We've noted before that compliance burdens imposed on the IT side of the house may be working against the firm's security needs. Indeed, you can be fully compliant and less secure than you were before. With this in mind, one commentator has suggested five principles for balancing these needs: 1) Base your security program on a security framework, 2) Leverage compliance budgets for information security controls, 3) Automate policy compliance and auditing, 4) Be prepared to manage change in threats and regulations, and 5) Create an effective awareness and training program. Read more about these principle in this article on SearchSecurity.com.