<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Govern on pericule</title>
    <link>https://pericule.com/tags/govern/</link>
    <description>Recent content in Govern on pericule</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Fri, 31 Jul 2026 18:22:31 +0000</lastBuildDate>
    <atom:link href="https://pericule.com/tags/govern/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>An Actively Reported &amp; Monitored Program</title>
      <link>https://pericule.com/posts/2026-07-31-an-actively-reported-and-monitored-program/</link>
      <pubDate>Fri, 31 Jul 2026 18:22:31 +0000</pubDate>
      <guid>https://pericule.com/posts/2026-07-31-an-actively-reported-and-monitored-program/</guid>
      <description>&lt;p&gt;We recently acquired a new Governance, Risk, and Compliance system and
have been migrating policies, automating evidence collection, and
using the built-in tests to identify issues. We&amp;rsquo;d had our previous
system for many years, and I&amp;rsquo;m impressed by how much these tools have
improved since I&amp;rsquo;d last looked. It&amp;rsquo;s already clear the new tool will
save time, not just for the compliance team but for the entire
engineering organization. I&amp;rsquo;m looking forward to less shuffling of
screenshots, spreadsheets, and PDFs, and I especially won&amp;rsquo;t miss
wasting the software and deployment engineers&amp;rsquo; time with meetings to
tick through access lists and scan reports.&lt;/p&gt;</description>
      <content:encoded><![CDATA[<p>We recently acquired a new Governance, Risk, and Compliance system and
have been migrating policies, automating evidence collection, and
using the built-in tests to identify issues. We&rsquo;d had our previous
system for many years, and I&rsquo;m impressed by how much these tools have
improved since I&rsquo;d last looked. It&rsquo;s already clear the new tool will
save time, not just for the compliance team but for the entire
engineering organization. I&rsquo;m looking forward to less shuffling of
screenshots, spreadsheets, and PDFs, and I especially won&rsquo;t miss
wasting the software and deployment engineers&rsquo; time with meetings to
tick through access lists and scan reports.</p>
<p>The GRC system is facilitating many of the activities of our security
and compliance team, including:</p>
<ul>
<li>Ensuring compliance with the requirements of all the frameworks we
observe</li>
<li>Managing policies, procedures, standards, and other documentation</li>
<li>Collecting evidence for and managing audits</li>
<li>Tracking program improvements</li>
<li>Hosting a trust center for current and prospective customers</li>
<li>Conducting third-party assessments (the system we have meshes nicely
with <a href="https://pericule.com/posts/2025-09-23-vendor-security-assessments-are-out-of-control/">my lean but targeted approach</a>)</li>
<li>Managing customer security questionnaires</li>
<li>Keeping a risk registry</li>
<li>Inventorying assets</li>
</ul>
<p>Choosing a system with a large number of built-in of integrations
(linkages to other SaaS services and IT systems) was wise&mdash;every time
we integrate the GRC system with another existing IT system, we
discover new vulnerabilities or broken processes.</p>
<p>But strategically, I&rsquo;m most excited about the automated testing, which
boosts our program from merely achieving to fully <em>monitoring</em>
compliance. At this level, compliance really gets tied back to
security because if the tests are properly designed, when they fail,
they&rsquo;ve found a security issue you need to address.</p>
<p>There are of course some systems for which no integrations have been
built. The GRC system&rsquo;s API becomes very important here. The more
fully developed the API is, the easier it will be for you to write
your own automations. Ours also has its own Model Context Protocol
(MCP) service. Between the API and the MCP, it&rsquo;s easy to have an LLM
like Claude develop the automations for you. That&rsquo;s how I automated
the migration of our existing trust center FAQ to the new GRC system
(which has a built-in, integrated trust center), a task which
otherwise would have cost an employee hours of time and much of the
feeling in their mouse-clicking hand.</p>
]]></content:encoded>
    </item>
  </channel>
</rss>
