The policy is current. The behavior is not.
The dangerous GRC gap is not always a missing document. It is a written path that no longer matches the system performing the work.
By Zion Boggan ·
The dangerous GRC gap is not always a missing document. It is a written path that no longer matches the system performing the work.
By Zion Boggan ·
A policy review proves that a document was reviewed. It does not prove that the system still behaves the way the document says.
A service is enabled, but its configured log source does not exist. It can appear healthy until the next boot exposes the mismatch.
A ticket says access was approved, but no receipt shows that the affected system changed. The approval is not the operation.
A scan is clean because the asset was never in the scanner population. Coverage must be reconciled to the authoritative inventory.
A transcript is quiet while a worker is active, or changes after work is finished. Watch the artifact, process, service, or state that belongs to the job.
Give each important policy a reality-check owner and a trigger list. Recheck after a material incident, system change, supplier change, control failure, or change in the authoritative inventory. Use a calendar cadence when no event occurs, but do not wait for the quarter if the system has changed.
Keep the review small enough to run. One policy statement, one recent event, one trace, and one explicit decision is more useful than a hundred-page annual attestation no operator can repeat.
Name the statement, system, event, evidence, and date that aligned.
State the exact written step and the actual step, without hiding the mismatch in a score.
Assign an owner, action, due date, compensating measure, and retest condition.
Set the event or date that will prove the updated path is operating.
Framework context: NIST CSF 2.0, NIST SP 800-53 Rev. 5, and NIST SP 800-161 Rev. 1.