About
About GRCIDE
GRCIDE is an independent publication for security governance, risk and compliance practitioners — a library of working method, a lab where that method is shipped as software, and an advisory door for organisations that want the method run for them.
01 — What this is
A method library, a lab, and an advisory door.
GRCIDE publishes the method behind governance, risk and compliance work: playbooks that run end to end, briefings on what changed in a regulation, and a regulatory radar. There are also templates usable the day they are downloaded, and engagement patterns showing how a piece of work is shaped. The Lab is where the same method is built into software. Advisory is the door for organisations that would rather have the method run for them than read it.
Every piece is written from the standards and from practice, not from a client file. Each regulatory date, article and designation is checked against the primary source before it is published, and the source is recorded. Anything still unchecked stays unpublished. Methods are written to survive the auditor's side of the table as well as the practitioner's, because that is the side on which a program actually fails.
It is written for the people who carry the work: the security manager standing up a management system, the officer preparing for an audit, the engineer who has just learned that a product regime applies. Not for a procurement checklist, and not for a reader who wants to be reassured.
02 — Principles
Three rules that shape the work.
Pragmatic over perfect
A control an organisation can actually run beats one that only reads well. Proportionate to the risk, never maximal for its own sake.
Method over slideware
Concrete method speaks louder than capability statements. Everything published here is written to be followed, step by step.
Outcomes over deliverables
A binder is not an outcome. What an engagement leaves behind is a program the organisation's own team owns and keeps running.
03 — Editorial standards
How the pieces are written.
These rules are enforced by a lint that runs before anything is published, not by good intentions.
- No invented engagements or outcomes. Nothing here is a client account. Engagement patterns are labelled as reference patterns and carry no outcome numbers.
- No employer-internal material. Nothing traceable to any organisation's internal documents, identifiers, assessments or people appears on this site.
- Method has to be auditable. A playbook carries scope, prerequisites, a step list, deliverables, what the auditor will ask, failure modes, and clause references.
- Plain voice. Direct, senior, concrete. Short sentences, no marketing vocabulary, no fear-selling, no rhetorical questions standing in for headings.
- Evidence labels. Every substantive claim about a regulation carries a verified source marker, and unverified claims are not published.
- Official designations. Standards and regulations are named the way the issuing body names them, checked once and recorded in a references file.
GRCIDE is an independent publication. Content is method and public-standard knowledge; it is not legal advice and does not describe any specific organisation.