GRC Engineering: The new way to be compliant
- ~Mimi

- Aug 9
- 2 min read

Y'all, I found this dope club of over 8000 people worldwide taking GRC and flipping it on its head. We're no longer focused on simply checking the box when an audit comes along. We are providing the proof and evidence, in real time on a regular basis, using automation. Traditional (GRC) Governance, Risk, and Compliance has been seen as a checkbox activity that is done one time. A report is generated, usually a gazillion pages, and it just kind of sits around. Have you ever read a SOC2 report and your eyes bulged? You are wondering what it means and how it relates to security. Or maybe your auditor (ISO, PCI, whomever) is asking you for all types of evidence that something is compliant, and you don't have it readily available. These are checkbox activities.
When we go through compliance audits, we hate it. It's time-consuming, full of meetings, and it doesn't actually tell you if you are secure or not. It barely tells you for sure that you are compliant. Mostly that you applied some controls and forgot about it until the next time. This isn't the case for every organization, but for those where it is, GRC Engineering is here to help you. Let's get some automation involved in the process so you have real-time evidence collection and actual proof that systems are compliant.
If you know me, I have done all sorts of things in cyber and tech. They all involved some form of GRC in the mix. Matching vulnerabilities to controls in a framework such as NIST or ISO. Working across teams with risk to make sure we have our evidence and delivering data to leadership as it pertains to the issues and what we are doing. Now I am expanding that knowledge with the GRC Engineering Club, and it's been a fun experience thus far. To brush up on my skills, I started the 6-week challenge they have in the lab. 6 weeks of building artifacts for my portfolio to showcase how we can automate some of this work using Terraform and AWS and what that can look like for an organization. I will update this page with links to my GitHub that show the challenge and how I worked through it. You will find real files, real commands, and sometimes real troubleshooting (yes, I know a lot, but there are some things in AWS, Terraform, and Python I don't know). Each challenge builds on the previous one and gives me the experience needed for helping organizations navigate this space and start automating. Disclaimer: I do not get anything from links in these articles unless they want me to advertise! LOL
Challenges
Week 1 - Compliant s3 Resources
Week 2
Week 3
Week 4
Week 5
Week 6



Comments