KEY CAPABILITY · GRCOPS
GRCOps: governance conducted continuously, not certified once a year.
GRCOps is a way of running governance, not another module. An audit tells you what was true one day; the approach covers the other days: you catch a gap as it opens, turn it into an owned and dated action, drive it through one lifecycle to a closure verified by evidence, and measure security work against the service levels you set.
- Draft
- Submitted
- Approved
- Effective
- Expired / closed
DER-042
Legacy TLS on the HR portal
Scope: HR portal · IT & Digital
Waives: NIS2 Art. 21 · ISO 27001 A.8.24
Expires: Nov 15, 2026
Residual risk: high
Approval chain BU CISO → Group CISO · approved, trail attached
Compensating actions
- Reinforced MFA on admin access applied
- Network segmentation in progress
- Extended logging & alerting planned
Coverage: partially applied
One lane of the queue: approved at the right level, compensated by tracked actions, weighed in posture until it expires.
AUDIT DAY VS EVERY DAY
The audit is a photograph. The posture is the film.
Left: what an audit certifies, valid the day it is signed. Right: what GRCOps runs the other days.
Point-in-time audit Signed 12 March
- MFA enforced on admin access
- Supplier access reviewed
- TLS 1.0 disabled on the HR portal
- Backups tested quarterly
Six months later Two of these have drifted. The report still says green.
Runtime
- 09:41 MFA drift detected on sso-core
- 09:42 Action A-2291 created · owner IAM · SLA 72 h
- D+1 Escalated: 48 h without acknowledgement
- D+2 Closed on evidence · re-verified · 31 h, within SLA
WHAT YOU RUN WITH IT
Seven things you run with GRCOps.
Open one. The scene beside it shows what moves in the queue.
01 Detect gaps at runtime
Continuous gap analysis on connected signals and verified controls: a control that drifts, a supplier answer that contradicts a fact, an advisory that matches your stack raises a finding the moment it happens, not at the next campaign.
- Drift detected on connected signals, not declared
- Findings raised where they happen, with the object kept
- The posture moves the same hour
02 One queue for every security action
Risk treatments, control gaps, supplier remediation items, derogation compensating measures, audit findings and advisory matches all land in the same queue, each carrying the object it came from.
- One queue, every source
- Each action linked to the risk, control or supplier behind it
- Nothing lives in an e-mail any more
03 A lifecycle, not a status field
Captured, qualified, assigned, in progress, awaiting verification, closed: every transition is an explicit decision with a trail, never a dropdown quietly changed.
- Explicit transitions, each with a trail
- Verification is a step, not a checkbox
- The same lifecycle for every lane
04 Service levels, ageing and escalation
Every action carries a clock: a time to acknowledge and a time to close per criticality and per organization. Ageing and overdue work surface on their own, and what stalls escalates instead of sinking to the bottom of a list.
- SLA per criticality and per organization
- Ageing and overdue visible without asking
- Escalation when the clock runs out
05 Derogations as a governed lane
Exceptions keep everything they had: a risk assessment at the gate, approval at the right level, compensating measures as tracked actions, scored coverage and an expiry that forces the conversation again.
- Approval at the right level, trail attached
- Compensating measures as tracked actions
- Expiry that reopens the decision
06 Closure verified by evidence
An action closes on proof: the changed control, the attached artefact, the re-scored risk. “Done” means verified, and the trail says by whom.
- Closure gated on evidence and re-scoring
- Who verified what, recorded
- The audit finds a trail, not a promise
07 Wired to where work happens
Actions sync both ways with the ticketing and messaging connectors from the marketplace, so teams work where they already are and the queue stays true.
- Two-way sync with ticketing and messaging
- Teams keep their tools
- The queue keeps the truth
THE RUN
Posture is not what the audit found. It is what you closed since.
The audit report is a photograph; the posture is the film. Between two audits, controls drift, suppliers change, exceptions age. GRCOps treats security as operations: gaps are detected when they open, every action carries a service level, delivery is measured, and the posture moves because something was fixed, not because a box was ticked.
- 01
Detect
Gaps are raised where they open: from a drifting control, a supplier assessment, a derogation request, a matched advisory or an audit point, with the link kept.
- 02
Drive
Owners, dates and service levels are set, work moves through the lifecycle, ageing and overdue items surface, and stalled ones escalate.
- 03
Prove
Closure is gated on evidence and re-scoring; the trail records who verified what. The posture updates because something changed, not because a box was ticked.
THE RUN, MEASURED
Delivery performance, the way operations teams read it.
Security work gets a service level like any other operation: time to acknowledge, time to close, per criticality. GRCOps reads delivery against it.
Within SLA
94 %
Median time to close
6 d
Overdue
3
Escalated this week
2
Time to close against SLA, by criticality
Each bar is the median time to close as a share of the service level; past the line is a breach. Ageing, overdue and escalation are the honest side of the posture, and the board reads them too.
UNDER THE HOOD
Where the actions come from, and where they land.
Risk Intelligence
Treatments, KRI breaches and derogations raised from the register become actions here.
Learn more
Third-Party Risk Management
Supplier remediation plans: joint actions with the vendor, tracked to closure.
Learn more
Board-Ready Reporting
Backlog, ageing, closure rates and SLA delivery read by organization, the honest side of the posture.
Learn more
Security by Design
The use case where project-time requirements and exceptions turn into dated actions.
Learn more
FAQ
GRCOps, in practice
Is GRCOps a ticketing tool?
No. Tickets are where a task gets executed; GRCOps is where a security action is governed: its origin, its owner, its clock, its lifecycle, its proof of closure and its effect on the posture. The two sync both ways, so teams keep their tools and the queue keeps the truth.
What service levels can we set?
A time to acknowledge and a time to close, per criticality and per organization, with escalation when the clock runs out. Delivery is then read against those levels: within SLA, ageing, overdue, escalated.
What happened to Derogations?
They are a lane of GRCOps. Everything the derogation register did is still there: the risk assessment at the gate, the approval chain per organization, compensating measures as tracked actions, scored coverage, the expiry timeline and the weight on posture. They simply live with the other actions now.
How is closure verified?
An action closes on proof: the changed control, the attached artefact, the re-scored risk. The step before closure is a verification, and the trail records who did it.
Who sees the queue?
Everyone at their level: owners see their actions, managers their team’s backlog and ageing, the CISO the full view by organization, and the board the closure rate and SLA delivery the reporting derives from it.
GLOSSARY
Terms to know
FROM AUDIT DAY TO EVERY DAY
Bring your last audit report. Watch it become a queue.
A live session: findings captured, given a clock, driven and closed on proof, the posture moving in the same hour.