An Actively Reported & Monitored Program
We recently acquired a new Governance, Risk, and Compliance system and have been migrating policies, automating evidence collection, and using the built-in tests to identify issues. We’d had our previous system for many years, and I’m impressed by how much these tools have improved since I’d last looked. It’s already clear the new tool will save time, not just for the compliance team but for the entire engineering organization. I’m looking forward to less shuffling of screenshots, spreadsheets, and PDFs, and I especially won’t miss wasting the software and deployment engineers’ time with meetings to tick through access lists and scan reports. ...