Perspectives on the Relationship between Compliance and Cybersecurity



Angelica Marotta — Sloan School of Management, Massachusetts Institute of Technology, USA
Stuart Madnick — Sloan School of Management, Massachusetts Institute of Technology, USA
Today, cybersecurity is evolving, and so is compliance's critical role in influencing cybersecurity prevention and mitigation approaches. However, while compliance often acts as a lever for maturity growth, using regulatory requirements as a plan for building a cybersecurity program may result in an incomplete approach to achieving a secure organizational environment. Thus, even if an organization is compliant with the most rigorous requirements, it may still have gaps that leave room for vulnerabilities. Compliance is not black and white but rather a matter of a series of components. This paper provides an in-depth literature review of 96 publications and investigates the compliance factors that may have an impact on cybersecurity practices. This research offers three contributions. Firstly, it provides an overview of compliance. Secondly, it provides a comparison between worker safety compliance and cybersecurity compliance. Thirdly, it investigates cybersecurity compliance in different sectors.




Compliance, Cybersecurity, Compliance Management, Regulations, Risk, Safety.




