Pillar
GRC and compliance is the work of proving a control exists when someone who does not write the code asks. The failure mode is a screenshot folder and a policy that does not match the repository.
Pull evidence again
Open the listTrack the questionnaire you already sent
Open the listQuestions about GRC and Compliance
Only if we can name a job: collect this evidence from GitHub and the cloud account, map it to this control, keep the screenshot out of Slack. A platform that is a questionnaire with a price will not make the list.
No. Operations is the queue. GRC is the proof. A SIEM alert is not evidence unless you can show the control that should have fired and the ticket that closed. Different lists, on purpose.
Keep the control in the repo and the ticket in the same system you already use. If a tool cannot read that, it is a binder. We will say so when the list exists.