Subscribe

Pillar

GRC and Compliance

GRC and compliance is the work of proving a control exists when someone who does not write the code asks. The failure mode is a screenshot folder and a policy that does not match the repository.

Questions about GRC and Compliance

Will SecureCoding rank GRC platforms?

Only if we can name a job: collect this evidence from GitHub and the cloud account, map it to this control, keep the screenshot out of Slack. A platform that is a questionnaire with a price will not make the list.

Is this the same as security operations?

No. Operations is the queue. GRC is the proof. A SIEM alert is not evidence unless you can show the control that should have fired and the ticket that closed. Different lists, on purpose.

What should engineering do about SOC 2 without a list?

Keep the control in the repo and the ticket in the same system you already use. If a tool cannot read that, it is a binder. We will say so when the list exists.