Security Orthodoxy Is Not Law

The Fusion Series · Part 5 of 6

The moment you propose folding the SOC into a unified operations team, someone says “compliance won’t allow it.” Almost every time, they’re wrong — and it’s worth knowing exactly why.

Of the four towers this series has been folding into one, security is the one people insist has to stay separate — and the reason they give is compliance. It is the strongest-sounding objection to a fusion center (Part 1), so it deserves a precise answer rather than a wave-off. Here is the precise answer: read the regulations closely and almost none of them say what people think they say.

The one genuine constraint

There is exactly one, and it is narrow: CALEA. Under it, a lawful intercept may be activated only with the affirmative intervention of a designated carrier officer or employee, and the carrier must name a senior person accountable for intercept security and file a system-security plan with the FCC. That is real, and it is non-negotiable. But notice what it actually requires: controlled access and a named, accountable individual — not a separate department. It is fully satisfiable inside a fusion center by ring-fencing intercept activation to CALEA-designated personnel with role-based access.

CALEA requires a named, accountable person and controlled access. It does not require a separate department. Almost nothing does.

The sacred cows

Now the frameworks invoked as though they mandate a standalone security organization. Read closely, they do not:

  • SOX does not require a separate security team. It requires management to assess internal controls and an auditor to attest to them; separation of duties enters only as a control activity companies choose under COSO — an implementation choice, not a mandate.
  • PCI-DSS requires separation between development/test and production environments — explicitly satisfiable with role-based access. Not a separate team.
  • NIS2 requires board approval and oversight of cyber-risk measures and makes leadership accountable — and it explicitly permits delegation of operational security. It does not require an independent function.
  • ISO 27001 and the NIST Cybersecurity Framework require that conflicting duties be segregated, with compensating controls — logging, supervision, audit trails — available to small teams. Neither requires a standalone security org.

See the pattern. Every one of these is about controls, access discipline, logging, and accountability. A well-designed fusion center can meet or beat all of them, because a unified view with role-based access and clean audit trails is often better controlled than four separate teams handing tickets across four chains of command. What not one of these frameworks requires is four separate round-the-clock rosters.

So what actually blocks it?

Usually turf, budget, and habit wearing the costume of compliance. It is worth being honest about this, because it is the real obstacle. The CISO and the CIO rarely report to the same person; the budgets are separate; the missions and the mindsets differ. Politics will fight fusion. That is a genuine force — but it is a political force, not a legal one, and naming it correctly is the first step to dealing with it.

What that means in practice

You do not need a regulation’s permission to fold security’s Tier-1 and Tier-2 into a unified team. You keep specialized threat hunting and deep incident response as a daytime expert discipline. You ring-fence lawful-intercept activation to designated personnel. You preserve board oversight for NIS2. And you hold yourself to the one gate that keeps a CISO in the room: mean-time-to-resolution improves with no increase in the missed-alert rate, and the audit comes back clean. Clear that bar and “compliance” has no argument left.

An honest caveat: most operators will still move slowly here, and many will leave security partly separate. That can be a legitimate choice — the point is to make it a choice, on the merits, rather than deferring to a regulation that, read closely, says no such thing.

Enough theory. Part 6 shows what a fusion center looks like when it is actually running — from a proof of concept measured in hours to a quieter, cheaper night shift — and what it is reasonable to expect it to save.

Go deeper

The full compliance breakdown — every framework, what it actually requires, and how a fusion center satisfies it — is in the white paper.

Read: Fuse or Fold →

If any of this lands and you want to talk about what it means for your operation — 15 minutes at cal.com/shawn-ennis. No prep needed.