The RSA exhibit hall was filled with companies promoting "Compliance" as the value proposition. While on the one hand it's easy to see how compliance is important since organizations who don't meet their compliance obligations may either be monetarily fined or prevented from doing business. However, vendors are reaching something we're calling compliance parity – if Vendor A makes you PCI compliant and Vendor B also makes you PCI compliant (and the same for vendors C,D and E), then hasn't compliance become a commodity at that point and don't A, B, C, D and E need something else to differentiate themselves? When we asked vendors about this our friends at Agiliance had the best response – the difference is Operational Excellence. Compliance in the first place is government's way of mandating IT operational improvements. In the long run organizations must drive operational improvement and compliance is really a few steps into a much longer journey. If a vendor does it right, their customers not only can pass a compliance audit, the quality of their IT organizations are substantially improved.
