← WRITING  ·  GRC NOTE

The policy is current. The behavior is not.

The dangerous GRC gap is not always a missing document. It is a written path that no longer matches the system performing the work.

By Zion Boggan ·

A policy review proves that a document was reviewed. It does not prove that the system still behaves the way the document says.

Run a reality check

Quarterly reality check from policy to observed event and drift decisionPOLICYwritten pathSYSTEMwhat actsEVENTwhat happenedDRIFTfix or accept
Follow one real event through the system that performed it. Compare the observed path with the written one.
Vertical policy reality checkPOLICYwritten pathSYSTEMwhat actsEVENTwhat happenedDRIFTfix or accept
Follow one event from written path to actual behavior and drift decision.
  1. Pick one policy statement.
  2. Identify the system that actually performs the behavior.
  3. Trace a recent event from request to approval to system state to evidence.
  4. Compare the observed path with the written path.
  5. Record drift as a change, risk, or exception. Do not quietly rewrite history.

Three drift patterns

logging

Enabled, but blind

A service is enabled, but its configured log source does not exist. It can appear healthy until the next boot exposes the mismatch.

approval

Intent recorded, action missing

A ticket says access was approved, but no receipt shows that the affected system changed. The approval is not the operation.

inventory

The important asset is out of scope

A scan is clean because the asset was never in the scanner population. Coverage must be reconciled to the authoritative inventory.

watching

Conversation mistaken for work

A transcript is quiet while a worker is active, or changes after work is finished. Watch the artifact, process, service, or state that belongs to the job.

Drift is information. A mismatch tells you where ownership, procedure, system behavior, or evidence needs to change. Hiding it turns a manageable gap into a surprise.

Make the review operational

Give each important policy a reality-check owner and a trigger list. Recheck after a material incident, system change, supplier change, control failure, or change in the authoritative inventory. Use a calendar cadence when no event occurs, but do not wait for the quarter if the system has changed.

Keep the review small enough to run. One policy statement, one recent event, one trace, and one explicit decision is more useful than a hundred-page annual attestation no operator can repeat.

What the record should say

observed

What matched?

Name the statement, system, event, evidence, and date that aligned.

drift

What differed?

State the exact written step and the actual step, without hiding the mismatch in a score.

decision

What happens next?

Assign an owner, action, due date, compensating measure, and retest condition.

refresh

When is it true again?

Set the event or date that will prove the updated path is operating.

Framework context: NIST CSF 2.0, NIST SP 800-53 Rev. 5, and NIST SP 800-161 Rev. 1.