Being compliant with a regulation (industry, government, etc.) should not give an organization a sense of security (false or deserved). If you have a good (meaningful, mature, risk based, etc.) security program your journey to compliance will be much less difficult. On the other hand if you are are trying to use a compliance requirement checklist as a security program, you will not be successful.
Ideas, tips, tricks, and theory on Information Security, risk management, forensics, and e-discovery.