{"id":23346,"date":"2018-12-13T02:51:21","date_gmt":"2018-12-13T02:51:21","guid":{"rendered":"https:\/\/staging.sightlinemg.com\/c4isrnet\/uncategorized\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/"},"modified":"2026-08-08T18:14:08","modified_gmt":"2026-08-08T18:14:08","slug":"does-it-compliance-mean-good-cybersecurity-experts-disagree","status":"publish","type":"post","link":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/","title":{"rendered":"Does IT compliance mean good cybersecurity? Experts disagree."},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The way some in the United States government and the private sector describe it, the cybersecurity checklists provided by the National Institute of Standards and Technology are onerous requirements that do not automatically translate to better protection. To others, the NIST framework is a battle plan to defend American government and private networks from an onslaught of hackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But to all, the NIST guidelines are at the center of a debate about how \u2014 and if \u2014 the United States government and American businesses can protect sensitive data amid what intelligence and Pentagon officials call a sustained campaign of hacking from China and other foreign countries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The NIST guidelines provide a framework for how every federal government agency from the Pentagon to the U.S. Postal Service should protect its computer networks systems. Even some businesses voluntarily choose to comply with them because of their comprehensive approach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To Ron Ross, a fellow at NIST, the argument that compliance with the standards does not equal cybersecurity security is frustrating.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cYou get this false argument that you are compliant but not secure. No, compliance does work,\u201d Ross said. &#8220;Compliance has to be thought of not as a checklist but as implementing a good risk management program and approach to all of your information technology assets, all your systems and networks.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhen you simplify the discussion to whether you are compliant or not, that makes no sense. Because compliance is following the NIST guidance, which is risk-based,\u201d Ross said, adding the NIST standards include understanding threat actors, internal vulnerabilities and trying to reduce attack surfaces. For him, these are hardly a box to check off, but rather an approach to good cybersecurity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As soon as next week, NIST will release its new risk management framework, which includes a new step that requires senior leadership to be involved earlier in the decision-making process when it comes to security and privacy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Also upcoming are changes to the federal government\u2019s guidelines on <a href=\"https:\/\/nvd.nist.gov\/800-53\">security controls<\/a> and requirements to access <a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-171\/rev-1\/final\">controlled but unclassified information.<\/a> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cPeople say that all the time, &#8216;Compliance is a checklist and just because you are compliant doesn\u2019t mean you are secure.\u2019 That\u2019s not how we interpret compliance,&#8221; Ross said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Others disagree with the assessment of compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tom Etheridge, the vice president of worldwide services at threat intelligence firm Crowdstrike, said \u201cbeing compliant and being secure are two separate things.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe have had a couple of commercial organizations call us up this year and they have said, \u2018We just got done with our NIST compliance audit and we passed with flying colors, and now we want you to run a red team up against the organization,\u2019\u201d Etheridge said. \u201cThe red team is in within a day and the customer is like, \u2018Thank god I am not relying on my old NIST-based compliance audit.\u2019\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Etheridge also pointed to an example of a small government contractor who was \u201cfully compliant with federal requirements\u201d but was still hacked by a nation-state actor, likely through a web server vulnerability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIf the government said a particular control was good enough, they implemented it and moved on. They were fully compliant, but in the end, suspected nation-state actors were able to infest their systems for years,\u201d the company\u2019s 2018 casebook says.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some government officials have also told Fifth Domain that they feel burdened by the \u201cchecklist\u201d security approach that is taken hold inside the U.S. government. One echoed the thoughts of Ethridge, saying that compliance does not equal security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, experts still say that the frameworks play an important role in cybersecurity, even if sometimes it\u2019s just a preliminary one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST standards \u201care not the end all be all, but they are really great step to get you where you want to be,\u201d said Dan Medina, director of strategic and technical engagement at cybersecurity company Glasswall Solutions. \u201cQuite frankly, if you are still using those checklists, then you might be ready for a new job because you should be well past that.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The NIST guidelines are at the center of a debate about how \u2014 and if \u2014 the United States government and American businesses can protect sensitive data<\/p>\n","protected":false},"author":7,"featured_media":26413,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":13,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[106,29,13,32],"tags":[],"coauthors":[2917],"class_list":["post-23346","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-daily-brief","category-home","category-industry","category-newsletters"],"acf":{"subheadline":"","legacy_arc_id":"LW7AMYT65FHO5EWKDSWUATZTOY","arc_canonical_url":"\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Does IT compliance mean good cybersecurity? Experts disagree. - C4ISRNet<\/title>\n<meta name=\"description\" content=\"The NIST guidelines are at the center of a debate about how \u2014 and if \u2014 the United States government and American businesses can protect sensitive data\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Does IT compliance mean good cybersecurity? Experts disagree.\" \/>\n<meta property=\"og:description\" content=\"The NIST guidelines are at the center of a debate about how \u2014 and if \u2014 the United States government and American businesses can protect sensitive data\" \/>\n<meta property=\"og:url\" content=\"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/\" \/>\n<meta property=\"og:site_name\" content=\"C4ISRNet\" \/>\n<meta property=\"article:published_time\" content=\"2018-12-13T02:51:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T18:14:08+00:00\" \/>\n<meta name=\"author\" content=\"Justin Lynch\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Justin Lynch\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/f1587e1f8c0d41f0683bf42b02602ad8\"\n\t            },\n\t            \"headline\": \"Does IT compliance mean good cybersecurity? Experts disagree.\",\n\t            \"datePublished\": \"2018-12-13T02:51:21+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:14:08+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/\"\n\t            },\n\t            \"wordCount\": 672,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/NIST.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Daily Brief\",\n\t                \"Home\",\n\t                \"Industry\",\n\t                \"Newsletters\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/\",\n\t            \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/\",\n\t            \"name\": \"Does IT compliance mean good cybersecurity? Experts disagree. - C4ISRNet\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/NIST.jpg.jpg\",\n\t            \"datePublished\": \"2018-12-13T02:51:21+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:14:08+00:00\",\n\t            \"description\": \"The NIST guidelines are at the center of a debate about how \u2014 and if \u2014 the United States government and American businesses can protect sensitive data\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/NIST.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/NIST.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/2018\\\/12\\\/13\\\/does-it-compliance-mean-good-cybersecurity-experts-disagree\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Industry\",\n\t                    \"item\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/industry\\\/\",\n\t                    \"ad_zone\": \"industry\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"Does IT compliance mean good cybersecurity? Experts disagree.\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"description\": \"Media for the Intelligence-Age Military | C4ISRNET\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/#organization\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"caption\": \"C4ISRNet\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/f1587e1f8c0d41f0683bf42b02602ad8\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/c4isrnet\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Does IT compliance mean good cybersecurity? Experts disagree. - C4ISRNet","description":"The NIST guidelines are at the center of a debate about how \u2014 and if \u2014 the United States government and American businesses can protect sensitive data","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/","og_locale":"en_US","og_type":"article","og_title":"Does IT compliance mean good cybersecurity? Experts disagree.","og_description":"The NIST guidelines are at the center of a debate about how \u2014 and if \u2014 the United States government and American businesses can protect sensitive data","og_url":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/","og_site_name":"C4ISRNet","article_published_time":"2018-12-13T02:51:21+00:00","article_modified_time":"2026-08-08T18:14:08+00:00","author":"Justin Lynch","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Justin Lynch","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/#article","isPartOf":{"@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/"},"author":{"name":"migration","@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/#\/schema\/person\/f1587e1f8c0d41f0683bf42b02602ad8"},"headline":"Does IT compliance mean good cybersecurity? Experts disagree.","datePublished":"2018-12-13T02:51:21+00:00","dateModified":"2026-08-08T18:14:08+00:00","mainEntityOfPage":{"@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/"},"wordCount":672,"commentCount":0,"publisher":{"@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/#organization"},"image":{"@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/#primaryimage"},"thumbnailUrl":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/NIST.jpg.jpg","articleSection":["Daily Brief","Home","Industry","Newsletters"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/","url":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/","name":"Does IT compliance mean good cybersecurity? Experts disagree. - C4ISRNet","isPartOf":{"@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/#website"},"primaryImageOfPage":{"@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/#primaryimage"},"image":{"@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/#primaryimage"},"thumbnailUrl":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/NIST.jpg.jpg","datePublished":"2018-12-13T02:51:21+00:00","dateModified":"2026-08-08T18:14:08+00:00","description":"The NIST guidelines are at the center of a debate about how \u2014 and if \u2014 the United States government and American businesses can protect sensitive data","breadcrumb":{"@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/#primaryimage","url":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/NIST.jpg.jpg","contentUrl":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/NIST.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/2018\/12\/13\/does-it-compliance-mean-good-cybersecurity-experts-disagree\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/staging.sightlinemg.com\/c4isrnet\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Industry","item":"https:\/\/staging.sightlinemg.com\/c4isrnet\/industry\/","ad_zone":"industry"},{"@type":"ListItem","position":3,"name":"Does IT compliance mean good cybersecurity? Experts disagree."}]},{"@type":"WebSite","@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/#website","url":"https:\/\/staging.sightlinemg.com\/c4isrnet\/","name":"C4ISRNet","description":"Media for the Intelligence-Age Military | C4ISRNET","publisher":{"@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/staging.sightlinemg.com\/c4isrnet\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/#organization","name":"C4ISRNet","url":"https:\/\/staging.sightlinemg.com\/c4isrnet\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/","url":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","contentUrl":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","caption":"C4ISRNet"},"image":{"@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/staging.sightlinemg.com\/c4isrnet\/#\/schema\/person\/f1587e1f8c0d41f0683bf42b02602ad8","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/staging.sightlinemg.com\/c4isrnet\/author\/migration\/"}]}},"jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"C4ISRNet","distributor_original_site_url":"https:\/\/staging.sightlinemg.com\/c4isrnet","push-errors":false,"jetpack_featured_media_url":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/NIST.jpg.jpg","_links":{"self":[{"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/23346","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/comments?post=23346"}],"version-history":[{"count":1,"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/23346\/revisions"}],"predecessor-version":[{"id":23361,"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/23346\/revisions\/23361"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/26413"}],"wp:attachment":[{"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/media?parent=23346"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/categories?post=23346"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/tags?post=23346"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/coauthors?post=23346"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}