About

Struggling to make sense of our current security policies. They're a jumble of outdated rules and half-finished projects. Here hoping to learn actual best practices for building sensible GRC frameworks. Tired of reinventing the wheel badly every time something comes up.