From Controls to Continuous Assurance: Rethinking GRC for Cloud-Native Environments
The standard process of building governance, risk, and compliance (GRC) programs has been straightforward: define a control, document a control, test the control on a regular basis, and generate a report for the auditor 1-2 times a year. This worked in the context where the IT infrastructure was changing slowly, The post From Controls to Continuous Assurance: Rethinking GRC for Cloud-Native…
We haven't written up this one. Container Journal has the full story — the link below goes straight to it.