If you are not following security best practices that are appropriate for your organization from a recognized source such as NIST, SANS or similar, then all of your compliance will not matter because your security policies, standards and procedures are flawed and/or incomplete.