Compliance Cautions: Investigating Security Issues Associated with U.S. Digital-Security Standards
Rock Stevens, Josiah Dykstra, Wendy Knox Everette, James Chapman, Garrett Bladow, Alexander Farmer, Kevin Halliday, Michelle L. Mazurek
摘要
Digital security compliance programs and policies serve as powerful tools for protecting organizations' intellectual property, sensitive resources, customers, and employees through mandated security controls. Organizations place a significant emphasis on compliance and often conflate high compliance audit scores with strong security; however, no compliance standard has been systemically evaluated for security concerns that may exist even within fully-compliant organizations. In this study, we describe our approach for auditing three exemplar compliance standards that affect nearly every person within the United States: standards for federal tax information, credit card transactions, and the electric grid. We partner with organizations that use these standards to validate our findings within enterprise environments and provide first-hand narratives describing impact.
We find that when compliance standards are used literally as checklists --- a common occurrence, as confirmed by compliance experts --- their technical controls and processes are not always sufficient. Security concerns can exist even with perfect compliance. We identified 148 issues of varying severity across three standards; our expert partners assessed 49 of these issues and validated that 36 were present in their own environments and 10 could plausibly occur elsewhere. We also discovered that no clearly-defined process exists for reporting security concerns associated with compliance standards; we report on our varying levels of success in responsibly disclosing our findings and influencing revisions to the affected standards. Overall, our results suggest that auditing compliance standards can provide valuable benefits to the security posture of compliant organizations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ UtilsSivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines 等ICSE 2026 · 被引用 5 次
- "Belt and suspenders" or "just red tape"?: Investigating Early Artifacts and User Perceptions of IoT App Security CertificationPrianka Mandal, Amit Seal Ami, Victor Olaiya, Sayyed Hadi Razmjo 等USENIX Security 2024 · 被引用 4 次
- On the Contents and Utility of IoT Cybersecurity GuidelinesJesse Chen, Dharun Anandayuvaraj, James C. Davis, Sazzadur RahamanFSE 2024 · 被引用 1 次
- The Challenges and Opportunities with Cybersecurity Regulations: A Case Study of the US Electric Power SectorSena Sahin, Burak Sahin, Robin Berthier, Kate Davis 等CCS 2025 · 被引用 1 次
- "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product SecurityPrianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin 等S&P 2025
它引用的顶会 Paper2
- The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise LevelRock Stevens, Daniel Votipka, Elissa M. Redmiles, Colin Ahern 等USENIX Security 2018 · 被引用 51 次
- TARDIS: Rolling Back The Clock On CMS-Targeting Cyber AttacksRanjita Pai Kasturi, Yiting Sun, Ruian Duan, Omar Alrawi 等S&P 2020 · 被引用 14 次
相关 Paper
- Above and Beyond: Organizational Efforts to Complement U.S. Digital Security Compliance MandatesRock Stevens, Faris Bugra Kokulu, Adam Doupé, Michelle L. MazurekNDSS 2022
- Quantifying Security Training in Organizations Through the Analysis of U.S. SEC 10-K FilingsJonas Hielscher, Maximilian GollaCCS 2025
- Cardpliance: PCI DSS Compliance of Android ApplicationsSamin Yaseer Mahmud, Akhil Acharya, Benjamin Andow, William Enck 等USENIX Security 2020
- An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland SecurityWilliam P. Maxam III, James C. DavisUSENIX Security 2024 · 被引用 14 次
- "We can't Change it Overnight": Understanding Industry Perspectives on IoT Product Security Compliance and CertificationPrianka Mandal, Adwait NadkarniS&P 2025
