GRC Architecture

The Side of GRC Most People Overlook

Whenever I tell people that I work in Governance, Risk and Compliance (GRC), the reaction is usually the same. “So, you spend your day writing policies?” It’s a fair question because, from the outside, that’s exactly what GRC looks like. Before I started working in this field, I probably would have said the same thing. The reality is very different.

Proof Over Paperwork: FedRAMP's Shift From Rev5 to 20x

Government rarely moves first on anything, which is what makes the current change at FedRAMP worth attention. The Federal Risk and Authorization Management Program is the seal that lets cloud providers sell to federal agencies, and for years it has been synonymous with a particular way of proving security: a very large stack of documents, assessed once, and revisited on an annual cadence.