There is no instance in which a security-first practice is weaker than a regulatory standard. Security is the metaphorical horse, compliance is the cart; an organization’s security drives their compliance. The challenges are understandable, but taking the path of least resistance is not. The importance of classifying data according to its sensitivity, location, attractiveness to attackers and other factors; not just by compliance requirements. The importance should be classified according to the sensitivity of the data, rather than by compliance.”]
Source: https://www.bankinfosecurity.com/whitepapers/but-i-was-compliant-w-2800