Coshow:
Hope we helped to get you fired up to make your compliance suck less.

KEEP READING...

You may also like