Identity at the Center

#340 - RSM & IDAC Present: Compliance & Digital Identity with Kia Smith

Mar 31, 2025
Kia Smith, a director at RSM with a law and federal IT audit background, focuses on compliance, governance, and cybersecurity. She discusses aligning compliance with security, the growing regulatory complexity driven by third-party and cloud relationships, the broad impact of CMMC on supply chains, and the emerging role of AI in compliance validation.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Compliance Is Evidence Of Protection

  • Compliance's core purpose is to provide assurance that information is being protected.
  • Kia Smith frames compliance as evidence that tells a larger story about organizational security posture.
ADVICE

Show How IAM Fits The Bigger Picture

  • Treat each compliance piece as part of a bigger picture rather than isolated artifacts.
  • Ensure your IAM evidence (RBAC, access reviews) demonstrates how the organization operates and protects data.
ADVICE

Don't Let Third Parties Outsource Your Risk

  • Map third-party services into your risk and governance model rather than assuming their certifications cover you.
  • Maintain continuous validation (spot checks, contractual notification) to ensure vendor posture aligns with yours.
Get the Snipd Podcast app to discover more snips from this episode
Get the app