Justin Vasquez is a Texas local-government IT director who has spent more than a decade responsible for the practical reality behind county technology: networks, endpoints, vendors, facilities, support, policy, security, and the inevitable jobs that do not fit neatly into an org chart.
His first meaningful modern CJIS technical audit was a shock. The last audit experience he carried in his head came from years earlier, when the compliance environment felt much simpler. The newer audit exposed a much larger gap between “we generally secure this environment” and “we understand the current controls, have built the right practices, can document them, and can prove what we are saying.”
The next audit was scheduled for the following morning. In the hours between them, he started translating control language into ordinary agency questions and comparing each requirement to the way the organization actually worked. That process became a repeatable method: Control → Lay-nguage → Reality → Gap → Remediation → Policy → Evidence.
Across the audits that followed, many honest no answers became honest yes answers because the underlying practices changed. Later audits became dramatically shorter and calmer. The point was never to learn how to “beat” an audit. The point was to stop being surprised by your own environment.
The larger lesson: GRC without the jargon
The audits also became a practical introduction to governance, risk, and compliance. Governance asks who owns the responsibility and what the organization expects. Risk asks what can go wrong, how significant it is, and what deserves attention. Compliance asks whether the organization can demonstrate that applicable requirements are being satisfied. In a small government environment, those three things meet every day—often without anybody calling them GRC.