Compliance: The Enterprise Vulnerability Roadmap

Presented at DEF CON 16 (2008), Aug. 8, 2008, 10 a.m. (50 minutes)

Compliance is no longer new. Compliance has been accepted by the corporate-state. Compliance is common-place. Compliance is the intruders' new friend. Decision makers thinks Compliance == Security. While many compliance standards have resulted in the implementation of some very important controls, they have also left a roadmap for intruders, ill doers and the sort to hone their attack. This presentation will go over such weaknesses and show how compliance entities are, regardless of intent, proving that compliance != security.


  • Weasel - Nomad Mobile Research Centre
    Weasel is a veteran member Nomad Mobile Research Centre. Over the years he has performed deep research into areas ranging from Forensics/Anti-Forensics to Enterprise Culture to Cyber Warfare and Binary Analysis. Weasel is the last surviving international member of NMRC as Canada has been ruled too lame to be considered "international."


Similar Presentations: