I am a IT security & compliance person at a medium sized company. We are required to be HIPAA, SOC 2 and HITRUST compliant.
One of the HITRUST controls requires us to only have approved software on work machines. Our CSO see no problem with he, or his IT team having games (Steam, Minecraft, EA origin...) bit torrent clients, other non-work related software on their machines. I gave him a list of software that should / shouldn't be on work machines and he said "Then we will just approve everything". As a security guy, I always strive to follow the minimum necessary rule. How do you handle a CSO who blatantly disregards standard security rules?
SOCIAL SHARE CARD GENERATOR